# HTTP: port 80, requests आणि responses

Source: https://ravindrabagale.com/mr/cyber/part-01/ch02-ports-and-protocols-ssh-http-https-ftp-sftp-and/2-3-http-port-80.html
Language: mr (Marathi with English technical terms)

HTTP हा browser आणि web server यांच्यात संवाद साधण्याचा protocol आहे. Browser request पाठवतो आणि server response देतो. पुढे Part 10 मध्ये Burp Suite शिकताना याच requests चं निरीक्षण करणार आहोत, त्यामुळे त्यांची रचना समजून घ्या.

GET /login.php?next=/profile HTTP/1.1          <- method, path + query, version
Host: shop.example.com                         <- which website (virtual host)
User-Agent: Mozilla/5.0 ...
Cookie: PHPSESSID=8f2c1a...                    <- session identifier
                                               <- blank line, then optional body

HTTP/1.1 200 OK                                <- status line
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=8f2c1a...; HttpOnly
<html> ... </html>

पहिल्या line मध्ये method, path/query आणि HTTP version आहे. Host header कोणती website हवी ते सांगतो. User-Agent client बद्दल माहिती देतो. Cookie मध्ये session identifier असू शकतो. Headers नंतर blank line येते; त्यानंतर गरजेनुसार request body असतो.

Response मध्ये आधी status line, मग headers आणि शेवटी body येतो. Content-Type response कोणत्या प्रकारचा आहे ते सांगतो. Set-Cookie browser ला cookie save/update करायला सांगतो.

HTTP methods

 | Method
 | अर्थ
 | नेहमीचा उपयोग

 | GET
 | Resource वाचणे; URL मधले query parameters
 | Page उघडणे, search

 | POST
 | Body मधून data पाठवणे
 | Login form, upload

 | PUT / PATCH
 | Resource replace / update करणे
 | REST APIs

 | DELETE
 | Resource delete करण्याची request
 | REST APIs

 | HEAD
 | GET सारखं, पण response body नाही
 | curl -I

 | OPTIONS
 | उपलब्ध options/methods तपासणे
 | CORS pre-flight

GET: resource वाचणे; page उघडणे किंवा search. Query parameters URL मध्ये दिसू शकतात.

POST: body मधून data पाठवणे; login form किंवा upload.

PUT/PATCH: resource replace/update करणे; REST APIs मध्ये वापर.

DELETE: resource delete करण्याची request.

HEAD: GET सारखे response headers, पण body नाही; curl -I.

OPTIONS: उपलब्ध communication options/methods; CORS pre-flight मध्येही वापर.

Status codes समजून घ्या

 | Status class
 | अर्थ
 | Examples

 | 1xx
 | माहिती / progress
 | 101 Switching Protocols

 | 2xx
 | यशस्वी
 | 200 OK, 201 Created, 204 No Content

 | 3xx
 | Redirect / cache संबंधित
 | 301 Moved Permanently, 302 Found, 304 Not Modified

 | 4xx
 | Client/request संबंधित error
 | 400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found

 | 5xx
 | Server संबंधित error
 | 500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable

1xx माहिती किंवा progress, 2xx यशस्वी request, 3xx redirect/cache संबंधित responses, 4xx client/request संबंधित error आणि 5xx server संबंधित error दर्शवतात. Table मधले exact codes आणि त्यांचा अर्थ वाचा.

curl -I http://example.com          # only headers
curl -v http://example.com          # full request and response

-I फक्त headers दाखवतो. -v connection आणि request/response बद्दल अधिक माहिती दाखवतो.

Security मध्ये काय धोका असतो?

Plain HTTP encrypted नसतो. Traffic च्या मार्गावर असलेली व्यक्ती किंवा compromised router passwords आणि cookies वाचू शकतो. HTTP स्वतः stateless आहे; app login लक्षात ठेवण्यासाठी cookies/sessions वापरतो. Session cookie चोरीला गेल्यास, इतर protections नसतील तर दुसरी व्यक्ती user म्हणून access मिळवू शकते. अनेक web attacks HTTP requests चा गैरवापर करतात.

Practice

curl -v http://example.com -o /dev/null चालवा. Request line, Host header, status code आणि दोन response headers ओळखा.

रवींद्र बागले यांची tip

401 म्हणजे योग्य authentication credentials मिळालेले नाहीत—उदा. login गरजेचा आहे. 403 म्हणजे server request ला परवानगी नाकारतो; valid login असून permission नसल्यास तो दिसू शकतो. सोपं लक्षात ठेवण्यासाठी authentication आणि authorization मधला फरक समजून घ्या.
