Skip to content

HTTP Fundamentals

HTTP is the web’s protocol, and the web is the largest attack surface there is. Understanding how a request and response are composed, what methods, headers, and status codes mean, and how state is kept (cookies, sessions) is the absolute prerequisite for the whole Web Hacking area: every attack in that section is, at bottom, a manipulated HTTP request.

POST /login HTTP/1.1 <- method, path, version
Host: target.com <- headers
User-Agent: ...
Cookie: session=abc123
Content-Type: application/x-www-form-urlencoded
<- blank line
user=admin&pass=secret <- body

And the response:

HTTP/1.1 200 OK <- version, status code
Set-Cookie: session=abc123; HttpOnly
Content-Type: text/html
<- blank line
<html>... <- body
GET request a resource (parameters in the URL)
POST send data (in the body) -> login, forms
PUT create/replace DELETE delete
PATCH partial modify HEAD like GET without a body
OPTIONS allowed methods (useful in API/CORS recon)

Status codes (what they tell you while attacking)

Section titled “Status codes (what they tell you while attacking)”
2xx success 200 OK, 201 Created
3xx redirection 301/302 (open redirect), 304 Not Modified
4xx client error 401 unauthenticated, 403 forbidden, 404 not found, 429 rate-limit
5xx server error 500 (sometimes leaks stack traces), 502/503

A 403→200 depending on a parameter, a 500 on a single quote, or a 302 to a controlled domain are vulnerability signals.

Cookie / Set-Cookie session state (HttpOnly, Secure, SameSite)
Authorization Bearer <token> / Basic
Host virtual routing (host header attacks)
Referer / Origin CSRF, CORS
X-Forwarded-For client IP (spoofable)
Content-Type how the body is interpreted (JSON vs form)
Content-Security-Policy, HSTS, X-Frame-Options defensive headers

HTTP is stateless: each request is independent. State is kept with:

  • Session cookies: the server stores the session and the browser resends the cookie.
  • Tokens (JWT, Bearer): identity travels in a header, often stateless on the server.

Understanding this is the basis of attacks on authentication, sessions, CSRF, and JWT.

HTTPS = HTTP over TLS (encrypted). HTTP/2 and HTTP/3 change the transport (multiplexing) and open their own attack classes (smuggling via downgrade, see HTTP Request Smuggling).

Burp Suite / OWASP ZAP intercept, modify, and replay requests
curl -v / -X POST -d make requests from the terminal

The proxy between your browser and the server is web’s #1 tool: you see and modify every request.

The whole Web Hacking area (SQLi, XSS, IDOR, SSRF, CSRF…) consists of manipulating HTTP requests. If you don’t understand what a header, method, or cookie is, you understand neither the attack nor the defense. It’s the language of the web.

  • I read and build an HTTP request/response by hand
  • I know the methods and what each implies
  • I interpret status codes and what they signal while attacking
  • I identify the security-relevant headers
  • I can explain how state is kept (cookies, sessions, tokens)
  • I use curl and a proxy (Burp/ZAP) to intercept and replay
  • I understand HTTPS and why HTTP/2 opens new attacks