Bug#493645: ITP: nostromo -- small, simple, fast and secure httpd

This is a discussion on Bug#493645: ITP: nostromo -- small, simple, fast and secure httpd within the Debian forums, part of the Linux category; Package: wnpp Severity: wishlist Owner: Kai Hendry * Package name : nostromo Version : 1.8.6 Upstream Author : Marcus Glocker * URL : http://www.nazgul.ch/dev.html * License : MIT Programming Lang: ...

Go Back   Unix Linux Forum > Unix > Linux > Debian

FixUnix.com - Unix Linux Forums

Unix Content Register FAQ Calendar Search Today's Posts Mark Forums Read
  #1  
Old 08-03-2008, 04:20 PM
Default Bug#493645: ITP: nostromo -- small, simple, fast and secure httpd

Package: wnpp
Severity: wishlist
Owner: Kai Hendry

* Package name : nostromo
Version : 1.8.6
Upstream Author : Marcus Glocker
* URL : http://www.nazgul.ch/dev.html
* License : MIT
Programming Lang: C
Description : small, simple, fast and secure httpd

Runs as a single process, handling connections with select. For CGIs
and directory listing it forks. Supports HTTP/1.1, CGI/1.1, chroot,
setuid, basic authentication, SSL, IPv6, custom repsonses, aliases, and
virtual hosts.


A prerelease test version of the package resides on:
http://hendry.iki.fi/debian/unstable

Seems smaller than lighttpd and looks on first impressions more secure
than thttpd. At least nicer looking code. I have in mind embedding
nhttpd on small low powered devices.

-- System Information:
Debian Release: lenny/sid
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: i386 (i686)



--
To UNSUBSCRIBE, email to debian-bugs-dist-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply With Quote
  #2  
Old 08-04-2008, 06:40 PM
Default Re: Bug#493645: ITP: nostromo -- small, simple, fast and secure httpd

On Sun, 2008-08-03 at 21:09 +0100, Kai Hendry wrote:
> Package: wnpp
> Severity: wishlist
> Owner: Kai Hendry
>
> * Package name : nostromo
> Version : 1.8.6
> Upstream Author : Marcus Glocker
> * URL : http://www.nazgul.ch/dev.html
> * License : MIT
> Programming Lang: C
> Description : small, simple, fast and secure httpd


"Secure"? Even though it allows parent directory traversal? As has
been said time and time again, Debian doesn't need yet another tiny
httpd that inevitably turns out to have such flaws.

It doesn't get URI decoding right either.

Ben.

--
Ben Hutchings
Nothing is ever a complete failure; it can always serve as a bad example.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQBIl4RN79ZNCRIGYgcRAiJZAJ4k0j3GEXjPbx/r4uNu3dTIOJysdgCfZcFt
pPnrvGcFTbpv9RXKVBuXpdQ=
=DjGk
-----END PGP SIGNATURE-----

Reply With Quote
  #3  
Old 08-25-2008, 03:10 AM
Default Re: Re: Bug#493645: ITP: nostromo -- small, simple, fast and securehttpd

> On Sun, 2008-08-03 at 21:09 +0100, Kai Hendry wrote:
> > Package: wnpp
> > Severity: wishlist
> >
> > * Package name : nostromo
> > * URL : http://www.nazgul.ch/dev.html
> > Programming Lang: C
> > Description : small, simple, fast and secure httpd

>

[..]
> As has been said time and time again, Debian doesn't need yet another
> tiny httpd that inevitably turns out to have such flaws.


For those who needs to choose a (light) webserver, this page is meant to
gather pros and cons of each one :
http://wiki.debian.org/WebServers

(Contributions are welcome.)

Franklin


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply With Quote
  #4  
Old 08-25-2008, 04:40 AM
Default Re: Re: Bug#493645: ITP: nostromo -- small, simple, fast and securehttpd

On Mon, Aug 25, 2008 at 08:43:16AM +0200, Franklin PIAT wrote:

> For those who needs to choose a (light) webserver, this page is meant to
> gather pros and cons of each one :
> http://wiki.debian.org/WebServers
>
> (Contributions are welcome.)


Both boa and lighttpd require much more installed size than apache2?
Interesting.

--
Tzafrir Cohen | tzafrir@jabber.org | VIM is
http://tzafrir.org.il | | a Mutt's
tzafrir@cohens.org.il | | best
ICQ# 16849754 | | friend


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply With Quote
  #5  
Old 08-27-2008, 05:10 PM
Default Re: Re: Re: Bug#493645: ITP: nostromo -- small, simple, fast andsecurehttpd

> On Mon, Aug 25, 2008 at 08:43:16AM +0200, Franklin PIAT wrote:
>
> > For those who needs to choose a (light) webserver, this page is meant to
> > gather pros and cons of each one :
> > http://wiki.debian.org/WebServers
> >
> > (Contributions are welcome.)

>
> Both boa and lighttpd require much more installed size than apache2?
> Interesting.


Funny... Unfortunately Lenny's apache2.2-common now depends on perl so
it's wrong ;-(

Franklin


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply With Quote
  #6  
Old 08-27-2008, 05:40 PM
Default Re: Re: Re: Bug#493645: ITP: nostromo -- small, simple, fast andsecurehttpd

On 27-Aug-08, 16:06 (CDT), Franklin PIAT wrote:
> > On Mon, Aug 25, 2008 at 08:43:16AM +0200, Franklin PIAT wrote:
> >
> > > For those who needs to choose a (light) webserver, this page is meant to
> > > gather pros and cons of each one :
> > > http://wiki.debian.org/WebServers
> > >
> > > (Contributions are welcome.)

> >
> > Both boa and lighttpd require much more installed size than apache2?
> > Interesting.

>
> Funny... Unfortunately Lenny's apache2.2-common now depends on perl so
> it's wrong ;-(


Yeah, but perl is pretty much required on Debian anyway, so shouldn't
count against it.

OTOH, the lighttpd includes all its modules, and might have more
functionality than Apache2 without any of its optional modules. Or not;
I've not done a detailed look.

Anyway, I'm not sure "package install size" is all that interesting a
comparison number; the main reason for looking at variant webservers is,
I'd guess, memory usage. Of course, that's a pain to quantify.

Steve


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply With Quote
  #7  
Old 08-28-2008, 11:50 AM
Default Re: Bug#493645: ITP: nostromo -- small, simple, fast andsecurehttpd

Steve Greenland wrote:
> On 27-Aug-08, 16:06 (CDT), Franklin PIAT wrote:
>> > On Mon, Aug 25, 2008 at 08:43:16AM +0200, Franklin PIAT wrote:
>> >
>> > > For those who needs to choose a (light) webserver, this page is

>> meant to
>> > > gather pros and cons of each one :
>> > > http://wiki.debian.org/WebServers
>> > >
>> > > (Contributions are welcome.)
>> >
>> > Both boa and lighttpd require much more installed size than apache2?
>> > Interesting.

>>
>> Funny... Unfortunately Lenny's apache2.2-common now depends on perl so
>> it's wrong ;-(

>
> Yeah, but perl is pretty much required on Debian anyway, so shouldn't
> count against it.


> Anyway, I'm not sure "package install size" is all that interesting a
> comparison number;


Yes... Unless you want to build a tiny (debian-live) system (about 35Mb)
for netbooting.

Franklin



--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply With Quote
Reply

Thread Tools


All times are GMT -5. The time now is 11:22 PM.

In an effort to better serve ads to our visitors, cookies are used on Fixunix.com. For more information, check out our Privacy Policy.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Ad Management by RedTyger