room ~ HTTP in Detail
HTTP in Detail
Methods, headers, cookies, status codes, curl, and security headers
1/7
lessons
HTTP & HTTPS Fundamentals
What is HTTP?
- HTTP = HyperText Transfer Protocol
- Client (browser) aur server ke beech request/response protocol
- Stateless = har request independent, server pichli request yaad nahi rakhta
- Sessions maintain karne ke liye cookies use hoti hain
HTTP vs HTTPS
| Feature | HTTP | HTTPS |
|---|---|---|
| Port | 80 | 443 |
| Encrypted | No | Yes (TLS) |
| Data visible | To anyone on network | Only client + server |
| Certificate | Not needed | SSL/TLS cert required |
URL Structure
https://example.com:443/profile?id=6#details
│ │ │ │ │ │
scheme domain port path query fragment
| Part | Example | Purpose |
|---|---|---|
| Scheme | https:// | Protocol type |
| Domain | example.com | Server address |
| Port | :443 | Service port (optional if default) |
| Path | /profile | Resource location |
| Query | ?id=6 | Parameters to server |
| Fragment | #details | Client-side anchor (not sent to server) |
HTTP Message Structure
Start line (method + path OR status code)
Headers (key: value pairs)
(empty line)
Body (optional data)
Pentest Relevance
- HTTP traffic = visible to intercepting proxy (Burp Suite)
- HTTPS protects from network sniffing, not from server-side bugs
- URL parameters (query strings) = potential injection points
- Always check: is the target using HTTP or HTTPS?