Description
HTTP requests send sensitive data in plaintext, exposing it to interception and man-in-the-middle attacks. HTTP alone does not provide transport confidentiality, integrity, or peer authentication.
Potential impact
- Information disclosure: Attackers may intercept sensitive data transmitted in plaintext.
- Data tampering: Data may be modified in transit.
- Authentication compromise: Stolen credentials may allow an attacker to impersonate a user.
Remediation
- Use HTTPS and keep server-certificate verification enabled to protect transmitted data.
- Use TLS 1.2 or later.
- Configure the server and application to require HTTPS.
Examples
Before
python
# Unsafe HTTP requests
import requests
response = requests.get('http://example.com/api/data')
After
python
# Safe HTTPS requests
import requests
response = requests.get('https://example.com/api/data')
Explanation
- Before: HTTP transmits sensitive data in plaintext and exposes it to man-in-the-middle attacks.
- After: HTTPS and default server-certificate verification protect data in transit. Do not disable certificate verification with
verify=False.