Intermediate · Nov 20, 2025
HTTP Internals for Bug Hunting
Headers, cookies, caching quirks, and request smuggling intuition — a mid-level web security primer.
Web Security
The browser is a hostile interpreter.
Most web bugs are misunderstandings between client and server about state, identity, or caching. Learn to read raw HTTP like a primary source.
Capture a login flow. Diff requests. Ask which values are attacker-controlled and which the server trusts without checking.
Secure notes · XSS blocked
Lesson notes
Sign in through the Student Lab app to save plain-text notes. Markup and scripts are blocked in the browser and again on the server.
Checking session…