3 ms·
I'm more of a learning by doing person. Here's three exercises that you'll learn a lot doing: 1) https://www.ssllabs.com/ssltest/ https://www.ssllabs.com/sslte
by ZoFreX 9y ago
I'm more of a learning by doing person. Here's three exercises that you'll learn a lot doing:
1) https://www.ssllabs.com/ssltest/ https://www.ssllabs.com/ssltest/ - try to get an A+. It's not important to in most cases in practice, but you'll learn a lot getting there. Their rating guide is also handy: https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide https://github.com/ssllabs/research/wiki/SSL-Server-Rating-G...
2) MITM yourself. I've done this using Charles, you can do it with any HTTP proxy that lets you rewrite requests on the fly - I hear Fiddler is popular. MITM yourself and try changing the page for an HTTP site. Then try doing it on a website that is part HTTP part HTTPS (e.g. HTTPS for login page for example) and "steal your password". Try again on a website that redirects from HTTP to HTTPS using a 301 but does not have HSTS. Finally try on a site with HSTS (nb: you won't manage this one). Congratulations, you now truly understand why HSTS is important and what it does better than most people!
3) Set up HTTPS on a website. You've probably already done this. In which case maybe do it with LetsEncrypt for an extra challenge?
- surds 9y agoThat's awesome. I prefer to learn by doing too. It is way more effective and practical. Thanks for the advice. These steps, along with a book to read on the topic, should work very well! Thanks!