4 ms·
I can explain it: m = n ? /* if (n != 0) */ /* adds index.html if path ends with "/" (means the filename is omitted), otherwise copies zero */
by jpegqs 5y ago
I can explain it:
m = n
? /* if (n != 0) */
/* adds index.html if path ends with "/" (means the filename is omitted), otherwise copies zero */
strcpy(b+i-1,b[i-2]-'/'?"":"index.html"),
/* log the requested filename to stdout */
printf("%s\n",b+5),
/* if "/." is in the path or an error occurred while opening the file */
strstr(b,"/.")||!(f=fopen(b+5,"rb"))
? "404 Not Found"
: "200 OK"
: "501 Not Implemented"; /* if (n == 0) */
By filtering filenames with "/." I prevent exploits with ".." and also don't allow to read files starting with a dot, these are hidden files in Unix-like OS.
- SV_BubbleTime 5y agoAh. I see, figured it might be that but it was tough to read. Ok, so sometimes I think I know C pretty well, then I’ll see lunatic code like this and realize I Do Not! Thanks for the answer and reformat.
- formerly_proven 5y agoWhat about "GET //etc/passwd"?
- NieDzejkob 5y agoJust fired up the server and that does indeed break it. I suppose openat2 with RESOLVE_BENEATH and AT_FDCWD would be a bullet-proof fix, but that's not very codegolf.
- jpegqs 5y agoYes, that's a vulnerability, I have fixed it on github.
- irundebian 5y agoActually it's the job of the operating system to handle file system authorizations. It's just the case that we have shitty default configurations for operating operating systems which allows a lot of ambient authority.
- NieDzejkob 5y agoHuh, any reason to use printf("%s\n",...) instead of puts?
- jpegqs 5y agoThanks, I forgot about that. It would be very helpful to have some extra space for fixes.