Cyber Security · मराठी आवृत्ती
HTTP: port 80, requests आणि responses
या page मध्ये
HTTP हा browser आणि web server यांच्यात संवाद साधण्याचा protocol आहे. Browser request पाठवतो आणि server response देतो. पुढे Part 10 मध्ये Burp Suite शिकताना याच requests चं निरीक्षण करणार आहोत, त्यामुळे त्यांची रचना समजून घ्या.
GET /login.php?next=/profile HTTP/1.1 <- method, path + query, version
Host: shop.example.com <- which website (virtual host)
User-Agent: Mozilla/5.0 ...
Cookie: PHPSESSID=8f2c1a... <- session identifier
<- blank line, then optional body
HTTP/1.1 200 OK <- status line
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=8f2c1a...; HttpOnly
<html> ... </html>
पहिल्या line मध्ये method, path/query आणि HTTP version आहे. Host header कोणती website हवी ते सांगतो. User-Agent client बद्दल माहिती देतो. Cookie मध्ये session identifier असू शकतो. Headers नंतर blank line येते; त्यानंतर गरजेनुसार request body असतो.
Response मध्ये आधी status line, मग headers आणि शेवटी body येतो. Content-Type response कोणत्या प्रकारचा आहे ते सांगतो. Set-Cookie browser ला cookie save/update करायला सांगतो.
HTTP methods
| Method | अर्थ | नेहमीचा उपयोग |
|---|---|---|
| GET | Resource वाचणे; URL मधले query parameters | Page उघडणे, search |
| POST | Body मधून data पाठवणे | Login form, upload |
| PUT / PATCH | Resource replace / update करणे | REST APIs |
| DELETE | Resource delete करण्याची request | REST APIs |
| HEAD | GET सारखं, पण response body नाही | curl -I |
| OPTIONS | उपलब्ध options/methods तपासणे | CORS pre-flight |
- GET: resource वाचणे; page उघडणे किंवा search. Query parameters URL मध्ये दिसू शकतात.
- POST: body मधून data पाठवणे; login form किंवा upload.
- PUT/PATCH: resource replace/update करणे; REST APIs मध्ये वापर.
- DELETE: resource delete करण्याची request.
- HEAD: GET सारखे response headers, पण body नाही;
curl -I. - OPTIONS: उपलब्ध communication options/methods; CORS pre-flight मध्येही वापर.
Status codes समजून घ्या
| Status class | अर्थ | Examples |
|---|---|---|
| 1xx | माहिती / progress | 101 Switching Protocols |
| 2xx | यशस्वी | 200 OK, 201 Created, 204 No Content |
| 3xx | Redirect / cache संबंधित | 301 Moved Permanently, 302 Found, 304 Not Modified |
| 4xx | Client/request संबंधित error | 400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found |
| 5xx | Server संबंधित error | 500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable |
1xx माहिती किंवा progress, 2xx यशस्वी request, 3xx redirect/cache संबंधित responses, 4xx client/request संबंधित error आणि 5xx server संबंधित error दर्शवतात. Table मधले exact codes आणि त्यांचा अर्थ वाचा.
curl -I http://example.com # only headers
curl -v http://example.com # full request and response
-I फक्त headers दाखवतो. -v connection आणि request/response बद्दल अधिक माहिती दाखवतो.
Security मध्ये काय धोका असतो?
Plain HTTP encrypted नसतो. Traffic च्या मार्गावर असलेली व्यक्ती किंवा compromised router passwords आणि cookies वाचू शकतो. HTTP स्वतः stateless आहे; app login लक्षात ठेवण्यासाठी cookies/sessions वापरतो. Session cookie चोरीला गेल्यास, इतर protections नसतील तर दुसरी व्यक्ती user म्हणून access मिळवू शकते. अनेक web attacks HTTP requests चा गैरवापर करतात.
Practice
curl -v http://example.com -o /dev/null चालवा. Request line, Host header, status code आणि दोन response headers ओळखा.