The C code in the "framework" this thing uses is pretty scary; grep for MAX_BUFFER_SIZE, malloc, strcpy, &c. The header parsing in particular.
q3k@nihilism ~/Projects/longs $ python2 -c "print 'GET / HTTP/1.1.\r\n' + 'a'*2000 + '\r\n\r\n'" | nc 127.0.0.1 1337
q3k@nihilism ~/Projects/longs $ PORT=1337 ./longs
*** Error in `./longs': free(): invalid next size (normal): 0x000000000155a5f0 ***
...
Sounds like a fun heap exploitation challenge. Almost CTF-like.EDIT: It also throws a whole bunch of warning when compiling. [moved this here from the first line after child post mention]
The compilation warnings was an additional remark, I should've phrased that post better.
[1] - https://github.com/riolet/longs/blob/master/wafer.c#L334-337
I don't have much experience with C outside of embedded systems, so my security practices in C are probably less than ideal for PC/server based code.