HTTP Fundamentals
HTTP is the web’s protocol, and the web is the largest attack surface there is. Understanding how a request and response are composed, what methods, headers, and status codes mean, and how state is kept (cookies, sessions) is the absolute prerequisite for the whole Web Hacking area: every attack in that section is, at bottom, a manipulated HTTP request.
Anatomy of a request
Section titled “Anatomy of a request”POST /login HTTP/1.1 <- method, path, versionHost: target.com <- headersUser-Agent: ...Cookie: session=abc123Content-Type: application/x-www-form-urlencoded <- blank lineuser=admin&pass=secret <- bodyAnd the response:
HTTP/1.1 200 OK <- version, status codeSet-Cookie: session=abc123; HttpOnlyContent-Type: text/html <- blank line<html>... <- bodyMethods
Section titled “Methods”GET request a resource (parameters in the URL)POST send data (in the body) -> login, formsPUT create/replace DELETE deletePATCH partial modify HEAD like GET without a bodyOPTIONS allowed methods (useful in API/CORS recon)Status codes (what they tell you while attacking)
Section titled “Status codes (what they tell you while attacking)”2xx success 200 OK, 201 Created3xx redirection 301/302 (open redirect), 304 Not Modified4xx client error 401 unauthenticated, 403 forbidden, 404 not found, 429 rate-limit5xx server error 500 (sometimes leaks stack traces), 502/503A 403→200 depending on a parameter, a 500 on a single quote, or a 302 to a controlled domain are vulnerability signals.
Headers that matter in security
Section titled “Headers that matter in security”Cookie / Set-Cookie session state (HttpOnly, Secure, SameSite)Authorization Bearer <token> / BasicHost virtual routing (host header attacks)Referer / Origin CSRF, CORSX-Forwarded-For client IP (spoofable)Content-Type how the body is interpreted (JSON vs form)Content-Security-Policy, HSTS, X-Frame-Options defensive headersState: cookies, sessions, and tokens
Section titled “State: cookies, sessions, and tokens”HTTP is stateless: each request is independent. State is kept with:
- Session cookies: the server stores the session and the browser resends the cookie.
- Tokens (JWT, Bearer): identity travels in a header, often stateless on the server.
Understanding this is the basis of attacks on authentication, sessions, CSRF, and JWT.
HTTPS, HTTP/2, and HTTP/3
Section titled “HTTPS, HTTP/2, and HTTP/3”HTTPS = HTTP over TLS (encrypted). HTTP/2 and HTTP/3 change the transport (multiplexing) and open their own attack classes (smuggling via downgrade, see HTTP Request Smuggling).
The tool: the proxy
Section titled “The tool: the proxy”Burp Suite / OWASP ZAP intercept, modify, and replay requestscurl -v / -X POST -d make requests from the terminalThe proxy between your browser and the server is web’s #1 tool: you see and modify every request.
Why it matters in security
Section titled “Why it matters in security”The whole Web Hacking area (SQLi, XSS, IDOR, SSRF, CSRF…) consists of manipulating HTTP requests. If you don’t understand what a header, method, or cookie is, you understand neither the attack nor the defense. It’s the language of the web.
Mastery checklist
Section titled “Mastery checklist”- I read and build an HTTP request/response by hand
- I know the methods and what each implies
- I interpret status codes and what they signal while attacking
- I identify the security-relevant headers
- I can explain how state is kept (cookies, sessions, tokens)
- I use curl and a proxy (Burp/ZAP) to intercept and replay
- I understand HTTPS and why HTTP/2 opens new attacks