HTTP Header Methods Quick Tutorial 04-19-2013, 11:31 PM
#1
Hi All,
I am back with another "sleep destroyer" okay.. forget that term :huh:
Today I will cover a very important topic that many people tend to overlook. Very important for Web Development/Web Hacking-Cracking/Pentesting/Bruteforcing.
This topic is HTTP Header Methods.
Every web browser sends to a web server (of the website whose address you accessing) some well-formatted data and receives some data in response. The data sent and received is not a random text. It has a rule-bound format that every web-browser and web server is to follow. This set of rules and the system of data transfer through internet is called Hyper Text Transfer Protocol (HTTP). The current version of it is HTTP 1.1.
Suppose, you are on abc.com and you clicked the link def.com. The browser will send this kind of text to the web server of def.com:
The def.com sends a response of this kind to your browser:
Wow! That's a great response! But looks ugly with those HTTP Headers. What does the browser do now?
It strips the header part and renders just this HTML part on the browser window:
Test Scenario:
[table][row][cell]
So now I think you got the point. We can simulate this with a small tool (that hopefully most of you know) is netcat. Lets send the above GET Request to def.com using netcat! :happy:
Now netcat expects you to type something. Type this request as used in example above: (write accordingly the part in <> that is for your help!)
Check out the response you got from web server. Cool right?
Hmm.. so that's the very basics.
[/cell][/row][/table]
There is LOADS of stuff you can do with this info! To give you a good head-on for this topic I am also posting this HTTP Methods Reference table that you can take a copy of if you want. Please note that this is for HTTP 1.1 only.
I will be happy if you like this little post and is useful to you. Please comment if you want to ask or confirm anything. I am sorry if I made any typo/other error here, plz let me know!
miling:
Thanks!
HTTP Methods
[table]
[row]
[cell]Method[/cell]
[cell]Request[/cell]
[cell]Definition[/cell]
[/row]
[row]
[cell]GET[/cell]
[cell]GET <Request-URI>?query_string HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\
[/cell]
[cell]The GET method is used to retrieve whatever is stored or produced by the resource located at the specified Request-URI. The GET method can be used to request files, to invoke server-side scripts, to interact with server-side CGI programs, and more. When HTML form variables are submitted with the form action set to GET, the form parameters are encoded in a query string and submitted to the HTTP server as part of the Request-URI using the GET request method.
[/cell]
[/row]
[row]
[cell]POST[/cell]
[cell]POST <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n
Content-Length: <length in bytes>\r\n
Content-Type: <content type>\r\n\r\n
<query_string or other data to post to Request-URI>
[/cell]
[cell]The POST method is used to submit data to the resource located at the specified Request-URI. Typically, the resource located at the specified Request-URI is a server-side script or CGI program designed to processes form data. When HTML form variables are submitted with the form action set to POST, the form parameters are encoded and submitted to the HTTP server as the body of the POST request message.[/cell]
[/row]
[row]
[cell]HEAD[/cell]
[cell]HEAD <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]"The HEAD method is identical to the GET method except that an HTTP 1.1 server should not return a message-body in the response. The meta-information contained in the HTTP headers in response to a HEAD request should be identical to the information sent in response to a GET request. This method can be used for obtaining meta-information about the entity implied by the request without transferring the entity-body itself. This method is often used for testing hypertext links for validity, accessibility, and recent modification."—Section 9.4, RFC 2616.[/cell]
[/row]
[row]
[cell]PUT[/cell]
[cell]PUT <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n
Content-Length: <length in bytes>\r\n
Content-Type: <content type>\r\n\r\n
<data to put to file>
[/cell]
[cell]The PUT method allows for data to be transferred to an HTTP server and stored at the location identified by the Request-URI.[/cell]
[/row]
[row]
[cell]OPTIONS[/cell]
[cell]OPTIONS <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]"The OPTIONS method represents a request for information about the communication options available on the request/response chain identified by the Request-URI." —Section 9.2, RFC 2616.[/cell]
[/row]
[row]
[cell]DELETE[/cell]
[cell]DELETE <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]"The DELETE method requests that the origin server delete the resource identified by the Request-URI."—Section 9.7, RFC 2616.[/cell]
[/row]
[row]
[cell]TRACE[/cell]
[cell]TRACE <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]"The TRACE method is used to invoke a remote, application-layer loop-back of the request message…. TRACE allows the client to see what is being received at the other end of the request chain and use that data for testing and diagnostic information."—Section 9.8, RFC 2616.[/cell]
[/row]
[row]
[cell]CONNECT[/cell]
[cell]CONNECT <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]The CONNECT message type is used to specify a proxy connection to the resource identified by the Request-URI.[/cell]
[/row]
[/table]
I am back with another "sleep destroyer" okay.. forget that term :huh:Today I will cover a very important topic that many people tend to overlook. Very important for Web Development/Web Hacking-Cracking/Pentesting/Bruteforcing.
This topic is HTTP Header Methods.
Every web browser sends to a web server (of the website whose address you accessing) some well-formatted data and receives some data in response. The data sent and received is not a random text. It has a rule-bound format that every web-browser and web server is to follow. This set of rules and the system of data transfer through internet is called Hyper Text Transfer Protocol (HTTP). The current version of it is HTTP 1.1.
Suppose, you are on abc.com and you clicked the link def.com. The browser will send this kind of text to the web server of def.com:
Code:
GET / HTTP/1.1
Host: def.comThe def.com sends a response of this kind to your browser:
Code:
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 20 Apr 2013 22:05:16 GMT
Content-Type: text/html
Content-Length: 148
Connection: close
<html>
<head>
<title>
This Website is S**t
</title>
</head>
<body>
Welcome to the Worst Website on the Internet!
</body>
</html>Wow! That's a great response! But looks ugly with those HTTP Headers. What does the browser do now?
It strips the header part and renders just this HTML part on the browser window:
Code:
<html>
<head>
<title>
This Website is S**t
</title>
</head>
<body>
Welcome to the Worst Website on the Internet!
</body>
</html>Test Scenario:
[table][row][cell]
So now I think you got the point. We can simulate this with a small tool (that hopefully most of you know) is netcat. Lets send the above GET Request to def.com using netcat! :happy:
Code:
nc -v def.com 80Now netcat expects you to type something. Type this request as used in example above: (write accordingly the part in <> that is for your help!)
Code:
GET / HTTP/1.1 <Press Enter Once>
Host: def.com <Press Enter Twice>Check out the response you got from web server. Cool right?
Hmm.. so that's the very basics.[/cell][/row][/table]
There is LOADS of stuff you can do with this info! To give you a good head-on for this topic I am also posting this HTTP Methods Reference table that you can take a copy of if you want. Please note that this is for HTTP 1.1 only.
I will be happy if you like this little post and is useful to you. Please comment if you want to ask or confirm anything. I am sorry if I made any typo/other error here, plz let me know!
miling:Thanks!
HTTP Methods
[table]
[row]
[cell]Method[/cell]
[cell]Request[/cell]
[cell]Definition[/cell]
[/row]
[row]
[cell]GET[/cell]
[cell]GET <Request-URI>?query_string HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\
[/cell]
[cell]The GET method is used to retrieve whatever is stored or produced by the resource located at the specified Request-URI. The GET method can be used to request files, to invoke server-side scripts, to interact with server-side CGI programs, and more. When HTML form variables are submitted with the form action set to GET, the form parameters are encoded in a query string and submitted to the HTTP server as part of the Request-URI using the GET request method.
[/cell]
[/row]
[row]
[cell]POST[/cell]
[cell]POST <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n
Content-Length: <length in bytes>\r\n
Content-Type: <content type>\r\n\r\n
<query_string or other data to post to Request-URI>
[/cell]
[cell]The POST method is used to submit data to the resource located at the specified Request-URI. Typically, the resource located at the specified Request-URI is a server-side script or CGI program designed to processes form data. When HTML form variables are submitted with the form action set to POST, the form parameters are encoded and submitted to the HTTP server as the body of the POST request message.[/cell]
[/row]
[row]
[cell]HEAD[/cell]
[cell]HEAD <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]"The HEAD method is identical to the GET method except that an HTTP 1.1 server should not return a message-body in the response. The meta-information contained in the HTTP headers in response to a HEAD request should be identical to the information sent in response to a GET request. This method can be used for obtaining meta-information about the entity implied by the request without transferring the entity-body itself. This method is often used for testing hypertext links for validity, accessibility, and recent modification."—Section 9.4, RFC 2616.[/cell]
[/row]
[row]
[cell]PUT[/cell]
[cell]PUT <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n
Content-Length: <length in bytes>\r\n
Content-Type: <content type>\r\n\r\n
<data to put to file>
[/cell]
[cell]The PUT method allows for data to be transferred to an HTTP server and stored at the location identified by the Request-URI.[/cell]
[/row]
[row]
[cell]OPTIONS[/cell]
[cell]OPTIONS <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]"The OPTIONS method represents a request for information about the communication options available on the request/response chain identified by the Request-URI." —Section 9.2, RFC 2616.[/cell]
[/row]
[row]
[cell]DELETE[/cell]
[cell]DELETE <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]"The DELETE method requests that the origin server delete the resource identified by the Request-URI."—Section 9.7, RFC 2616.[/cell]
[/row]
[row]
[cell]TRACE[/cell]
[cell]TRACE <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]"The TRACE method is used to invoke a remote, application-layer loop-back of the request message…. TRACE allows the client to see what is being received at the other end of the request chain and use that data for testing and diagnostic information."—Section 9.8, RFC 2616.[/cell]
[/row]
[row]
[cell]CONNECT[/cell]
[cell]CONNECT <Request-URI> HTTP/1.1\r\n
Host: <hostname or IP address of host>\r\n\r\n
[/cell]
[cell]The CONNECT message type is used to specify a proxy connection to the resource identified by the Request-URI.[/cell]
[/row]
[/table]
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
![[Image: Need-ASP.Net-Expert-with-C2.jpg]](http://axtongroup.com/asp.net-developer/wp-content/uploads/2013/02/Need-ASP.Net-Expert-with-C2.jpg)
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
![[Image: Need-ASP.Net-Expert-with-C2.jpg]](http://axtongroup.com/asp.net-developer/wp-content/uploads/2013/02/Need-ASP.Net-Expert-with-C2.jpg)
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)