How HTTP works
TL;DR
An HTTP exchange is a request and a response, both made of a start line, headers, and an optional body. Learn to read them raw and the whole web stops being magic.
What it is
The web runs on HTTP: your client sends a request, the server sends back a response. Every page load, API call and form submit is one of these.
How it works
A request has a method and path (GET /search?q=cat), headers (host, cookies, content-type), and sometimes a body (form data, JSON). The response has a status code, its own headers, and usually a body. The common methods:
- GET — fetch something; parameters ride in the URL.
- POST — send data, usually to change something; parameters in the body.
- PUT / DELETE / PATCH — update and remove, common in APIs.
HTTP is stateless — each request stands alone — so apps use cookies or tokens to remember who you are between requests.
Why it matters for testing
Web testing is reading and changing these requests. A proxy like Burp Suite lets you see and edit every one, which is where most findings start.