POST
17
MENTIONS
6
EPISODES
4
PODCASTS
Search complete. 17 mentions across 6 episodes found for "POST".
Sep 20, 2026
Course 43 - Practical Malware Development | Episode 9: Finalizing Client-Side Command & Control
S
11:10speaker_5HOST
Sure.
S
11:10speaker_4HOST
When we send that payload, we are using an HTTP POST request, right?
S
11:16Steve CovinoADVERTISER
Yes.
S
11:16speaker_4HOST
I hear a lot about GEE requests, like that's what happens every time I type a website into my browser.
S
11:21speaker_4HOST
So why use a POST request here instead of just a simple DUA request?
S
11:26speaker_5HOST
It really comes down to security and payload size.
S
11:29speaker_5HOST
GEE requests append all the data directly into the URL itself.
S
16:08speaker_4HOST
It keeps the heartbeat going no matter what.
Course 43 - Practical Malware Development | Episode 6: Database Foundations and PHP Integration
S
15:37speaker_2HOST
So how does P.O.S.T. fix that?
S
15:39speaker_3HOST
The POST method embeds the data deep within the body of the HTTP request itself.
S
15:44speaker_3HOST
It's like putting your letter inside a thick envelope rather than writing it on the back of a postcard.
S
15:48speaker_2HOST
Okay, so the data travels invisibly behind the scenes.
S
15:51speaker_2HOST
The browser seals it in a POST envelope and sends it to our server.
S
15:55speaker_2HOST
Now, the PH key checks if the request method is POST and if the username and password are set.
S
16:01speaker_2HOST
We use the include function to pull in our con.php tunnel, and we ask the database if this combo exists in the users table.
S
16:09speaker_3HOST
But this exact moment, the moment user input touches the database query, is the most dangerous intersection in web application security.
Cyber Mornings Daily - September 14th, 2026
S
11:51speaker_1HOST
But you also need to review your log files.
S
11:54speaker_1HOST
Look for HTTP POST request to the API v4 projects ID repository commits endpoint.
S
12:01speaker_0HOST
And what are they looking for in those logs?
S
12:02speaker_1HOST
You're hunting for the file dot path parameters to spot exploitation attempts.
Anthropic Threat Report Reveals ShinyHunters Russian and Chinese All Abused Claude for Cyberattacks, GitLab Vulnerability Exploited Just One Day After Disclosure, NSA Reorganizes Into Five Mission Centers
J
4:24James AzarHOST
Now we go to hunt.
J
4:26James AzarHOST
If you're worried about this, you should be pulling logs for HTTP POST requests to a repository commits API path carrying a file path parameter, and any secret that lived on that box is burnt at that point.
J
4:38James AzarHOST
Patching stops to read.
J
4:40James AzarHOST
It doesn't unsteal the key that the threat actors may have gotten their hands on.
Cyber Mornings Daily - September 12th, 2026
S
7:13speaker_0HOST
No.
S
7:13speaker_0HOST
The reporting says defenders need to hunt through their logs for specific HTTP POST requests directed to the repository commits API, specifically looking for payloads containing a file.path parameter.
S
7:26speaker_0HOST
Why that specific parameter? What is that telling us?
S
7:29speaker_1HOST
So that file.path parameter, that is the mechanism of the exploit.
12 MINS LATER
S
19:28speaker_0HOST
Yeah.
S
19:29speaker_0HOST
Attackers were probing for that specific file path payload within hours of disclosure, proving that the window for human reaction is practically gone.
S
19:37speaker_1HOST
Which is your stark reminder to patch immediately, limit public access, and actively hunt through your logs for those specific HTTP POST requests.
S
19:47speaker_0HOST
Absolutely.
Go Web Programming
S
12:08speaker_4HOST
That is a perfect way to explain idempotency.
S
12:10speaker_4HOST
Then, standing in stark contrast to that, we have the POST method.
S
12:14speaker_4HOST
POST is neither safe nor idempotent.
S
12:17speaker_3HOST
POST is the workhorse of the interactive web.
S
12:20speaker_3HOST
You use it when you are actively submitting a form, finalizing a checkout cart, or publishing a comment.
S
12:25speaker_4HOST
Right.
10 MINS LATER
S
22:03speaker_4HOST
The passengers made it to the right terminal.
S
22:05speaker_4HOST
Now the main handler has to unpack the baggage and needs to extract the data the user actually sent.