Python Simple HTTP Server: Quick File Sharing and Testing

Python includes a built-in module, http.server (or SimpleHTTPServer in Python 2), that allows you to quickly spin up a basic HTTP server. This server serves files from the directory it’s started in. It’s incredibly useful for:

  • Quickly sharing files within a local network (e.g., in a Capture The Flag scenario to host a payload).
  • Locally testing static web content (HTML, CSS, JavaScript).
  • Debugging network requests or verifying connectivity.
  • Providing a temporary web server for various tasks where a full-featured web server is overkill.

Basic Usage

To start a simple HTTP server, navigate to the directory you want to serve and run the command, specifying a port.

sudo python3 -m http.server 80

Command Breakdown:

  • sudo: Running on port 80 (or any port below 1024) typically requires root privileges on Linux/Unix systems.
  • python3: Specifies the Python 3 interpreter. Use python if python3 is not linked or python points to Python 2.
  • -m http.server: Tells Python to run the http.server module as a script.
  • 80: The port number on which the server will listen for incoming HTTP requests. If no port is specified, it defaults to 8000.

Common Variations and Examples

Serving on a Different Port (e.g., 8000)

If you don’t need to run on a privileged port (like 80 or 443), you can use a higher port number, often without sudo.

python3 -m http.server 8000

Serving with Python 2 (Legacy)

If you are in an environment with Python 2, the module name is different.

python -m SimpleHTTPServer 8000

Serving from a Specific Directory

The server serves files from the current working directory. To serve files from a different directory, cd into that directory first.

# Example: serve files from the 'payloads' subdirectory
cd payloads
python3 -m http.server 8080

Security Considerations

WARNING: This is a simple server designed for development and testing, NOT for production environments.

  • No Security Features: It lacks authentication, encryption (HTTPS), request filtering, or other security mechanisms.
  • Exposure Risk: Never expose this server to the public internet or untrusted networks, especially if the served directory contains sensitive files.
  • Privilege Escalation: If you serve from / or other sensitive locations and it’s exploited, it could lead to privilege escalation or data exposure.

Use this tool responsibly and always be aware of the security implications.