{"id":32603,"date":"2019-10-31T21:47:55","date_gmt":"2019-10-31T18:47:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya\/"},"modified":"2019-10-31T21:47:55","modified_gmt":"2019-10-31T18:47:55","slug":"potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya","title":{"rendered":"Microsoft has seen signs of the end of the Intel processor shortage.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Half of websites <noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/services\/ssl\/dv?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=https&amp;utm_content=site\">use HTTPS<\/a><\/noindex>, and their number is steadily increasing. The protocol reduces the risk of traffic interception but does not eliminate attack attempts altogether. We will discuss some of them \u2014 POODLE, BEAST, DROWN, and others \u2014 and ways to protect against them in our article.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/449866\/\"><img decoding=\"async\" alt=\"Microsoft has seen signs of the end of the Intel processor shortage.\" src=\"\/wp-content\/uploads\/2019\/04\/305d426243ec7e580b5dd14de36eaed0.jpeg\" style=\"display:block;margin: 0 auto;\" \/> <\/a><\/noindex><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n<i>\/ Flickr \/ <noindex><a rel=\"nofollow\" href=\"https:\/\/www.flickr.com\/photos\/2011101\/23434336563\/\">Sven Graeme<\/a><\/noindex> \/ CC BY-SA<\/i><\/p>\n<h2>POODLE<\/h2>\n<p>\nThe attack was first reported <noindex><a rel=\"nofollow\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-3566\">POODLE<\/a><\/noindex> in 2014. The vulnerability in the SSL 3.0 protocol was discovered by information security expert Bodo M\u00f6ller and colleagues from Google.<\/p>\n<p>Its essence is as follows: a hacker forces the client to connect using SSL 3.0 by mimicking connection drops. Then, they search for special marker messages in the encrypted <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%A0%D0%B5%D0%B6%D0%B8%D0%BC_%D1%81%D1%86%D0%B5%D0%BF%D0%BB%D0%B5%D0%BD%D0%B8%D1%8F_%D0%B1%D0%BB%D0%BE%D0%BA%D0%BE%D0%B2_%D1%88%D0%B8%D1%84%D1%80%D0%BE%D1%82%D0%B5%D0%BA%D1%81%D1%82%D0%B0\">CBC<\/a><\/noindex>-mode traffic. Through a series of forged requests, the attacker gains the ability to reconstruct the content of the data of interest, such as cookies.<\/p>\n<p>SSL 3.0 is an outdated protocol. However, the issue of its security is still relevant. Clients use it to avoid compatibility problems with servers. According to some data, almost 7% of the 100,000 most popular websites <noindex><a rel=\"nofollow\" href=\"https:\/\/www.thesslstore.com\/blog\/nearly-21-of-the-worlds-top-100000-websites-still-arent-using-https\/\">still support SSL 3.0<\/a><\/noindex>. There are also <noindex><a rel=\"nofollow\" href=\"https:\/\/www.globalsign.com\/en\/blog\/poodle-vulnerability-expands-beyond-sslv3-to-tls\/\">modifications<\/a><\/noindex> of POODLE targeting more modern TLS 1.0 and TLS 1.1. This year, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.tripwire.com\/state-of-security\/vulnerability-management\/zombie-poodle-goldendoodle\/\">data has emerged<\/a><\/noindex> new attacks Zombie POODLE and GOLDENDOODLE, which bypass the protection of TLS 1.2 (they are still related to CBC encryption).<\/p>\n<p><b>How to protect yourself.<\/b> In the case of the original POODLE, it's necessary to disable support for SSL 3.0. However, this comes with the risk of compatibility issues. An alternative solution could be the TLS_FALLBACK_SCSV mechanism \u2014 it ensures that data exchange over SSL 3.0 will only occur with older systems. Attackers will no longer be able to initiate a protocol downgrade. To protect against Zombie POODLE and GOLDENDOODLE, one must disable CBC support in applications based on TLS 1.2. A radical solution would be to switch to TLS 1.3 \u2014 this new version of the protocol does not use CBC encryption. Instead, more resilient AES and ChaCha20 are used.<\/p>\n<h2>BEAST<\/h2>\n<p>\nOne of the earliest attacks on SSL and TLS 1.0, discovered in 2011. Like POODLE, BEAST <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acunetix.com\/blog\/articles\/tls-vulnerabilities-attacks-final-part\/\">use<\/a><\/noindex> Features of CBC encryption. Attackers deploy a JavaScript agent or Java applet on the client machine that intercepts messages during data transmission over TLS or SSL. Since attackers are aware of the contents of the \"forged\" packets, they can use them to decrypt the initialization vector and read other messages to the server, such as authentication cookie files.<\/p>\n<p>As of today, the BEAST vulnerability still <noindex><a rel=\"nofollow\" href=\"https:\/\/www.zdnet.com\/article\/its-2018-and-network-middleware-still-cant-handle-tls-without-breaking-encryption\/\">affects a range of network tools<\/a><\/noindex>: proxy servers and applications used to secure local internet gateways.<\/p>\n<p><b>How to protect yourself.<\/b> The attacker needs to regularly send requests to decrypt data. In VMware <noindex><a rel=\"nofollow\" href=\"https:\/\/kb.vmware.com\/s\/article\/2008784\">recommend<\/a><\/noindex> reduce the SSLSessionCacheTimeout from five minutes (the default recommendation) to 30 seconds. This approach complicates the attackers' plans, although it will have some negative impact on performance. Additionally, it is important to understand that soon the BEAST vulnerability may become obsolete by itself \u2014 starting from 2020, major browsers <noindex><a rel=\"nofollow\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/tls-10-and-tls-11-being-retired-in-2020-by-all-major-browsers\/\">will stop<\/a><\/noindex> supporting TLS 1.0 and 1.1. In any case, these protocols are used by less than 1.5% of all browser users.<\/p>\n<h2>DROWN<\/h2>\n<p>\nis a cross-protocol attack that exploits flaws in the implementation of SSLv2 with 40-bit RSA keys. An attacker listens to hundreds of the target's TLS connections and sends special packets to the server using SSLv2 with the same private key. By employing <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Adaptive_chosen-ciphertext_attack\">Bleichenbacher's attack<\/a><\/noindex>, a hacker can decrypt one of approximately a thousand client's TLS sessions.<\/p>\n<p>DROWN was first disclosed in 2016 \u2014 at that time it was <noindex><a rel=\"nofollow\" href=\"https:\/\/www.acunetix.com\/blog\/articles\/tls-vulnerabilities-attacks-final-part\/\">affecting a third of servers<\/a><\/noindex> in the world. To this day, it has not lost relevance. Of the 150,000 most popular sites, 2% still <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ssllabs.com\/ssl-pulse\/\">support<\/a><\/noindex> use SSLv2 and vulnerable encryption mechanisms.<\/p>\n<p><b>How to protect yourself.<\/b> It is necessary to apply the patches provided by cryptographic library developers that disable SSLv2 support. For example, two such patches were released for OpenSSL (in 2016, <noindex><a rel=\"nofollow\" href=\"https:\/\/drownattack.com\/#mitigation\">these were updates<\/a><\/noindex> 1.0.1s and 1.0.2g). Updates and instructions to disable the vulnerable protocol have also been published in <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/drown\">Red Hat<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/httpd.apache.org\/docs\/2.2\/mod\/mod_ssl.html#sslprotocol\">Apache<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2016-0800\">Debian<\/a><\/noindex>.<\/p>\n<blockquote><p><i>\"The resource may be vulnerable to DROWN if its keys are used by a third-party server with SSLv2, such as a mail server,\" notes the head of development <noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=https&amp;utm_content=site\">of the IaaS provider 1cloud.ru<\/a><\/noindex> Sergey Belkin. \u2014 This situation arises when multiple servers share a common SSL certificate. In this case, SSLv2 support must be disabled on all machines.<\/i><\/p><\/blockquote>\n<p>\nYou can check if your system needs an update using a special <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nimia\/public_drown_scanner\">utility<\/a><\/noindex> \u2014 it was developed by security experts who discovered DROWN. More recommendations related to protection against this type of attack can be found in the <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openssl.org\/blog\/blog\/2016\/03\/01\/an-openssl-users-guide-to-drown\/\">post on the OpenSSL website<\/a><\/noindex>.<\/p>\n<h2>Heartbleed<\/h2>\n<p>\nOne of the most significant vulnerabilities in software \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Heartbleed\">Heartbleed<\/a><\/noindex>was discovered in 2014 in the OpenSSL library. At the time of the error announcement, the number of vulnerable websites <noindex><a rel=\"nofollow\" href=\"https:\/\/news.netcraft.com\/archives\/2014\/04\/08\/half-a-million-widely-trusted-websites-vulnerable-to-heartbleed-bug.html\">was estimated at half a million<\/a><\/noindex> \u2014 about 17% of secured resources on the web.<\/p>\n<p>The attack is implemented through a small Heartbeat module of the TLS extension. The TLS protocol requires that data be transmitted continuously. In the event of prolonged inactivity, a disconnection occurs, and the connection must be re-established. To address the problem, servers and clients artificially 'noise' the channel (<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc6520\">RFC 6520, p.5<\/a><\/noindex>), transmitting a packet of random length. If it was larger than the maximum packet size, vulnerable versions of OpenSSL would read memory beyond the allocated buffer. This area could contain any data, including private encryption keys and information about other connections.<\/p>\n<p>The vulnerability was present in all versions of the library between 1.0.1 and 1.0.1f inclusive, as well as in several operating systems \u2014 Ubuntu up to 12.04.4, CentOS older than 6.5, OpenBSD 5.3, and others. A complete list is available <noindex><a rel=\"nofollow\" href=\"http:\/\/heartbleed.com\/\">on the Heartbleed website<\/a><\/noindex>. Although patches against this vulnerability were released almost immediately after its discovery, the problem remains relevant to this day. Even as of 2017, <noindex><a rel=\"nofollow\" href=\"https:\/\/thehackernews.com\/2017\/01\/heartbleed-openssl-vulnerability.html\">nearly 200,000 sites<\/a><\/noindex>, were still vulnerable to Heartbleed.<\/p>\n<p><b>How to protect yourself.<\/b> It is necessary to <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openssl.org\/source\/\">update OpenSSL<\/a><\/noindex> to version 1.0.1g or higher. You can also manually disable Heartbeat requests using the DOPENSSL_NO_HEARTBEATS option. After the update, security experts <noindex><a rel=\"nofollow\" href=\"https:\/\/thehackernews.com\/2017\/01\/heartbleed-openssl-vulnerability.html\">recommend<\/a><\/noindex> should reissue SSL certificates. Replacement is needed in case the encryption key data has been compromised by hackers.<\/p>\n<h2>Certificate Replacement<\/h2>\n<p>\nA managed node with a legitimate SSL certificate is set up between the user and the server, actively intercepting traffic. This node presents itself as a legitimate server, providing a valid certificate, and allows for a MITM attack.<\/p>\n<p>According to <noindex><a rel=\"nofollow\" href=\"https:\/\/jhalderm.com\/pub\/papers\/interception-ndss17.pdf\">a study<\/a><\/noindex> According to commands from Mozilla, Google, and several universities, approximately 11% of secure connections on the internet are being monitored. This is a result of suspicious root certificates being installed on users' computers.<\/p>\n<p><b>How to protect yourself.<\/b> Use the services of reliable <noindex><a rel=\"nofollow\" href=\"https:\/\/1cloud.ru\/services\/ssl?utm_source=habrahabr&amp;utm_medium=cpm&amp;utm_campaign=https&amp;utm_content=site\">SSL providers<\/a><\/noindex>. You can check the 'quality' of certificates using the service <noindex><a rel=\"nofollow\" href=\"https:\/\/www.certificate-transparency.org\/\">Certificate Transparency<\/a><\/noindex> (CT). Cloud providers can also help with detecting monitoring; already today, some large companies offer specialized tools for monitoring TLS connections.<\/p>\n<p>Another means of protection will be the new <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/444986\/\">the standard<\/a><\/noindex> ACME, which automates the acquisition of SSL certificates. It will also add additional mechanisms for verifying the ownership of the website. You can read more about it <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/444986\/\">in one of our previous articles<\/a><\/noindex>.<\/p>\n<p><img decoding=\"async\" alt=\"Microsoft has seen signs of the end of the Intel processor shortage.\" src=\"\/wp-content\/uploads\/2019\/04\/0ce792d1ebce9077460ebd02518e01ac.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>\/ Flickr \/ <noindex><a rel=\"nofollow\" href=\"https:\/\/www.flickr.com\/photos\/yusamoilov\/13334048894\/\">Yuri Samoilov<\/a><\/noindex> \/ CC BY<\/i><\/p>\n<h2>The Prospects of HTTPS<\/h2>\n<p>\nDespite a number of vulnerabilities, IT giants and cybersecurity experts are confident in the future of the protocol. For the active implementation of HTTPS, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.w3.org\/DesignIssues\/Security-NotTheS.html\">is<\/a><\/noindex> the creator of the WWW, Tim Berners-Lee. According to him, over time, TLS will become more secure, significantly enhancing the safety of connections. Berners-Lee even suggested that in the <noindex><a rel=\"nofollow\" href=\"https:\/\/www.w3.org\/DesignIssues\/Security-ClientCerts.html\">future,<\/a><\/noindex> client certificates for identity authentication will emerge. They will help improve server protection against intruders.<\/p>\n<p>The development of SSL\/TLS technology is also planned to be enhanced with machine learning\u2014intelligent algorithms will be responsible for filtering malicious traffic. In HTTPS connections, administrators have no means to know the contents of encrypted messages, including discovering requests from malware. Today, neural networks are already capable of filtering potentially dangerous packets with 90% accuracy. (<noindex><a rel=\"nofollow\" href=\"https:\/\/2018.bsidesbud.com\/wp-content\/uploads\/2018\/03\/seba_garcia_frantisek_strasak.pdf?forcedefault=true\">slide 23 of the presentation<\/a><\/noindex>).<\/p>\n<h2>Conclusions<\/h2>\n<p>\nAttacks on HTTPS are mostly related not to issues in the protocol itself, but to the support of outdated encryption mechanisms. The IT industry is gradually moving away from previous generation protocols and is offering new tools for vulnerability detection. In the future, these tools will become increasingly intelligent.<\/p>\n<h5>Additional resources on the topic:<\/h5>\n<p><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/448760\/\"> Cloud development, cybersecurity, and personal data: digest from 1cloud<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habrahabr.ru\/company\/1cloud\/blog\/315758\/\">SSL digest: Best practical materials on Habr and beyond<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habrahabr.ru\/company\/1cloud\/blog\/316266\/\">VPN digest: Introductory articles on Habr and beyond<\/a><\/noindex><\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/1cloud\/blog\/449866\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u043b\u043e\u0432\u0438\u043d\u0430 \u0441\u0430\u0439\u0442\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 HTTPS, \u0438 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u0442\u0441\u044f. \u041f\u0440\u043e\u0442\u043e\u043a\u043e\u043b \u0441\u043e\u043a\u0440\u0430\u0449\u0430\u0435\u0442 \u0440\u0438\u0441\u043a \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u0442\u0440\u0430\u0444\u0438\u043a\u0430, \u043d\u043e \u043d\u0435 \u0438\u0441\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u043f\u043e\u043f\u044b\u0442\u043a\u0438 \u0430\u0442\u0430\u043a \u043a\u0430\u043a \u0442\u0430\u043a\u043e\u0432\u044b\u0435. \u041e \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u0445 \u043d\u0438\u0445 \u2014 POODLE, BEAST, DROWN \u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u2014 \u0438 \u0441\u043f\u043e\u0441\u043e\u0431\u0430\u0445 \u0437\u0430\u0449\u0438\u0442\u044b, \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0435\u043c \u0432 \u043d\u0430\u0448\u0435\u043c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0435. \/ Flickr \/ Sven Graeme \/ CC BY-SA POODLE \u0412\u043f\u0435\u0440\u0432\u044b\u0435 \u043e\u0431 \u0430\u0442\u0430\u043a\u0435 POODLE \u0441\u0442\u0430\u043b\u043e \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":24394,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-32603","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u043b\u043e\u0432\u0438\u043d\u0430 \u0441\u0430\u0439\u0442\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 HTTPS, \u0438 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 HTTPS \u0438 \u043a\u0430\u043a \u043e\u0442 \u043d\u0438\u0445 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u043b\u043e\u0432\u0438\u043d\u0430 \u0441\u0430\u0439\u0442\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 HTTPS, \u0438 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:47:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:47:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Potential HTTPS attacks and how to protect against them | ProHoster","description":"Half of websites utilize HTTPS, and their number is steadily increasing.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 HTTPS \u0438 \u043a\u0430\u043a \u043e\u0442 \u043d\u0438\u0445 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f | ProHoster","og:description":"\u041f\u043e\u043b\u043e\u0432\u0438\u043d\u0430 \u0441\u0430\u0439\u0442\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 HTTPS, \u0438 \u0438\u0445 \u0447\u0438\u0441\u043b\u043e \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/potentsialnye-ataki-na-https-i-kak-ot-nih-zashhititsya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:47:55+00:00","article:modified_time":"2019-10-31T18:47:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"32603","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 11:43:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:55:24","updated":"2026-01-21 11:43:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/32603","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=32603"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/32603\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/24394"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=32603"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=32603"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=32603"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}