7 ms·
Lon.gs: A URL shortener in C
- andrew3726 10y agoWebsite seems down (connection refused). Did you use any network library (aside from native, I mean)?
- tcdent 10y agoIs the website actually the URL shortener, or some other stack? I think it's highly unlikely HN just C10K'd them.
- fideloper 10y agot2.nano has CPU credits, they may have gotten spent and we're now seeing the results of throttling (limit on % cpu allowed to use)
- chadscira 10y agoWell it is entirely possible that a single HN user C10K'd them
- andrew3726 10y agoseems more like it just wasn't accessible using https (http works just fine).
- tux3 10y agoNote that if you have an extension like HTTPS Everywhere, you might have to disable it. At least I could only connect to plain HTTP.
- andrew3726 10y agoThanks, didn't think of that!
- vmarsy 10y agothe URL creation and the browsing of a short URL definitely works fast, I guess this being on the front page is a cheap way to verify if the C10k claims are true!
- nodesocket 10y agoSeems great and performant, but not productized. Seems like things are hard-coded in the c code. For example... What are the api endpoints? docs? Can you view a list of all shortened urls? Can you delete shortened urls? Can you change the base domain of lon.gs?
- nxzero 10y agoOddly, was hoping this was a way to turn URLs into long URLs; 2,083 characters if you want to support all the web clients.
- nomel 10y agoThere are many, like http://longurlmaker.com http://longurlmaker.com. I find http://shadyurl.com http://shadyurl.com to be more useful in getting people to not click a link though.
- chadscira 10y agoCloudFlare is a perfect companion for something like this because you can hard cache the redirects on their edges. I have a few services that run off tiny boxes, and just leverage CloudFlare free edge caching.
- ianlevesque 10y agoAnd handle an HN influx better than many Wordpress sites.
- nxzero 10y agoShortened a URL, but service doesn't appear to redirect: http://lon.gs/akt http://lon.gs/akt EDIT: Very strange, the redirect now goes to a URL I didn't enter... (http://www.sadfasdfasfdasdfsadfasd.com http://www.sadfasdfasfdasdfsadfasd.com)
- cmdrfred 10y agoIt seems pretty responsive.
- 616c 10y agoPerhaps I am the only one, but is anyone interested in the opposite direction, static site generator like CLI app to do short linking? YOURLS was popular for a while, and I tried it, but I was concerned with running a not very popular PHP app even on shared hosting. At least Wordpress gets decent attention. I was worried of people compromising my own YOURLS instance against me. http://www.cvedetails.com/vulnerability-list.php?vendor_id=11533&product_id=21232&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=0&month=0&cweid=0&order=1&trc=2&sha=59b76e93ee62fd17aa2253076d9777cb4f7d57f6 http://www.cvedetails.com/vulnerability-list.php?vendor_id=1...
- JonathonW 10y agoThere's this, which is a script that manipulates Apache .htaccess to do short linking: http://lucasgonze.github.io/shurl/ http://lucasgonze.github.io/shurl/ No idea about equivalents for nginx, or something that could run on Github Pages (these would probably be the same, given that nginx doesn't have an equivalent to .htaccess out of the box).
- 616c 10y agoI am going to check out shurl, very interesting. It does sound familiar but I cannot remember why. Sometimes I see these things and forget to bookmark them later.
- deleted 10y ago[deleted]
- pslam 10y agoLooking at the coding patterns used in the C source, I am utterly horrified this is running live on a public facing website. I can see at least one buffer overrun dependent on database contents, and I wouldn't be surprised if there's public-facing vulnerabilities in this thing, but I don't want to spend another 5 minutes looking.
- efnor 10y agoJudging by the code, everything that goes into the database is a Base64 encoded. Where do you see a buffer overflow?
- hueving 10y agoDependent on what comes out of the DB, not what goes in.
- zeta0134 10y agoThat still counts as a vulnerability, even if it's not exploitable without also being able to write the correct state into the database. Databases almost always contain user-generated data. I don't trust the data contained therein any more than I trust the user. Validate it every time.
- themihai 10y agoThat sounds a bit too much. The data from db is supposed to be already validated. Do you validate the input received from the validation function as well?(⸮)
- zeta0134 10y agoI'm not saying you need to fully validate the database, but at least making sure the row you're about to read can actually fit in the buffer you just allocated would be a good practice, even if the input validation shouldn't normally allow it. If the database could theoretically hold it according to its schema, the program should be prepared for the largest row size that is still technically legal. (Where "prepared" may simply mean that it throws a "This should never happen" error and aborts the request.)
- alternize 10y agohum. I tried to short "http://lon.gs" http://lon.gs" and then short the result again, now it redirects indefinitely... http://lon.gs/ack http://lon.gs/ack
- deleted 10y ago[deleted]
- tptacek 10y agoThe C code in the "framework" this thing uses is pretty scary; grep for MAX_BUFFER_SIZE, malloc, strcpy, &c. The header parsing in particular.
- q3k 10y agoAgreed. q3k@nihilism ~/Projects/longs $ python2 -c "print 'GET / HTTP/1.1.\r\n' + 'a'*2000 + '\r\n\r\n'" | nc 127.0.0.1 1337 q3k@nihilism ~/Projects/longs $ PORT=1337 ./longs *** Error in `./longs': free(): invalid next size (normal): 0x000000000155a5f0 *** ... Sounds like a fun heap exploitation challenge. Almost CTF-like. EDIT: It also throws a whole bunch of warning when compiling. [moved this here from the first line after child post mention]
- ryanlm 10y agoThat's not a warning. That's a runtime error.
- q3k 10y agoI know, this is some internal glibc allocation code failing because that request overflowed a buffer on the heap. The bug is, as tptacek mentioned, in the header receiving function [1]. The compilation warnings was an additional remark, I should've phrased that post better. [1] - https://github.com/riolet/longs/blob/master/wafer.c#L334-337 https://github.com/riolet/longs/blob/master/wafer.c#L334-337
- tptacek 10y agoNot the only case of this, either.
- longs 10y agoThank you for raising this issue. We're currently working on fixing this. Here's the issue on the [tracker](https://github.com/riolet/longs/issues/6 https://github.com/riolet/longs/issues/6).
- 10y ago
- mwcampbell 10y agoI'm surprised there's still any interest in standalone URL shorteners. Didn't Twitter make them obsolete when it implemented its own?
- tropicalmug 10y agoThere are other needs for a shortened URL. Perhaps you have to hardcode a link in code and don't want to be tied to a page whose contents may break. If you control your URL shortener, you can hardcode your shortened one, and update the redirect as needed.
- hk__2 10y ago> Perhaps you have to hardcode a link in code and don't want to be tied to a page whose contents may break. If you control your URL shortener, you can hardcode your shortened one, and update the redirect as needed. And when your URL shortener goes down, all links are dead. Shortening URLs is the last thing you want to do when you need to preserve pages that might go down. Caching is a better solution.
- morninj 10y agohttp://perma.cc http://perma.cc addresses this problem.
- colemickens 10y agoWhy would one use this over archive.is?
- rsync 10y agoWe[1] just launched a new shortener and it supports URLs. That's not the primary use-case for it[2][3], but we're happy to support people shortening URLs if they want to. The reason there's room for this is that our URL shortening function has no ads, no third party tracking, no bloat ... no dark patterns. That's worth something to some people. [1] Oh By, Inc. [2] https://0x.co/examples.html https://0x.co/examples.html [3] https://0x.co/hnfaq.html https://0x.co/hnfaq.html
- kornish 10y agoSeems a bit buggy. I shortened "http://hello.com" http://hello.com", it returned "lon.gs/akm", and I visited the shortened URL only to be redirected to https://codeandoando.com/integracion-continua-con-drone/ https://codeandoando.com/integracion-continua-con-drone/.
- deleted 10y ago[deleted]
- ratsimihah 10y agothis made my URL longer :/ lon.gs/ae9
- BrainInAJar 10y agoLooks like the perfect way to turn URL's in to root shells on the hosting server
- logicallee 10y agoThis is broken. Here's the short url of http://news.ycombinator.com http://news.ycombinator.com --> lon.gs/amk Going to lon.gs/amk redirects me to an overstock.com address for a specific product. The site doesn't appear to have been hacked, at least there's no affiliate link in the URL I was sent to. It just appears the site is broken.
- Retr0spectrum 10y agoI noticed something similar. I think their id decoding/encoding may be buggy.
- cyphar 10y agoIt looks like their "INSERT OR IGNORE" logic is broken, in that they don't properly retry if they ignored it.
- longs 10y agoThank you for raising this bug. We have fixed it.
- deleted 10y ago[deleted]
- colemickens 10y agoIs anyone suffering from lack of URL shorteners? Or does anyone really care what their URL shortener is implemented in? Is there even any way that the application code contributes to the request time more meaningfully than the persistence mechanism used? Cool hacks are cool I guess but from the sounds of it, the C code is a bit scary. If you had to build this, why not build it in Rust? At least it wouldn't be so terrifying from a security standpoint and you'd still get whatever performance is supposedly needed.
- deleted 10y ago[deleted]
- q3k 10y agoThis code is more than a bit scary. This code is of very poor quality, is very poorly documented and has numerous (I'm pretty confident that they're exploitable, too) bugs. It really isn't a project that I'd recommend to anyone, unless I wanted a shell on their machine. I'm quite distraught that it is getting this many (seemingly blind) upvotes.
- deleted 10y ago[deleted]
- hoov 10y agoI was thinking the same thing and then some. I ask a version of this as an interview question, and this doesn't pass my muster. That being said, I do think that implementing a URL shortener is a really good exercise, and I commend the author for that.
- Retr0spectrum 10y agoOn the subject of code quality: https://www.reddit.com/r/C_Programming/comments/4p5ung/longs_we_wrote_a_url_shortener_in_c_with_wafer/d4iihi7?context=3 https://www.reddit.com/r/C_Programming/comments/4p5ung/longs... (After a few minutes of poking)
- aphextron 10y agobut...but.. it's in C!
- ryanlm 10y agoI consider the fact that it is written in C a feature.
- josteink 10y agoAnd now, reload this entire thread and check all the horrible bugs and security vulnerabilities this so called "feature" got you. This is why you should never use C in networked code or when working with third-party data unless you absolutely bloody well have to: It's just too many ways to fuck up, and most programmers will.
- ryanlm 10y agoYou're forgetting something about networked code. At some layer of the stack it has to be written in C or assembly.
- nomel 10y agoNo he didn't forget. The lower layers, yeah it probably will be in C (but it doesn't HAVE to be). But in the application layer, it probably shouldn't be. If things like memory management are not the first priority when writing every line of code, then you shouldn't be using C, and that's really the only reason you should be using C, when there's a specific need for memory management. Not surprisingly, this is exactly why the world has moved beyond C for the application layer, it's painful to have to think about that stuff constantly, so people just don't (this being an example).
- ryan-c 10y agoFrom https://www.reddit.com/r/C_Programming/comments/4p5ung/longs_we_wrote_a_url_shortener_in_c_with_wafer/d4iihi7 https://www.reddit.com/r/C_Programming/comments/4p5ung/longs... $ curl -i http://lon.gs/abf HTTP/1.1 301 Moved Permanently Location: foo X-Evil-Header: evilvalue there were also examples of XSS and data URIs. (they claim to have fixed this elsewhere in the thread, but I guess some of the "evil" URLs still work)
- knicholes 10y agoWasn't there something posted recently about urls that are too short are too easily guessed and that it's good to make sure that these short urls are longer?
- ryanf323 10y agoThis does not handle Microsoft office URL pre-fetching...and is written in C...
- theseoafs 10y agoIf there are any aspiring crackers looking to bring down their first site, this one should be easier than the average
- didip 10y agoI respect the desire to work on low level language like C. Programmers should not be afraid of it. But that said, building a proper HTTP stack is not trivial. If you want to use C language, then why not create Nginx module? Nginx already solved the hard problems: * HTTP parser * Distribute work via event loop on multiple workers * Useful load balancing strategies (not as great as HAProxy, but i am satisfied with it) * Serious effort in dealing with CVE * Widely used and battle tested Here's a fine guide on how to write Nginx module in C: http://www.evanmiller.org/nginx-modules-guide.html http://www.evanmiller.org/nginx-modules-guide.html
- AdamJacobMuller 10y agohttps://kore.io/ https://kore.io/ is also a (very?) good C framework for this stuff. I don't know enough C to honestly evaluate that though.
- didip 10y agoThanks for sharing, I haven't heard about this framework.
- tptacek 10y agoI disagree, and think that programmers should be very wary of C.
- efficax 10y agoWhy would you write something like this in C anymore? If you really need it to have a tiny memory footprint, write it in rust. If you need it to be fast, but can handle a runtime taking care of memory management, write it in go. C is just asking for trouble anymore.
- nine_k 10y agoLet's look at this project as a cautionary tale.
- zoom6628 10y agoSome comments about comments and the code: 1. The URL shortener is just a demonstration of the framework being used. For a POC/MVP i would not expect it to be the most reliable code on the planet. Im ok with that. 2. The WAFer framework is great idea for bringing a very lite server and minimalist framework to certain devices. This has applications in SBC and IOT devices where all resources are at a premium. 3. Yes the C code might not be perfect but remove any github project that isnt perfect, secure and you wont have many left. The principle objective is 'get it out there' and let people like the other commenters have their input/opinion from which to make it better. 4. The concept and this lite implementation of the idea is hugely useful in certain use cases. Just like nginx is great for general purpose servers. This is almost a C implementation of Bottle for python. 5. nodesocket and chadscira seem to have gotten the point of this and given useful feedback to the authors (Im not one of them in case you were thinking that). So to sum it up - a great post, excellent work with a tool that has a lot of potential for specific scenarios. When deploying if using things like Cloudfare Edge and giving it a bit of Productizing (my day job is as a Product Manager for a global ERP business) then this could be a hit (pun intended :-J ).