Mastodon Mastodon Mastodon Mastodon

HyperText Transfer Protocol [HTTP]

Updated: · CyberSecureFox Editorial Team

HTTP (Hypertext Transfer Protocol) is the application protocol that browsers, apps and servers use to request and deliver web pages, files and API data.

How HTTP works

HTTP is a request-response protocol. A client sends a request with a method (GET, POST, PUT, DELETE and others), a URL and headers; the server answers with a status code (200 OK, 301 redirect, 404 not found, 500 server error), headers and a body. HTTP is stateless: each request stands alone, so cookies and tokens are used to keep users logged in.

  • HTTP/1.1 – text-based, still widely used (RFC 9112);
  • HTTP/2 – binary, many requests over one connection (RFC 9113);
  • HTTP/3 – runs over QUIC on UDP for faster connections (RFC 9114).

HTTPS is HTTP inside an encrypted TLS connection, authenticated with a certificate from a certificate authority.

Why HTTP matters for security

Plain HTTP travels unencrypted, so anyone on the network – for example on public Wi-Fi – can read or change it. That is why browsers now mark HTTP sites as “Not secure” and major sites use HTTPS only. HTTP itself is also an attack surface:

  • request smuggling and desync attacks between proxies and servers;
  • header injection, open redirects and cookie theft;
  • denial-of-service tricks such as the HTTP/2 Rapid Reset attack (2023), which enabled record-size DDoS attacks.

Best practices

  • Serve every site over HTTPS and enable HSTS so browsers never fall back to HTTP.
  • Set security headers: Content-Security-Policy, X-Content-Type-Options, secure and HttpOnly cookies.
  • Keep web servers, proxies and CDNs updated.
Synonyms:
Hypertext Transfer Protocol