–POST /cgi-bin/login.pl?id=1234 HTTP/1.1
–Host: www.my.site
–Content-Length: 21
–
–user=admin&pass=AdMiN
•
• Attacks can take place in one or more of the following components:
•
•HTTP
headers (+method and protocol designation)
•
•path
component
•
•request parameters