A web server in a shell script
debian-administration.org
debian-administration.org
For experiments relying on that is fine, but not for anything more serious.
It includes a netcat-based webserver written in bash (that speaks CGI) as well as a Sinatra-like micro "framework" for shell (that also speaks CGI) that lets you do things like this:
get "/DeanMartin.jpg" dean_handler
function dean_handler () {
header "Content-Type" "image/jpeg"
cat "DeanMartin.jpg"
}
Unfortunately I haven't figure out a way to get rid of that placeholder function name (e.x. "dean_handler" above). Ideas?This is one of my favorite bash scripts, it's an IRC bot in about 12 lines:
http://inamidst.com/code/shellbot
It's also pretty easy to add other commands & extend.
I recently had lunch with a friend and I asked him about if he was planning new features their key/value store and I loved his answer: (paraphrased)
I'm a unix-guy. I want small bits of software that does one thing and does it really well.
His point was that software these days is rarely "finished". However in Unix so much of the software are small pieces. Each piece does one job and does it well. Then you can fit those pieces together in all sorts of configurations to do new and interesting things.
sudo apt-get install apache2
sudo vim /usr/lib/cgi-bin/hello_world
sudo chmod a+x $_
Not that much of a hassle.http://en.wikipedia.org/wiki/Comparison_of_lightweight_web_s...
sudo apt-get install lighttpdcd $WEB_DIR; python -m SimpleHTTPServer
for evented goodness.
You don't need OOP for reusability.
In the few cases where scalability matters, you can re-implement the relevant behavior, but that's a performance trade-off.
...
Oh dear. Ohdearohdearohdear.
Now all we need to do is make sure that the first character in $filename is "&" followed by some privilege escalation exploit and ...
(Am I missing something?)
echo none:`date`
echo double: "`date`"
echo single: '`date`'
% foo="& do_evil"
% cat "$foo"
cat: & do_evil: No such file or directory
Now if the request was for the path /../../../../../../etc/passwd ... that's a different story.edit: and with the CGI stuff it might be possible to execute rm or something else dangerous/destructive.