re: Tomcat Security Exposure

From: Adam Manock (abmanock@earthlink.net)
Date: 03/25/02


Date: Mon, 25 Mar 2002 07:28:54 -0500
To: bugtraq@securityfocus.com
From: Adam Manock <abmanock@earthlink.net>


 From the Tomcat-user list, anyone know any more?

>During development and deployment I discovered
>that many types of errors while reading the web.xml
>file would result in the app coming up (at least
>partly), but with no security.
>
>This seems like a serious security exposure in
>a production environment.
>
>I believe this is potentially a serious security
>exposure and suggest that tomcat should never
>allow access to the app if it has any problems
>reading the web.xml file or establishing any of
>the security environment.
>
>Frank Lawlor
>Athens Group, Inc.
>(512) 345-0600 x151
>Athens Group, an employee-owned consulting firm integrating technology
>strategy and software solutions.

Adam



Relevant Pages

  • Re: Adding Front End Security Server
    ... Terry, I understand your concerns and the need for security, but one can ... It a Home User firewall. ... > After reading several articles on the SANS.org website, ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: SImple, easy, secure and cheap database solution for website?
    ... all I did was say more or less what you have above - unfortunately the OP seems to have stamped his feet, thrown his toys about and then stomped out of the room when he didn't get the replies he liked... ... Good help you if you think that security is just a matter if reading some civil service blurb - considering how secure some HMG IT data management has been... ... As for the idiot who thinks he can set up such a system but had to ask how to obtain a file view of a server directory, ...
    (uk.net.web.authoring)
  • Security Job Tracks?
    ... are reading this, I am asking a small favor of all of the "experts" ... there are so many topics in the security arena. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)
  • Auditing in WinXP
    ... and as a result I am reading up furiously on as many ... Local Security Policy, and I would like to know were I can view any of the ... In the Local Security Settings window, ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
    (Security-Basics)
  • Re: Security Issue with Office XP Outlook 2002 SP3
    ... Writing to .Body or .HTMLBody is not restricted and won't fire the security, ... only reading those properties does. ... > transition between the Outlook mail item object handle in VB6 and the ... > equivalent Extended MAPI handle in C code. ...
    (microsoft.public.outlook.program_addins)