LEARN16 min+75 XP

Log Formats & Parsing

In this lesson you'll build a solid conceptual foundation before moving into hands-on practice. Read through the material carefully — the knowledge check at the end of this module will test your understanding.

Key concepts covered: • How the underlying system works at a protocol level • Common misconfigurations attackers look for • Defensive controls and how they can be bypassed • Real-world examples from public disclosures

Take notes. The best security practitioners are the ones who understand *why* something works, not just *that* it works.

terminal
// Example: Inspecting a raw HTTP request
GET /api/user?id=1 HTTP/1.1
Host: target.example.com
Cookie: session=abc123
Authorization: Bearer eyJ...

// What can an attacker learn from this?
// 1. The endpoint accepts an 'id' parameter
// 2. Session tokens are in cookies (CSRF risk)
// 3. JWT in Authorization header (check for weak signing)