HTTP requests can include methods beyond GET and POST. As a penetration tester, it is important to determine which other HTTP verbs (that is, methods) the web server allows. Support for other verbs may disclose sensitive information (for example, TRACE) or allow for a dangerous invocation of application code (for example, DELETE). Let's see how Burp can help test for HTTP verb tampering.
Testing for HTTP verb tampering
Getting ready
Using OWASP Mutillidae II, let's determine whether the application allows HTTP verbs beyond GET and POST.
How to do it...
- Navigate...