8 ms·
Nweb: a tiny, safe web server (static pages only)
- inconshreveable 13y agoFor those of you who are interested in a tiny, safe, static file server that provides secure, public URLs from any machine (ngrok-style), I have a simple project called srvdir that will probably be useful to you: https://srvdir.net https://srvdir.net
- mo 13y agoNice, but the writing suggests that it's secure as in end-to-end encryption, what people expect from HTTPS, while in fact you tunnel everything in plain through a central server. You should make this clear on the site.
- Codhisattva 13y agoNot a prank!
- oracle2025 13y agoThis is actually the first thing I thought, after having a quick look at this code, and being aware of todays date ;-)
- theboss 13y agoThe only thing safer about this that I see is it is extremely small. No high assurance design, etc. What am I missing here that makes them advertise its safety?
- fmela 13y agoJust because the code is tiny doesn't mean that it is safe. How do we know that the code is not vulnerable to e.g. buffer overflow exploit?
- kedean 13y agoI find your comment particularly funny, because in the information security course I took for my masters degree, we had to perform remote buffer overflow exploits using an older version of this exact software.
- dfc 13y agoI am always on the look out for a small, lightweight and secure web server for impromptu file sharing. Right now I use publicfile from djb.[^1] My only complaint is that there is no debian package for publicfile so I have to build my own package. I would love to find an equivalent (ftp not necessary) daemon that is included in debian. Is anyone aware of a something in debian repos that I am overlooking? [^1]: http://cr.yp.to/publicfile.html http://cr.yp.to/publicfile.html
- justincormack 13y agoWebfsd is in the Debian repos but the stupid person who packaged it created an init script for it as if you want to run it as a service rather than ad hoc. So you may as well build from source...
- davidw 13y agoOr you could contribute something back and file a bug report, or maybe even a patch allowing people to use it either way. Certainly beats insulting someone you don't even know who was trying to make the world a little bit better by doing some free work.
- deleted 13y ago[deleted]
- pmahoney 13y agoThis is hardly in the category of "lightweight and secure", but for impromptu stuff, this Ruby+Rack one-liner serves directory listings and static files from the current directory: ruby -e 'require "rack"; include Rack; \ Server.start :app => Directory.new(".", \ Static.new(nil, :urls => ["/"], :root => "."))'
- dylz 13y agopython -m SimpleHTTPServer
- 13y ago
- nthitz 13y agohttp://www.ibm.com/developerworks/systems/library/es-nweb/sidefile1.html http://www.ibm.com/developerworks/systems/library/es-nweb/si... Direct link to the (200 lines of) source code. I can't speak to the security, but it is a nice little read.
- evmar 13y agoThis code is really not good, and certainly not worth learning from. It appears that if you request a path like "//etc/foobar" with two slashes at the front it'll allow traversal outside the starting directory, though it's mitigated by checking file extensions.
- JasonFruit 13y agoThat may be, but the docs are quite nice; people who can write better code might still gain from considering how they can make their documentation this instructive.
- tptacek 13y agoAdding to what everyone else has said, this also "how not" to write socket code; for instance, the assumption that you can read a whole HTTP request "in one go" with a single large read call is false. Also, casting function calls to (void) is nonsensical. You can perhaps forgive the sprintf() call because, AIX. (Believe it or not, there was a time when snprintf was a portability problem). You can't forgive the log() function that doesn't explicitly bounds check its argument (though it's not exploitable in this code).
- wyager 13y ago> Also, casting function calls to (void) is nonsensical. Does extremely pedantic C require the results of function calls to be used? I know the correct way to mark a variable as unused is to cast it to void, but I'm not sure if you're supposed to do that for function return values as well.
- theseoafs 13y agoNothing about the cast is "required". However, it's good practice because the cast explicitly acknowledges the function has a return value that we're throwing out. Looking at the following function call: (void)create_widget(&widget); It's clear that `create_widget` returns some value -- it's probably an error code that tells us whether the widget creation was successful. The source code here says "I know this function returns an important value, but I'm going to disregard it here". This could be useful for debugging if you find that, for example, an error condition is being handled improperly (e.g. "oh, we're obviously throwing out the return value of this function, which we shouldn't be doing"). This function call is much less informative: create_widget(&widget);
- tptacek 13y agoIt's a terrible and (I think) amateurish practice that misapprehends the point of C's type checking while adding lots of visual noise, which is why you'll virtually never see it in well-liked C code.
- cgh 13y ago
- pblakeney 13y agoMy C is a little rusty, but it seems like this web server is definitely not safe. The very first function in the code has a local stack variable and uses sprintf() to fill it. That's almost a textbook example of a buffer overflow vulnerability, if I'm not mistaken. Even if they try and compensate for that by checking the data length before it's passed to that function, it's still scary to see someone using sprintf() instead of snprintf() these days. It's like walking a tightrope without a net.
- nknighthb 13y agoIt's scary style (and speaking of style, this code is really inconsistent in its formatting), but from a quick search of the usages of the logger function, I didn't see any way to overflow the buffer. * BUFSIZE is 8096. * logbuffer (the local variable) is BUFSIZEx2 * s1 looks like it's always trusted and an order of magnitude smaller than BUFSIZE. * The format strings and numbers are nowhere near big enough to make up the difference. * Where s2 is untrusted data, I think it's always guaranteed to be <=BUFSIZE and zero-terminated. But there are definitely other possible issues I haven't looked at closely, and I'm certainly troubled that this mess has showed up on an IBM site as an example of a "safe" web server.
- Rzor 13y agoI want to learn a bit about web servers and I think that study the source code of a functional one may worth more than try to build something from scratch at first glance. Since I'm seeing too many comments on the security issues of this particular project, can you guys recommend something more reliable? Thanks in advance. Edit: I "know" C and C++ and would like to remain in one of these languages, if it's not asking too much.
- pjmlp 13y agoIf you care about security then C and C++ are out of the game, specially if there is a team of different skill sets involved. Having said this, have a look at Wt and Poco http://www.webtoolkit.eu/wt http://www.webtoolkit.eu/wt http://pocoproject.org http://pocoproject.org
- dmoreno 13y agoTry also libonion: https://github.com/davidmoreno/onion https://github.com/davidmoreno/onion It is not a HTTP server, but a library to create your own ones. With many examples, as a trivial only share files at https://github.com/davidmoreno/onion/blob/master/examples/basic/basic.c https://github.com/davidmoreno/onion/blob/master/examples/ba...
- jrochkind1 13y agotoday i learned: there's still AIX. Huh, really?
- kokey 13y agoYup. Banks still have lots of these, and Solaris is being phased out more actively than AIX.
- elf25 13y agotry MacHTTP instead.
- rsync 13y agoDoes this do SSL ? If not, there is no reason to use this instead of the (excellent) thttpd. thttpd is a very, very nice tool. It's very handy sometimes to just fire up thttpd -d /some/dir because you want to look at the contents of the dir in a web browser but don't want to spin up the whole environment and server, etc. I put thttpd on a lot of informal servers just to have it around when I need something like that...
- Pitarou 13y agoThis is not intended for real world usage. Its purpose is to help others learn how web servers work.
- kragen 13y agoA few months ago, I wrote httpdito, a tiny web server that serves static pages only. It's about the same amount of code as nweb, but less functionality, and I have more confidence in its security: http://canonical.org/~kragen/sw/dev3/server.s http://canonical.org/~kragen/sw/dev3/server.s, with README at http://canonical.org/~kragen/sw/dev3/httpdito-readme http://canonical.org/~kragen/sw/dev3/httpdito-readme. It's 296 instructions. I'm not saying it's secure, but I certainly intended it to be, and it doesn't suffer from the particular problems tptacek, evmar, kedean, and nknighthb identify in nweb. I'd like to think I'm not naïve enough to have written problems like that, but that's probably not true. (I'm pretty sure that "Try my new secure software!" is something that should not be followed with "I wrote it in C!" but usually assembly language is not going to be an improvement. In this case I think it happens to be.) httpdito was discussed on HN a bit before it was finished; for example, it's no longer completely trivial to DoS it, although I could do more to protect it against that.
- chm 13y agoThis crowd is always tough to please. There's a description at the top which says, about the 200 loc http server: You can see exactly what it can and can't do. Thank you Mr. Griffiths. Your example will help extend my understanding of an http server, even if I don't intend on writing one. I would never read through the 90 klocs of httpd.
- ChuckMcM 13y agoI always enjoy articles that reiterate how the simple stuff really is pretty simple. I like thttpd for that reason, its a really simple (and a bit more featureful) webserver than this one, but not by a lot. Easy to comprehend, easy to keep all the moving pieces in your head in one piece. Folks building embedded stuff have been using this stuff to create their UIs for like forever it seems, and this kind of web server works pretty well in that capacity. [1] http://www.acme.com/software/thttpd/ http://www.acme.com/software/thttpd/
- steventhedev 13y agoIf I had infinite time and patience, I'd tinker with this to show the differences in socket code, specifically with the approaches outlined in the C10k document. Although it was largely unfinished, the approach outlined in C10m would be interesting to see implemented here (via the intel user-space driver).
- stefs 13y ago> if LINUX sleep for one second to ensure the data arrives at the browser can someone explain that please?
- Pitarou 13y agoIt's explained further down: After the last byte of the file is sent, the nweb web server web() function stops for one second. This is to enable the file contents to be sent down the socket. If it immediately closes the socket, some operating systems do not wait for the socket to finish sending the data but drops the connection very abruptly. This would mean that some of the file content would not get to the browser, and this confuses the browser by waiting forever for the last bit of the file and often results in a blank web page being displayed.
- stefs 13y agoah, sorry - i just read a part and ctrl+f'd for this, but searched for the wrong terms apparently. would this cause connection timeouts if copying data to the socket took longer than one second? i'm always a bit sceptical when i encounter such seemingly arbitrary timing assumptions.
- kragen 13y agoThis text has an error rate of about one factual error per sentence, as you'd expect from someone who capitalizes "Linux" as if it were an acronym.
- Pitarou 13y agoWe're definitely in "works on my machine" territory here. Still it's good for building your confidence as a programmer, no?
- reustle 13y agoAll you really need is > python -m SimpleHTTPServer
- adultSwim 13y agoThis is a great example of how to clearly document a project. The technical criticisms are confirmation of that. How many HN submissions to open source projects are as well explained?
- abimaelmartell 13y agoThe code is ugly, checkout https://github.com/cesanta/mongoose https://github.com/cesanta/mongoose (GPL & MIT) or https://github.com/sunsetbrew/civetweb https://github.com/sunsetbrew/civetweb (GPL)