/* garbage httpd, just to see if it works * easily DoSable (like the rest of the network stack), vulnerable to path traversal, etc */ #include #include #include #include #include #include #include #include #include const char *sockpath = "/net/listen/0.0.0.0/tcp/80"; const char *webroot = "/usr/www"; size_t webrootl; static void status(FILE *c, const char *code) { fprintf(c, "HTTP/1.1 %s\r\n\r\n", code); } static void handle(FILE *c) { char buf[2048]; fgets(buf, sizeof buf, c); printf("%s", buf); if (memcmp(buf, "GET /", 5) != 0) { status(c, "400 Bad Request"); return; } char *path = buf + 4; char *end = strchr(path, ' '); if (end) *end = '\0'; if (strlen(webroot) + strlen(path) + 1 <= sizeof(buf)) { memmove(buf + strlen(webroot), path, strlen(path) + 1); memcpy(buf, webroot, strlen(webroot)); } hid_t h = camellia_open(buf, OPEN_READ); printf("%s, %d\n", buf, h); if (h < 0) { status(c, "404 Not Found"); return; } if (path[strlen(path) - 1] != '/') { FILE *f = fdopen(h, "r"); if (!f) { status(c, "500 Internal Server Error"); return; } /* regular file */ status(c, "200 OK"); for (;;) { int len = fread(buf, 1, sizeof buf, f); if (len <= 0) break; fwrite(buf, 1, len, c); } fclose(f); } else { /* directory listing */ DIR *dir = opendir_f(fdopen(h, "r")); if (!dir) { status(c, "500 Internal Server Error"); return; } fprintf(c, "HTTP/1.1 200 OK\r\n" "Content-Type: text/html; charset=UTF-8\r\n" "\r\n" "

directory listing for %s


" "
  • ..
  • ", buf ); struct dirent *d; while ((d = readdir(dir))) { fprintf(c, "
  • %s
  • ", d->d_name, d->d_name); } closedir(dir); } } int main(int argc, char **argv) { int c; optind = 0; while ((c = getopt(argc, argv, "a:r:")) != -1) { switch (c) { case 'a': sockpath = optarg; break; case 'r': webroot = optarg; break; default: fprintf(stderr, "usage: httpd [-a /net/listen/IP/tcp/PORT] [-r path]\n"); return 1; } } for (;;) { hid_t conn = camellia_open(sockpath, OPEN_RW); if (conn < 0) { errx(1, "open('%s') failed, errno %d", sockpath, -conn); } FILE *f = fdopen(conn, "a+"); handle(f); fclose(f); } }