← Learn
Intermediate · Nov 20, 2025

HTTP Internals for Bug Hunting

Headers, cookies, caching quirks, and request smuggling intuition — a mid-level web security primer.

Web Security

The browser is a hostile interpreter.

Most web bugs are misunderstandings between client and server about state, identity, or caching. Learn to read raw HTTP like a primary source.

Capture a login flow. Diff requests. Ask which values are attacker-controlled and which the server trusts without checking.

Secure notes · XSS blocked

Lesson notes

Sign in through the Student Lab app to save plain-text notes. Markup and scripts are blocked in the browser and again on the server.

Checking session…