19.09.2017 Views

the-web-application-hackers-handbook

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

40 Chapter 3 n Web Application Technologies<br />

HTTP uses a message-based model in which a client sends a request message<br />

and <strong>the</strong> server returns a response message. The protocol is essentially<br />

connectionless: although HTTP uses <strong>the</strong> stateful TCP protocol as its transport<br />

mechanism, each exchange of request and response is an autonomous transaction<br />

and may use a different TCP connection.<br />

HTTP Requests<br />

All HTTP messages (requests and responses) consist of one or more headers,<br />

each on a separate line, followed by a mandatory blank line, followed by an<br />

optional message body. A typical HTTP request is as follows:<br />

GET /auth/488/YourDetails.ashx?uid=129 HTTP/1.1<br />

Accept: <strong>application</strong>/x-ms-<strong>application</strong>, image/jpeg, <strong>application</strong>/xaml+xml,<br />

image/gif, image/pjpeg, <strong>application</strong>/x-ms-xbap, <strong>application</strong>/x-shockwaveflash,<br />

*/*<br />

Referer: https://mdsec.net/auth/488/Home.ashx<br />

Accept-Language: en-GB<br />

User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64;<br />

Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR<br />

3.0.30729; .NET4.0C; InfoPath.3; .NET4.0E; FDM; .NET CLR 1.1.4322)<br />

Accept-Encoding: gzip, deflate<br />

Host: mdsec.net<br />

Connection: Keep-Alive<br />

Cookie: SessionId=5B70C71F3FD4968935CDB6682E545476<br />

The first line of every HTTP request consists of three items, separated by spaces:<br />

n A verb indicating <strong>the</strong> HTTP method. The most commonly used method<br />

is GET, whose function is to retrieve a resource from <strong>the</strong> <strong>web</strong> server. GET<br />

requests do not have a message body, so no fur<strong>the</strong>r data follows <strong>the</strong> blank<br />

line after <strong>the</strong> message headers.<br />

n The requested URL. The URL typically functions as a name for <strong>the</strong> resource<br />

being requested, toge<strong>the</strong>r with an optional query string containing parameters<br />

that <strong>the</strong> client is passing to that resource. The query string is indicated<br />

by <strong>the</strong> ? character in <strong>the</strong> URL. The example contains a single parameter<br />

with <strong>the</strong> name uid and <strong>the</strong> value 129.<br />

n The HTTP version being used. The only HTTP versions in common use<br />

on <strong>the</strong> Internet are 1.0 and 1.1, and most browsers use version 1.1 by<br />

default. There are a few differences between <strong>the</strong> specifications of <strong>the</strong>se<br />

two versions; however, <strong>the</strong> only difference you are likely to encounter<br />

when attacking <strong>web</strong> <strong>application</strong>s is that in version 1.1 <strong>the</strong> Host request<br />

header is mandatory.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!