tools:http-headers
Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
tools:http-headers [2025/09/12 14:01] – created Humphrey Boa-Gart | tools:http-headers [2025/09/30 22:44] (current) – external edit 127.0.0.1 | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== HTTP Headers ====== | ====== HTTP Headers ====== | ||
- | {{wst>expand}} | + | **HTTP headers** are key-value pairs of metadata sent in HTTP requests and responses, by both the client //(such as your web browser)// and the server //(such as the AMI's [[tools: |
+ | |||
+ | HTTP headers are processed by the client application and the web server, and are usually invisible to the end user. Data sent as HTTP headers includes, but is not limited to: | ||
+ | |||
+ | * How information sent through the connection is encoded. | ||
+ | * Compatibility & version information about the client & server | ||
+ | * Cache control | ||
+ | * Session verification & authentication | ||
+ | * Remote access policies | ||
+ | |||
+ | By understanding how HTTP headers work, you can begin to manipulate HTTP transmissions. | ||
+ | |||
+ | |||
+ | ===== Manipulating Headers ===== | ||
+ | |||
+ | Manually changing the values HTTP headers is fairly easy to do, and provides for some tactical opportunities on the field. Spoofing your [[diy: | ||
+ | |||
+ | Header security is also a thing! Many websites are poorly developed, and use client-defined HTTP headers to delegate access to the system. The way to defend against this is making sure header inputs are sanitized and tested against spoofed headers, but not everyone does it. Poke around with your browser' | ||
+ | |||
+ | Consult the articles below for more thorough information on other header types you can screw with. | ||
+ | |||
+ | |||
+ | ===== Further Reading ===== | ||
+ | |||
+ | Since a full writeup on HTTP headers is beyond the mission of the //Anonymous Military Institute//, | ||
+ | |||
+ | * [[wp>List of HTTP header fields]] on Wikipedia | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
{{tag> | {{tag> |
tools/http-headers.1757685704.txt.gz · Last modified: (external edit)
Find this page online at: https://bestpoint.institute/tools/http-headers
Find this page online at: https://bestpoint.institute/tools/http-headers