2 ms·
> In Computer Science, for example, there are many concepts that are commonly assumed to be beyond the abilities of mere mortals: protocols, cryptography, and w
by Natsu 1y ago
> In Computer Science, for example, there are many concepts that are commonly assumed to be beyond the abilities of mere mortals: protocols, cryptography, and web servers come to mind.
This baffles me, because a basic HTTP/1.0 server is about 20 lines of printing certain human-readable text over a socket in Perl, and I'm not cheating by just importing a library that does all the things.
I know because I have a www.pl script sitting around that I've frequently using for testing and such. I'm sure it violates various parts of the RFCs in different ways, but... sometimes that's what I'm testing anyway, and when I do want it to work, it simply prints file contents over a socket with a content-type header based on the file extension. It's even smart enough not to be vulnerable to directory traversal (i.e. it'll only serve files from the content directory), etc.
Sure, that's in some sense cheating by leaving out a lot of hard parts from HTTP/1.1 or 2.0, but really, you're just reading a string coming over a network socket, responding with another string, and then closing the connection with HTTP/1.0. You're really just worried about printing out the right thing in response to input from the client.
It's not magic and it's not even very complicated. At least crypto has a lot of formulas to keep track of, timing attacks to worry about, etc. You can have a simple web server that's too dumb to be vulnerable to most web attacks with a few lines of scripting, most of which involve formatting strings and printing them.
- immibis 1y agoFWIW you're also allowed to close the connection in 1.1, but you have to send a header saying you're doing so. You also don't have to, as it's not that hard to allow pipelining.
- Natsu 1y agoSure, you can just send Connection: close but that's not generally what people want, because they might have take a hit to latency by establishing another SSL connection.