The HTTP protocol works by accepting various HTTP methods as verbs at the beginning of an HTTP request. While programmers usually only consider GET and POST. If the web application is not developed to handle other types of HTTP requests, then we may be able to this exploit this insecure configuration.

HTTP has 9 different verbs, here are some common ones

VerbDescription
HEADIdentical to a GET request, but its response only contains the headers, without the response body
PUTWrites the request payload to the specified location
DELETEDeletes the resource at the specified location
OPTIONSShows different options accepted by a web server, like accepted HTTP verbs
PATCHApply partial modifications to the resource at the specified location

Insecure coding practices cause the other type of verbs to be accepted when a web developer applies specific filters to mitigate particular vulnerabilities while not covering all HTTP methods.

One way of changing the verb is through Burp via Change Request Method in the right-click dialog. Another way is being is manually specifying the method in curl

curl -i -X OPTIONS http://SERVER_IP:PORT/

Bypass Security Filter

A security filter may only be imposed on specific type of verb, using a different one might lead to bypassing that filter.