> For the complete documentation index, see [llms.txt](https://dev7days.gitbook.io/dev7days/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dev7days.gitbook.io/dev7days/backend-security/man-in-the-middle-mitm.md).

# Man in the Middle (MITM)

This problem is occur when we have someone (Hacker) that stay between our user and target website. He always captures the request between user and target and try to get the information.

<img src="https://2166680554-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FP9VzT74ziIucCaJgfreE%2Fuploads%2FqvofGbxD9L9rQE2btuHk%2Ffile.excalidraw.svg?alt=media&amp;token=645e883e-bee1-4112-98a7-bc1da81fd4f9" alt="" class="gitbook-drawing">

**How to Protect**

1. Use `HTTPS, SSL` to encrypt the data between client and server
2. Use `HSTS` to informs browsers that the site should only be accessed using HTTPS, and that any future attempts to access it using HTTP should automatically be converted to HTTPS. (This is more secure than simply configuring a HTTP to HTTPS (301) redirect on your server, where the initial HTTP connection is still vulnerable to a man-in-the-middle attack.)\
   \
   reference: <https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security>
