September 29, 2026
curl for Hackers: A Practical Guide to HTTP, APIs & Web Testing
One of my favourite and best tool Iโve ever seen for Web application testing, bug bounty or whether it is testing APIs.

By Cy5ec-rhythm
12 min read
If you are learning cybersecurity, Linux, web security, bug bounty, or even just working with APIs, there is one command you should get comfortable with:
curlcurlAt first, curl looks like a simple command that just opens a URL from the terminal.
But once you start using it properly, you realize that it can do much more.
You can use curl to:
- Send HTTP requests
- Check website responses
- Inspect HTTP headers
- Test APIs
- Send GET and POST requests
- Add custom headers
- Send cookies
- Test authentication
- Upload files
- Download files
- Follow redirects
- Debug HTTP connections
- Reproduce requests captured in Burp Suite
- Automate web requests from the terminal
This is my practical curl handbook. I'm keeping it focused on the commands that are actually useful when working with Linux, networking, APIs, and cybersecurity.
1. What is curl?
curl stands for Client URL.
It is a command-line tool used to transfer data between your machine and a server using different protocols.
The most common one you'll use is:
HTTP / HTTPSHTTP / HTTPSFor example:
curl https://example.comcurl https://example.comThis sends a request to the website and prints the response in your terminal.
That's the simplest possible use of curl.
2. Check if curl is installed
On Kali Linux:
curl --versioncurl --versionYou'll see something similar to:
curl 8.x.xcurl 8.x.xYou can also check where it is installed:
which curlwhich curlExample:
/usr/bin/curl/usr/bin/curlIf it isn't installed:
sudo apt update
sudo apt install curlsudo apt update
sudo apt install curl3. Basic GET Request
The most basic command:
curl https://example.comcurl https://example.comThis performs an HTTP GET request.
Think of it like:
Your Computer
|
| GET /
โ
Web Server
|
| HTTP Response
โ
Your TerminalYour Computer
|
| GET /
โ
Web Server
|
| HTTP Response
โ
Your TerminalIf you want to make it clear that you're using GET:
curl -X GET https://example.comcurl -X GET https://example.comBut normally you don't need -X GET because GET is already the default method.
So this:
curl https://example.comcurl https://example.comis enough.
4. Save the Response to a File
Sometimes the response is too large to read directly in the terminal.
Use:
curl https://example.com -o page.htmlcurl https://example.com -o page.htmlNow check the file:
lslsYou can read it using:
cat page.htmlcat page.htmlOr:
less page.htmlless page.html5. Download a File
Suppose a server provides a file:
curl -O https://example.com/file.zipcurl -O https://example.com/file.zipThe -O option saves the file using the filename from the URL.
For example:
https://example.com/report.pdfhttps://example.com/report.pdfwill normally be saved as:
report.pdfreport.pdf6. Download With Your Own Filename
You can choose the filename yourself:
curl -o report.pdf https://example.com/file.pdfcurl -o report.pdf https://example.com/file.pdfHere:
-o โ output filename-o โ output filename7. Show HTTP Response Headers
This is one of the most useful things when doing web security.
Use:
curl -I https://example.comcurl -I https://example.comExample output:
HTTP/2 200
content-type: text/html
server: nginx
strict-transport-security: max-age=31536000HTTP/2 200
content-type: text/html
server: nginx
strict-transport-security: max-age=31536000This lets you quickly inspect things such as:
- HTTP status code
- Server
- Content-Type
- Security headers
- Cookies
- Redirect information
8. Show Headers + Response Body
Use:
curl -i https://example.comcurl -i https://example.comDifference:
-I โ headers only
-i โ headers + body-I โ headers only
-i โ headers + body9. Verbose Mode
When something isn't working, this is one of my first commands.
curl -v https://example.comcurl -v https://example.com-v means verbose.
It gives you more information about the connection.
You can see things like:
* Connected to example.com
> GET / HTTP/2
> Host: example.com
> User-Agent: curl/...
>
< HTTP/2 200
< content-type: text/html* Connected to example.com
> GET / HTTP/2
> Host: example.com
> User-Agent: curl/...
>
< HTTP/2 200
< content-type: text/htmlThis is extremely useful for troubleshooting.
10. Extra Verbose Mode
You can also use:
curl -vv https://example.comcurl -vv https://example.comor:
curl -vvv https://example.comcurl -vvv https://example.comThe more vs you use, the more debugging information curl can provide.
11. Follow Redirects
Imagine you request:
curl http://example.comcurl http://example.comand the server responds:
301 Moved Permanently
Location: https://example.com/301 Moved Permanently
Location: https://example.com/By default, curl doesn't necessarily follow the redirect.
Use:
curl -L http://example.comcurl -L http://example.com-L tells curl to follow redirects.
This is very useful when testing websites.
12. Check the Final URL After Redirects
You can combine:
curl -IL http://example.comcurl -IL http://example.comThis follows redirects while showing headers.
Useful for checking redirect chains.
13. Change the User-Agent
Every HTTP request usually contains a User-Agent.
curl's default might look something like:
curl/8.x.xcurl/8.x.xYou can change it:
curl -A "Mozilla/5.0" https://example.comcurl -A "Mozilla/5.0" https://example.comor:
curl --user-agent "Mozilla/5.0" https://example.comcurl --user-agent "Mozilla/5.0" https://example.comYou can use this when testing how a server responds to different clients.
For example:
curl -A "Googlebot" https://example.comcurl -A "Googlebot" https://example.comOnly do this on systems you're authorized to test.
14. Add Custom Headers
This is extremely important when working with APIs.
Use:
curl -H "Content-Type: application/json" https://example.com/apicurl -H "Content-Type: application/json" https://example.com/apiYou can add multiple headers:
curl \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-H "X-Test: hello" \
https://example.com/apicurl \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-H "X-Test: hello" \
https://example.com/apiThe -H option means:
Add HTTP headerAdd HTTP header15. Authorization Header
APIs commonly use authorization headers.
Example:
curl \
-H "Authorization: Bearer YOUR_TOKEN" \
https://example.com/api/profilecurl \
-H "Authorization: Bearer YOUR_TOKEN" \
https://example.com/api/profileA common format is:
Authorization: Bearer TOKENAuthorization: Bearer TOKENNever publish real API keys or access tokens in a blog post, GitHub repository, screenshot, or command history.
Use placeholders such as:
YOUR_TOKENYOUR_TOKENinstead.
16. GET Request With Query Parameters
Suppose an API expects:
/api/users?id=10/api/users?id=10You can use:
curl "https://example.com/api/users?id=10"curl "https://example.com/api/users?id=10"Multiple parameters:
curl "https://example.com/api/users?id=10&role=admin"curl "https://example.com/api/users?id=10&role=admin"Notice that the URL is inside quotes.
This is especially important when using & in the shell.
17. Using curl's -G
You can also construct query parameters using:
curl -G https://example.com/api/users \
-d "id=10" \
-d "role=admin"curl -G https://example.com/api/users \
-d "id=10" \
-d "role=admin"This produces a GET request with query parameters.
Conceptually:
GET /api/users?id=10&role=adminGET /api/users?id=10&role=admin18. POST Request
Now we get into something much more interesting.
A POST request can send data to a server.
Simple example:
curl -X POST https://example.com/logincurl -X POST https://example.com/loginBut usually you'll also send data.
For example:
curl -X POST \
-d "username=test&password=test123" \
https://example.com/logincurl -X POST \
-d "username=test&password=test123" \
https://example.com/loginHere:
-X POST โ use POST method
-d โ send data-X POST โ use POST method
-d โ send data19. POST Form Data
A typical HTML form might send:
username=test
password=test123username=test
password=test123You can reproduce it with:
curl -X POST \
-d "username=test&password=test123" \
https://example.com/logincurl -X POST \
-d "username=test&password=test123" \
https://example.com/loginThis is useful when learning how web forms actually work.
20. POST JSON Data
Modern APIs commonly use JSON.
Example:
curl -X POST \
-H "Content-Type: application/json" \
-d '{"username":"test","email":"test@example.com"}' \
https://example.com/api/userscurl -X POST \
-H "Content-Type: application/json" \
-d '{"username":"test","email":"test@example.com"}' \
https://example.com/api/usersThe important parts are:
Content-Type: application/jsonContent-Type: application/jsonand:
{"username":"test","email":"test@example.com"}{"username":"test","email":"test@example.com"}21. Pretty-Print JSON
If the server returns JSON, the response can sometimes be difficult to read.
You can pipe it to jq:
curl https://example.com/api/users | jqcurl https://example.com/api/users | jqIf jq isn't installed:
sudo apt install jqsudo apt install jqNow JSON becomes much easier to read.
For example:
curl https://example.com/api/user | jq '.username'curl https://example.com/api/user | jq '.username'This extracts a particular field.
22. Send Data From a File
Instead of writing JSON directly in the command:
curl -X POST \
-H "Content-Type: application/json" \
-d @data.json \
https://example.com/api/userscurl -X POST \
-H "Content-Type: application/json" \
-d @data.json \
https://example.com/api/usersThe @ tells curl to read the request body from a file.
Example data.json:
{
"username": "test",
"email": "test@example.com"
}{
"username": "test",
"email": "test@example.com"
}This is much cleaner for larger requests.
23. Cookies
Cookies are very important when working with authenticated web applications.
You can send a cookie using:
curl -b "session=abc123" https://example.com/dashboardcurl -b "session=abc123" https://example.com/dashboard-b means:
--cookie--cookieYou can send multiple cookies:
curl -b "session=abc123; theme=dark" https://example.com/curl -b "session=abc123; theme=dark" https://example.com/Only use session cookies from systems and accounts you're authorized to test.
24. Save Cookies
You can tell curl to save cookies to a file:
curl -c cookies.txt https://example.comcurl -c cookies.txt https://example.comNow you have:
cookies.txtcookies.txt25. Reuse Cookies
You can then use those cookies later:
curl -b cookies.txt https://example.com/dashboardcurl -b cookies.txt https://example.com/dashboardThis is useful when testing applications that maintain sessions using cookies.
26. Basic Authentication
Some websites use HTTP Basic Authentication.
curl supports it directly:
curl -u username:password https://example.com/curl -u username:password https://example.com/Example:
curl -u admin:test123 https://example.com/admincurl -u admin:test123 https://example.com/adminBe careful with this method because the password may end up in your shell history.
A safer approach is:
curl -u username https://example.com/curl -u username https://example.com/curl will ask you for the password.
27. Form Upload
Suppose a website has a file upload endpoint.
You can send a file using:
curl -F "file=@test.txt" https://example.com/uploadcurl -F "file=@test.txt" https://example.com/uploadFor multiple fields:
curl \
-F "username=test" \
-F "file=@test.txt" \
https://example.com/uploadcurl \
-F "username=test" \
-F "file=@test.txt" \
https://example.com/uploadThis uses multipart form data.
28. HTTP Methods
curl supports different HTTP methods.
GET
curl -X GET https://example.com/apicurl -X GET https://example.com/apiPOST
curl -X POST https://example.com/apicurl -X POST https://example.com/apiPUT
curl -X PUT https://example.com/apicurl -X PUT https://example.com/apiPATCH
curl -X PATCH https://example.com/apicurl -X PATCH https://example.com/apiDELETE
curl -X DELETE https://example.com/apicurl -X DELETE https://example.com/apiThese methods are commonly used in REST APIs.
29. Testing an API Endpoint
A basic API request:
curl https://example.com/api/userscurl https://example.com/api/usersWith JSON response:
curl \
-H "Accept: application/json" \
https://example.com/api/userscurl \
-H "Accept: application/json" \
https://example.com/api/usersWith authentication:
curl \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Accept: application/json" \
https://example.com/api/userscurl \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Accept: application/json" \
https://example.com/api/users30. PUT Request With JSON
Example:
curl -X PUT \
-H "Content-Type: application/json" \
-d '{"name":"Rhythm"}' \
https://example.com/api/users/10curl -X PUT \
-H "Content-Type: application/json" \
-d '{"name":"Rhythm"}' \
https://example.com/api/users/10This is commonly used to update an existing resource.
31. PATCH Request
PATCH is generally used for partial updates.
Example:
curl -X PATCH \
-H "Content-Type: application/json" \
-d '{"name":"Rhythm"}' \
https://example.com/api/users/10curl -X PATCH \
-H "Content-Type: application/json" \
-d '{"name":"Rhythm"}' \
https://example.com/api/users/1032. DELETE Request
Example:
curl -X DELETE \
https://example.com/api/users/10curl -X DELETE \
https://example.com/api/users/10When testing APIs, always understand what the endpoint actually does before sending destructive requests.
Use a lab or an application where you have permission.
33. Check the HTTP Status Code
You can print only the status code:
curl -s -o /dev/null -w "%{http_code}\n" https://example.comcurl -s -o /dev/null -w "%{http_code}\n" https://example.comOutput:
200200This is extremely useful for scripts.
For example:
curl -s -o /dev/null -w "%{http_code}\n" https://example.com/logincurl -s -o /dev/null -w "%{http_code}\n" https://example.com/login34. Show Response Time
You can measure how long a request takes:
curl -o /dev/null -s -w "Time: %{time_total}s\n" https://example.comcurl -o /dev/null -s -w "Time: %{time_total}s\n" https://example.comExample:
Time: 0.421sTime: 0.421sYou can also print several metrics:
curl -o /dev/null -s -w \
"Status: %{http_code}\nTime: %{time_total}s\nSize: %{size_download} bytes\n" \
https://example.comcurl -o /dev/null -s -w \
"Status: %{http_code}\nTime: %{time_total}s\nSize: %{size_download} bytes\n" \
https://example.comThis becomes very useful when writing scripts.
35. Check TLS / HTTPS Information
Use verbose mode:
curl -v https://example.comcurl -v https://example.comYou can see information related to the TLS connection.
For more detailed TLS inspection, tools such as:
openssl s_clientopenssl s_clientare usually more appropriate.
For example:
openssl s_client -connect example.com:443openssl s_client -connect example.com:44336. Ignore Certificate Verification
You might see this option in labs:
curl -k https://example.comcurl -k https://example.com-k tells curl not to verify the server certificate.
This can be useful when working with:
- Local labs
- Test servers
- Self-signed certificates
But don't blindly use -k in real environments.
Certificate verification exists for a reason.
37. Set a Request Timeout
If a server doesn't respond, your command may wait for a long time.
Use:
curl --max-time 10 https://example.comcurl --max-time 10 https://example.comThis means curl can spend a maximum of 10 seconds on the operation.
You can also set a connection timeout:
curl --connect-timeout 5 https://example.comcurl --connect-timeout 5 https://example.com38. Retry Failed Requests
curl can retry some failed requests:
curl --retry 3 https://example.comcurl --retry 3 https://example.comYou can combine this with a delay:
curl --retry 3 --retry-delay 2 https://example.comcurl --retry 3 --retry-delay 2 https://example.comDon't use aggressive retry loops against systems you don't own or aren't authorized to test.
39. Limit Download Speed
You can limit transfer speed:
curl --limit-rate 100K https://example.com/file.zip -o file.zipcurl --limit-rate 100K https://example.com/file.zip -o file.zipThis limits the transfer rate to approximately:
100 KB/s100 KB/s40. Use a Proxy
curl can send requests through a proxy:
curl -x http://127.0.0.1:8080 https://example.comcurl -x http://127.0.0.1:8080 https://example.comThis is especially useful with security testing tools.
For example, if a local HTTP proxy is listening on:
127.0.0.1:8080127.0.0.1:8080you can route the request through it.
41. curl With Burp Suite
This is one of the most useful combinations when learning web security.
If Burp Suite is listening on:
127.0.0.1:8080127.0.0.1:8080run:
curl -x http://127.0.0.1:8080 https://example.comcurl -x http://127.0.0.1:8080 https://example.comNow the request can pass through Burp.
You can inspect:
- Request headers
- Response headers
- Parameters
- Cookies
- HTTP methods
- Server responses
This is a great way to understand what actually happens when a browser communicates with a server.
42. Reproduce a Request From Burp
Suppose Burp gives you a request like:
POST /login HTTP/1.1
Host: example.com
Content-Type: application/json
Cookie: session=YOUR_SESSION
{"username":"test","password":"test123"}POST /login HTTP/1.1
Host: example.com
Content-Type: application/json
Cookie: session=YOUR_SESSION
{"username":"test","password":"test123"}You can reproduce the request using:
curl 'https://example.com/login' \
-H 'Content-Type: application/json' \
-H 'Cookie: session=YOUR_SESSION' \
--data-raw '{"username":"test","password":"test123"}'curl 'https://example.com/login' \
-H 'Content-Type: application/json' \
-H 'Cookie: session=YOUR_SESSION' \
--data-raw '{"username":"test","password":"test123"}'This is one of the biggest reasons I like curl.
Instead of manually interacting with a browser, you can reproduce the exact HTTP request from the terminal.
43. URL Encoding
Suppose you need to send:
hello worldhello worldYou can use:
curl --data-urlencode "q=hello world" https://example.com/searchcurl --data-urlencode "q=hello world" https://example.com/searchcurl handles the encoding.
This is useful for:
- Search parameters
- Form parameters
- Special characters
- Spaces
- User input testing
44. Test Different Parameters
For example:
curl -G https://example.com/search \
--data-urlencode "q=test"curl -G https://example.com/search \
--data-urlencode "q=test"Another example:
curl -G https://example.com/search \
--data-urlencode "q=hello world"curl -G https://example.com/search \
--data-urlencode "q=hello world"This is cleaner than manually encoding spaces and special characters.
45. Inspect Server Headers
A quick way to inspect headers:
curl -I https://example.comcurl -I https://example.comWhen doing basic web security checks, I usually look for headers such as:
Content-Security-Policy
Strict-Transport-Security
X-Content-Type-Options
X-Frame-Options
Referrer-Policy
Permissions-PolicyContent-Security-Policy
Strict-Transport-Security
X-Content-Type-Options
X-Frame-Options
Referrer-Policy
Permissions-PolicyMissing security headers don't automatically mean that a website is vulnerable.
They are only one part of the overall security picture.
46. Check a Website's Response Without Printing the Body
Use:
curl -s -o /dev/null -w "%{http_code}\n" https://example.comcurl -s -o /dev/null -w "%{http_code}\n" https://example.comLet's break it down:
-s โ silent
-o /dev/null โ throw away response body
-w โ print custom information
%{http_code} โ HTTP status-s โ silent
-o /dev/null โ throw away response body
-w โ print custom information
%{http_code} โ HTTP statusThis is extremely useful in shell scripts.
47. Check Multiple URLs
Suppose you have:
urls.txturls.txtcontaining:
https://example.com
https://example.org
https://example.nethttps://example.com
https://example.org
https://example.netYou can use:
while read -r url; do
curl -s -o /dev/null -w "%{http_code} $url\n" "$url"
done < urls.txtwhile read -r url; do
curl -s -o /dev/null -w "%{http_code} $url\n" "$url"
done < urls.txtExample output:
200 https://example.com
200 https://example.org
404 https://example.net200 https://example.com
200 https://example.org
404 https://example.netNow curl becomes part of automation.
48. Check Redirects for Multiple URLs
while read -r url; do
curl -Ls -o /dev/null -w "%{http_code} %{url_effective}\n" "$url"
done < urls.txtwhile read -r url; do
curl -Ls -o /dev/null -w "%{http_code} %{url_effective}\n" "$url"
done < urls.txtThis shows the final URL after redirects.
49. Silent Mode
If you don't want curl to show the progress meter:
curl -s https://example.comcurl -s https://example.com-s means silent.
This is very useful when using curl inside scripts.
50. Silent + Errors
Sometimes completely silent mode hides useful errors.
Use:
curl -sS https://example.comcurl -sS https://example.comThis suppresses the progress meter but still shows errors.
I use this a lot in scripts.
51. Fail on HTTP Errors
Use:
curl -f https://example.com/not-foundcurl -f https://example.com/not-foundIf the server returns certain HTTP error responses, curl can return a failure status.
This becomes useful when you're scripting.
52. Check DNS Resolution
curl itself isn't a replacement for DNS tools, but verbose mode can help:
curl -v https://example.comcurl -v https://example.comFor dedicated DNS investigation, use:
dig example.comdig example.comor:
nslookup example.comnslookup example.com53. Force curl to Use a Specific IP
This is very useful for testing virtual hosts.
curl --resolve example.com:443:192.0.2.10 https://example.com/curl --resolve example.com:443:192.0.2.10 https://example.com/This tells curl:
For example.com on port 443,
connect to 192.0.2.10For example.com on port 443,
connect to 192.0.2.10while still using:
Host: example.comHost: example.comThis can be useful when testing your own servers or lab environments.
54. Specify an Interface
You can tell curl which network interface to use:
curl --interface eth0 https://example.comcurl --interface eth0 https://example.comUseful when your machine has multiple network interfaces.
Check interfaces using:
ip addrip addr55. IPv4 Only
Force IPv4:
curl -4 https://example.comcurl -4 https://example.comIPv6 only:
curl -6 https://example.comcurl -6 https://example.comThis can help troubleshoot networking problems.
56. HEAD vs GET
One thing that confused me when I started was the difference between:
curl -I https://example.comcurl -I https://example.comand:
curl https://example.comcurl https://example.comThe first sends a HEAD request.
The second sends a GET request.
HEAD generally asks for response headers without downloading the response body.
57. HTTP/1.1
You can explicitly request HTTP/1.1:
curl --http1.1 https://example.comcurl --http1.1 https://example.comHTTP/2:
curl --http2 https://example.comcurl --http2 https://example.comThis can be useful when troubleshooting protocol-specific behavior.
58. HTTP Response Headers and Security Testing
For a quick header review:
curl -I https://example.comcurl -I https://example.comFor a complete request/response view:
curl -v https://example.comcurl -v https://example.comFor a saved response:
curl -i https://example.com -o response.txtcurl -i https://example.com -o response.txtThen:
less response.txtless response.txt59. A Practical API Request
Here's a more realistic API example:
curl -X POST 'https://api.example.com/users' \
-H 'Authorization: Bearer YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-d '{
"name": "Rhythm",
"role": "student"
}'curl -X POST 'https://api.example.com/users' \
-H 'Authorization: Bearer YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
-d '{
"name": "Rhythm",
"role": "student"
}'Breaking it down:
-X POST-X POSTMethod.
-H Authorization-H AuthorizationAuthentication.
-H Content-Type-H Content-TypeFormat of our request body.
-H Accept-H AcceptFormat we want back.
-d-dRequest body.
60. My Most-Used curl Commands
If I had to keep only a small list while working in cybersecurity, these would be it:
Basic request
curl https://example.comcurl https://example.comHeaders
curl -I https://example.comcurl -I https://example.comVerbose
curl -v https://example.comcurl -v https://example.comFollow redirects
curl -L https://example.comcurl -L https://example.comCustom header
curl -H "X-Test: hello" https://example.comcurl -H "X-Test: hello" https://example.comPOST data
curl -X POST -d "name=test" https://example.com/apicurl -X POST -d "name=test" https://example.com/apiJSON
curl -X POST \
-H "Content-Type: application/json" \
-d '{"name":"test"}' \
https://example.com/apicurl -X POST \
-H "Content-Type: application/json" \
-d '{"name":"test"}' \
https://example.com/apiCookie
curl -b "session=YOUR_SESSION" https://example.com/dashboardcurl -b "session=YOUR_SESSION" https://example.com/dashboardProxy
curl -x http://127.0.0.1:8080 https://example.comcurl -x http://127.0.0.1:8080 https://example.comStatus code
curl -s -o /dev/null -w "%{http_code}\n" https://example.comcurl -s -o /dev/null -w "%{http_code}\n" https://example.com61. curl + Cybersecurity
This is where curl becomes really interesting.
When you're learning web security, don't think of curl as a "website downloader."
Think of it as a way to manually construct HTTP requests.
A browser might send:
GET /profile HTTP/2
Host: example.com
Cookie: session=...
User-Agent: ...
Accept: application/jsonGET /profile HTTP/2
Host: example.com
Cookie: session=...
User-Agent: ...
Accept: application/jsonWith curl, you can recreate something similar:
curl 'https://example.com/profile' \
-H 'Cookie: session=YOUR_SESSION' \
-H 'Accept: application/json'curl 'https://example.com/profile' \
-H 'Cookie: session=YOUR_SESSION' \
-H 'Accept: application/json'Now you can modify individual parts of the request and observe how the application responds.
That makes curl extremely useful for learning:
- HTTP
- APIs
- Authentication
- Cookies
- Sessions
- Headers
- Request methods
- Web application behavior
- Burp Suite workflows
62. curl and Bug Bounty
If you're doing bug bounty, curl can be useful for manually verifying things you find during testing.
For example:
curl -I https://target.examplecurl -I https://target.exampleCheck headers.
Then:
curl -v https://target.examplecurl -v https://target.exampleInspect the request and response.
For an API:
curl -H "Authorization: Bearer YOUR_TOKEN" \
https://target.example/api/usercurl -H "Authorization: Bearer YOUR_TOKEN" \
https://target.example/api/userFor a POST endpoint:
curl -X POST \
-H "Content-Type: application/json" \
-d '{"test":"value"}' \
https://target.example/api/testcurl -X POST \
-H "Content-Type: application/json" \
-d '{"test":"value"}' \
https://target.example/api/testThe important thing is authorization.
Only test targets that are explicitly within the scope of a bug bounty program, your own infrastructure, or a lab.
63. curl + Burp + Browser
One workflow I recommend for learning web security is:
Browser
โ
Burp Suite
โ
HTTP Request
โ
ServerBrowser
โ
Burp Suite
โ
HTTP Request
โ
ServerThen take the request and reproduce it using:
curlcurlFor example:
curl 'https://example.com/api/user' \
-H 'Authorization: Bearer YOUR_TOKEN'curl 'https://example.com/api/user' \
-H 'Authorization: Bearer YOUR_TOKEN'Then modify one thing at a time.
This helps you understand exactly which part of the request changes the server's response.
64. One Important Tip
Don't memorize every curl option.
Seriously.
There are too many.
Instead, understand the core ones:
-X
-H
-d
-i
-I
-v
-L
-o
-O
-b
-c
-F
-x-X
-H
-d
-i
-I
-v
-L
-o
-O
-b
-c
-F
-xOnce you understand these, most curl commands become easy to read.
And when you forget something:
curl --helpcurl --helpor:
man curlman curlConclusion
When I first started using curl, I thought it was basically a command for downloading things from the internet.
It isn't.
For cybersecurity, curl is basically a small HTTP client that gives you control over the request.
You can control:
Method
Headers
Cookies
Parameters
Body
Authentication
Proxy
Redirects
Protocol
TimeoutsMethod
Headers
Cookies
Parameters
Body
Authentication
Proxy
Redirects
Protocol
TimeoutsAnd that's exactly why it is so useful.
If you're learning cybersecurity, don't just memorize curl commands.
Run them.
Change one parameter.
Look at the request.
Look at the response.
Put the request through Burp Suite.
Break it down.
Once you start doing that, HTTP starts making a lot more sense.
And honestly, that's when curl stops being just another Linux command and becomes one of the tools you actually reach for.
Quick Reference
curl URL
โ
GET request
curl -I URL
โ
Headers only
curl -v URL
โ
Detailed request/connection information
curl -H "Header: value" URL
โ
Custom header
curl -d "data=value" URL
โ
Send data
curl -X POST ...
โ
POST request
curl -b "cookie=value" URL
โ
Send cookie
curl -x proxy URL
โ
Use proxy
curl -L URL
โ
Follow redirects
curl -s -o /dev/null -w "%{http_code}" URL
โ
Get HTTP status code
curl URL
โ
GET request
curl -I URL
โ
Headers only
curl -v URL
โ
Detailed request/connection information
curl -H "Header: value" URL
โ
Custom header
curl -d "data=value" URL
โ
Send data
curl -X POST ...
โ
POST request
curl -b "cookie=value" URL
โ
Send cookie
curl -x proxy URL
โ
Use proxy
curl -L URL
โ
Follow redirects
curl -s -o /dev/null -w "%{http_code}" URL
โ
Get HTTP status code
That's the curl handbook I wish I had when I started learning web security.