Bashttpd - An http server in bash
github.com
github.com
A very simple js frontend sends get requests to wwwoosh, and some bash commands get executed to control a relays board that turns the lights on and of.
It's very simple, consumes almost no memory and is very reliable.
I'm somewhat saddened to see that they don't own dd.sh domain anymore. It was at least twice as cute as no.de is :)
In a demonstration of genius he then proceeded to shutdown this particular forkbomb, using - you guessed it - only dd and sh ...
foo="hello world"
echo $foo # prints "hello world" [2 arguments]
echo "$foo" # prints "hello world" [1 argument]
Note that you can't trivially inject a command this way, though you can inject arbitrary arguments: foo="; ls"
echo $foo # prints "; ls"
I would recommend never using test ([) with more than three arguments. Once you start doing -a and -o, then people can inject confusing values for variables, making it impossible to parse: foo='!'
bar='2'
[ "$foo" = 1 -a "$bar" = 2 ] # -bash: [: too many arguments
Since test runs a subprocess, it can't tell the difference between data and arguments. Instead, you should do something like this: foo='!'
bar='2'
[ "$foo" = 1 ] && [ "$bar" = 2 ]
(This also has the advantage of being way more legible.) [[ "$foo" = 1 && "$bar" = 2 ]]I've pushed the change to use /usr/bin/env bash :-)
Presuming env is in /usr/bin, thus obviating the compatible argument somewhat.
The only catch is that you need to rig up a key, it being SSL and all. -nocert probably won't play nicely with your browser.
http://lock.cmpxchg8b.com/certificate/hello.sh.html (source: http://bit.ly/mGCVks)
I proposed an internal web api at work for some hardware that needed to call out and test an address against a database of known problems. The initial response was the pain of setting up the infrastructure of a web server just for this one thing, was "huge" except it isn't really huge, its like 12 lines of perl or python code. People need to know that you can do that to see the pocket web server as a neat solution.
People might say that this is utterly useless, but actually in one big companies I worked for we had something like this (not really http but still bash server) to execute and control tests running on the machine. The beauty of the bash is that runs on 100% clean servers which is great for product testing.
That makes it worth it :-)
It also gets people thinking, being creative and doing something "fun". Sometimes you just have to do fun things and see where they lead.
Also, regarding environment sandboxing: it's probably worth looking at the direction the CGI spec went in.
Which makes it a bit imprecise to call it a web server made with bash (as it requires netcat). I clicked on the title already wondering how would it be possible to open a socket with bash only.