Python Simple HTTP Server: Quick File Sharing and Testing
Python includes a built-in module, http.server (or SimpleHTTPServer in Python 2), that allows you to quickly spin up a basic HTTP server. This server serves files from the directory it’s started in. It’s incredibly useful for:
- Quickly sharing files within a local network (e.g., in a Capture The Flag scenario to host a payload).
- Locally testing static web content (HTML, CSS, JavaScript).
- Debugging network requests or verifying connectivity.
- Providing a temporary web server for various tasks where a full-featured web server is overkill.
Basic Usage
To start a simple HTTP server, navigate to the directory you want to serve and run the command, specifying a port.
sudo python3 -m http.server 80Command Breakdown:
sudo: Running on port80(or any port below1024) typically requires root privileges on Linux/Unix systems.python3: Specifies the Python 3 interpreter. Usepythonifpython3is not linked orpythonpoints to Python 2.-m http.server: Tells Python to run thehttp.servermodule as a script.80: The port number on which the server will listen for incoming HTTP requests. If no port is specified, it defaults to8000.
Common Variations and Examples
Serving on a Different Port (e.g., 8000)
If you don’t need to run on a privileged port (like 80 or 443), you can use a higher port number, often without sudo.
python3 -m http.server 8000Serving with Python 2 (Legacy)
If you are in an environment with Python 2, the module name is different.
python -m SimpleHTTPServer 8000Serving from a Specific Directory
The server serves files from the current working directory. To serve files from a different directory, cd into that directory first.
# Example: serve files from the 'payloads' subdirectory
cd payloads
python3 -m http.server 8080Security Considerations
WARNING: This is a simple server designed for development and testing, NOT for production environments.
- No Security Features: It lacks authentication, encryption (HTTPS), request filtering, or other security mechanisms.
- Exposure Risk: Never expose this server to the public internet or untrusted networks, especially if the served directory contains sensitive files.
- Privilege Escalation: If you serve from
/or other sensitive locations and it’s exploited, it could lead to privilege escalation or data exposure.
Use this tool responsibly and always be aware of the security implications.