HTTP Protocol Internals & Offensive Semantics
Train an experienced web/API pentester and bug bounty hunter to predict vulnerabilities that arise when two components interpret the same HTTP message differently. Assume fluency with HTTP requests, Burp Suite, common web vulnerabilities, TLS, proxies, APIs and web architecture, and never re-explain them. Use RFC 9110 as the semantic backbone, then RFC 9111, 9112, 9113, 9114, 9204, 9213, 9421, 9530, 9651, 7239 and 6265. Every lesson must state the precise protocol mechanic, distinguish normative HTTP behaviour from implementation behaviour, connect it to real infrastructure (CDN, WAF, load balancer, reverse proxy, API gateway, framework, application), and answer: what could two parsers disagree about here? Show raw request and response bytes rather than describing them. Name real implementations whose behaviour differs. End every lesson with a concrete test the reader can run against a live target and the observable that decides the result. Label claims as established, inferred, or controversial. No fluff, no filler, no generic web-security advice.
11 sections ยท 98 lessons
Course outline
Section 1 - HTTP Semantics as an Attack-Surface Model
- Resources vs Representations: the Identity Layer
- Messages, Content, Metadata, and Application State
- Version-Independent Semantics vs Wire Format
- What Survives Protocol Translation and What Does Not
- Statelessness in HTTP's Model
- Connection-Attached State as Attack Surface
- Reading RFCs Offensively: MUST, SHOULD, and Recipient Requirements
- Extensibility Points, Error Handling, and Ambiguity as Attack Hypotheses
- Exercise: Tracing One Request Through CDN, WAF, LB, Proxy, App
Section 2 - Target URIs, Authority, Host, and Request Routing
- Determining the Target Resource: Scheme, Authority, Path, Query
- The Effective Request URI Across HTTP Versions
- Origin-Form and Absolute-Form Request Targets
- Authority-Form and Asterisk-Form
- Host, :authority, and Virtual-Host Routing
- Duplicate, Conflicting, and Malformed Authority Values
- Forwarded and the X-Forwarded-* Family
- Proxy Trust Reconstruction and Header Spoofing
- Exercise: Building an Authority Mutation Matrix
- Exercise: Locating Where Routing Decisions Are Made
Section 3 - Methods as Security Semantics
- Safe, Idempotent, and Cacheable Are Three Different Properties
- Where Gateways, Caches, and WAFs Guess Wrong About Methods
- GET and HEAD: Retrieval Semantics and Response Divergence
- POST vs PUT vs PATCH: Processing vs Replacement
- DELETE and Request Content Expectations
- OPTIONS, TRACE, and Max-Forwards
- CONNECT and Tunnelling Semantics
- Unknown Methods, Case Sensitivity, and Method Overrides
- GET-With-Body and HEAD Handling Discrepancies
- Exercise: The Method x Body Matrix
- Exercise: Attributing 405 to a Layer
Section 4 - Status Codes, Interim Responses, and HTTP Control Flow
- Status Codes as Machine Instructions, Not Labels
- 301, 302, 303: Method Rewriting on Redirect
- 307 and 308: Method and Body Preservation
- Location Construction, Redirect Caching, and Client Divergence
- Expect: 100-continue and Interim Responses
- Early Rejection and Unread Request Bodies
- 4xx Rejection Taxonomy as Parser Telemetry
- 421, 505, Connection Closure, and Timing as Oracles
- Exercise: One-Property-at-a-Time Malformed Request Families
Section 5 - HTTP Fields, Parsing, Normalization, and Hidden Inputs
- Field Name and Value Grammar
- Repeated Fields, Comma-Combination, and Ordering
- Connection and Hop-by-Hop Fields
- Nominated Headers, Trailers, and Hop Boundaries
- Name-Level Mutations: Case, Underscores, Malformed Names
- Value-Level Mutations: Whitespace, obs-fold, Line Endings, Unusual Bytes
- Structured Fields: Items, Lists, and Dictionaries
- Exercise: Building a Header Mutation Corpus
- Exercise: Recording Accept, Reject, Normalize, Combine, Strip, Rewrite
Section 6 - Representations, Content Semantics, Negotiation, and Ranges
- Representation Metadata vs Message Content
- Content-Encoding vs Transfer-Encoding vs Framing
- Server-Driven Negotiation: Accept, Accept-Encoding, Accept-Language
- Vary and Intermediary Interaction
- ETag, Weak vs Strong Validators, and Last-Modified
- If-Match, If-None-Match, If-Modified-Since, and If-Range
- Range, Content-Range, and 206 Responses
- multipart/byteranges, Overlapping and Malformed Ranges
- Digest Fields: Content-Digest vs Repr-Digest
- Exercise: Are All Layers Examining the Same Representation?
Section 7 - Authentication, State, Identity, and Message Integrity
- WWW-Authenticate, Authorization, and Protection Spaces
- HTTP Authentication vs Application Authentication
- Proxy-Authenticate and Proxy-Authorization
- Identity Boundaries Across Infrastructure Layers
- Cookie and Set-Cookie Parsing and Scoping
- Duplicate Cookies, Ordering, and Legacy Syntax
- RFC 9421 Signed Components and the Signature Base
- Derived Components, Canonicalization, and Coverage Gaps
- Exercise: Modelling Auth as Raw, Interpretation, Canonical, Decision
Section 8 - HTTP Caching as a Security Boundary
- The Cache Model: Storage, Cacheability, Private vs Shared
- Freshness, Age, Heuristics, and Validation
- Cache-Control, s-maxage, and Stale Directives
- Layered Caches: Browser, Framework, Reverse Proxy, CDN
- Cache Key Construction and Unkeyed Inputs
- From Unkeyed Input to Cache Poisoning
- Cache Deception and Path Parser Discrepancies
- Exercise: Reverse-Engineering an Unknown Cache Black-Box
Section 9 - HTTP/1.1 Message Framing and Desynchronization
- Request Lines, Message Boundaries, and Persistent Connections
- Why Body-Length Interpretation Is Security-Critical
- Content-Length vs Transfer-Encoding: Framing Precedence
- Chunked Coding Grammar, Malformed Chunks, and Trailers
- Classic Desync: CL.TE, TE.CL, and TE.TE
- CL.0, 0.CL, and Pause-Based Desync
- Header Smuggling Variants
- Front-End Bypass and Request Tunnelling
- Response Queue Poisoning and Credential Theft
- Exercise: Instrumenting a Two-Server Chain
- Exercise: Distinguishing Desync from Pipelining False Positives
Section 10 - HTTP/2, HTTP/3, Cross-Version Translation, and Novel HTTP Research
- Frames, Streams, and Multiplexing
- Pseudo-Headers and HPACK
- H2.CL and H2.TE: Downgrade Desync
- Pseudo-Header Injection, Request Splitting, and Tunnelling
- HTTP/3 over QUIC: Stream Independence and QPACK
- Connection Coalescing and Authority Assumptions
- A Methodology for Discovering New HTTP Attack Classes
- Micro-Hypotheses, Anomaly Detection, and Differential Evaluation
Section 11 - Capstone: From HTTP Knowledge to HTTP Research
- The Five Questions: Reducing Any HTTP Element to a Differential Test
- Testing Across the Full Chain
- Capstone Steps 1-4: Extract Rules, Generate Inconsistent Interpretations
- Capstone Steps 5-8: Series Testing and Generalising the Primitive