# Telnet to view source code

**URL:** <https://boards.straightdope.com/t/telnet-to-view-source-code/307304>\
**Category:** Factual Questions\
**Created:** [June 7, 2005, 4:20pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304 "2005-06-07T16:20:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![SlickRoenick](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@SlickRoenick](https://boards.straightdope.com/u/SlickRoenick)\
**Post date:** [June 7, 2005, 4:20pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/1 "2005-06-07T16:20:46Z")

</div>

Is there any way that i can telnet into my web servers in order to view the source on a page that isn’t published? I barely remember something from my old networking classes that goes like:

```auto

telnet www.whatever.com http
GET HTTP1.0 www.whatever.com/coolpage.htm

```

Since it isn’t working right, i’m sure my syntax is wrong.

---

<div class="post-metadata">

**Author:** ![Metacom](https://avatars.discourse-cdn.com/v4/letter/m/ecae2f/32.png) [@Metacom](https://boards.straightdope.com/u/Metacom)\
**Post date:** [June 7, 2005, 4:29pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/2 "2005-06-07T16:29:56Z")

</div>

The type of telnet session your thinking of is basically just manually typing out the HTTP requests that a web browser would send; in other words, if you can get the page via that method you can get it with a web browser.

---

<div class="post-metadata">

**Author:** ![engineer\_comp\_geek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/engineer_comp_geek/32/504_2.png) [@engineer\_comp\_geek](https://boards.straightdope.com/u/engineer_comp_geek)\
**Post date:** [June 7, 2005, 4:36pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/3 "2005-06-07T16:36:58Z")

</div>

Depends a lot on how your web server is set up. Most web servers these days don’t allow telnet connections. FTP works for most sites though.

---

<div class="post-metadata">

**Author:** ![fiddlesticks](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fiddlesticks/32/18129_2.png) [@fiddlesticks](https://boards.straightdope.com/u/fiddlesticks)\
**Post date:** [June 7, 2005, 4:37pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/4 "2005-06-07T16:37:10Z")

</div>

This worked for me…the bold text is what I typed.

```auto

$ **telnet www.google.com 80**
Trying 66.102.7.147...
Connected to www.google.com.
Escape character is '^]'.
**GET / HTTP/1.1 www.google.com**

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Set-Cookie: PREF=ID=888b11d924129e3b:TM=1118162608:LM=1118162608:S=-5OTXl0QatEXj942; expires=Sun, 17-Jan-2038 19:14:07 GMT; path=/; domain=.google.com
Server: GWS/2.1
Transfer-Encoding: chunked
Date: Tue, 07 Jun 2005 16:43:28 GMT

7c7
<html><head>...

```

For some reason (and I’m sure there is a perfectly logical one) I had to hit Enter twice after the GET line.

However, you can’t use this method to reach a page that can’t be reached via a normal web browser. So if you can’t get to [http://www.somewhere.com/page.html](http://www.somewhere.com/page.html) by typing the address in your browser you won’t be view it via telnet either. All you are doing with this telnet stuff is what your web browser does behind the scenes for you.

---

<div class="post-metadata">

**Author:** ![Shalmanese](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Shalmanese](https://boards.straightdope.com/u/Shalmanese)\
**Post date:** [June 7, 2005, 4:37pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/5 "2005-06-07T16:37:39Z")

</div>

are you telnetting into port 80?

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [June 7, 2005, 4:38pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/6 "2005-06-07T16:38:30Z")

</div>

> [@engineer\_comp\_geek](#):
>
> Depends a lot on how your web server is set up. Most web servers these days don’t allow telnet connections. FTP works for most sites though.

How does the webserver tell the difference between a telnet connection and a browser connection to the same port?

---

<div class="post-metadata">

**Author:** ![Anvil\_Soup](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@Anvil\_Soup](https://boards.straightdope.com/u/Anvil_Soup)\
**Post date:** [June 7, 2005, 4:45pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/7 "2005-06-07T16:45:11Z")

</div>

The HTTP 1.0 syntax would be:

```auto

telnet www.whatever.com http
GET /coolpage.htm HTTP/1.0

```

followed by two carriage returns.

The (more up-to-date) [HTTP 1.1 syntax](http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html) would be:

```auto

telnet www.whatever.com http
GET /coolpage.htm HTTP/1.0
Host: www.whatever.com

```

However, as already noted, there is no difference between doing this and accessing [whatever.com/coolpage.htm](http://whatever.com/coolpage.htm) in a browser, then viewing the page source.

---

<div class="post-metadata">

**Author:** ![Anvil\_Soup](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@Anvil\_Soup](https://boards.straightdope.com/u/Anvil_Soup)\
**Post date:** [June 7, 2005, 4:58pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/8 "2005-06-07T16:58:39Z")

</div>

Arrgh … that second snippet should say 1.1, obviously…

---

<div class="post-metadata">

**Author:** ![Omphaloskeptic](https://avatars.discourse-cdn.com/v4/letter/o/bcef8e/32.png) [@Omphaloskeptic](https://boards.straightdope.com/u/Omphaloskeptic)\
**Post date:** [June 7, 2005, 6:56pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/9 "2005-06-07T18:56:57Z")

</div>

You can also use wget if it’s available on your system. wget basically does the telnet and saves the result to a local file; various options allow you to set the attributes following the GET request line.

> [@Anvil Soup](#):
>
> However, as already noted, there is no difference between doing this and accessing [whatever.com/coolpage.htm](http://whatever.com/coolpage.htm) in a browser, then viewing the page source.

[nitpick]Well, almost no difference. A browser will typically send several other attributes (besides the Host: attribute), such as a User-Agent string (to identify the browser type), Accept\* (acceptable display formats and languages), Cookie, Referer (URL of referring page), etc. Some webservers require acceptable values for some of these attributes (to prevent easy hotlinking or deeplinking) with unacceptable values causing (e.g.) a redirect to the homepage or a no-hotlinks image. You can of course type these in manually if you know what they should be.[/nitpick]

---

<div class="post-metadata">

**Author:** ![Stringer](https://avatars.discourse-cdn.com/v4/letter/s/eb8c5e/32.png) [@Stringer](https://boards.straightdope.com/u/Stringer)\
**Post date:** [June 7, 2005, 7:05pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/10 "2005-06-07T19:05:04Z")

</div>

> [@gazpacho](#):
>
> How does the webserver tell the difference between a telnet connection and a browser connection to the same port?

It doesn’t. I suspect that **engineer\_comp\_geek** meant that the telnet service/daemon on web servers is usually disabled (for security reasons.) But that doesn’t mean you can’t open a terminal to an open port (in this case the HTTP port - 80) and send the expected GET command manually.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [June 9, 2005, 12:09pm UTC](https://boards.straightdope.com/t/telnet-to-view-source-code/307304/11 "2005-06-09T12:09:17Z")

</div>

The OP was asking about viewing the source code of a page, not the rendered result.

Summarizing what others have said …

For 100% static html pages source and rendered result are the same thing. Load the page with a browser & use the browser’s view source feature. No need for telnet.  
For any dynamic pages (ASP, PHP, etc.), the telnet trick just retrieves the page the server generates. That doesn’t get you to the source code of the page in any sense.

In fact, some pages in some technologies are generated entirely by compiled binary code; there is no source page in the traditional web-server sense of a file copied from the server to the browser.

Further, any generated page is dynamic, with the http output stream depending on incoming http attributes, server state, cookies, etc. Unless our intrepid telnet operator knows exactly what the server will do with each of those items, they’ll be hard-pressed to stimulate the server in exactly the same way as their browser would. And even of they got it right, they’d still be looking at a rendered result, not source contents.  
Finally, many modern pages, even if static html files on the server, use browser-side script to modify the DOM after it gets to the browser, or use DHTML. The result is the output as rendered in the browser is different from the output as sent by the server. Normally the view source option in the browser gives you the pre-modification version, ie the DOM stream as delivered from the server before the client-side starts massaging it.  
When you couple dynamic server-side generation with dynamic client-side scripting, the idea that you can “get to the bottom of things” with a tool like telnet is silly. For somebody’s home-brew basic HTML 101 site sure, but not for anything commercial, or even anything built by a modern bot or design tool.
