PDA

View Full Version : How-TO -> TOMCAT SECURE From WHM you can SETUP TOMCAT, but... The Security/Config?


Mr Sanchez
06-04-2008, 08:05 AM
Hello,

Team POWER setup TOM (surely from WHM >> Manage Plugins).
And he say:

The admin url is http://servername.mydomain.com:8080/
The admin user is root
The admin password is 8IoSnsGqcCS

And he say: "Remember we no support this if you need support in TOM then pay to we US $150 by hour."


Then... Please somebody can help to we?
Is possible give ADMIN + PASSWORD different to each customer? How?But the more important: Security
How avoid by example USERX run command "format disk" from JSP?
How avoid user malicious run command similar to "copy /home/OTHER/USERS to /home/hacker/" ?
Maybe (As in PHP) we need disabled functions?, whom?, how?What we can do with:

The admin user is root
The admin password is 8IoSnsGqcCS

Where we used this?

Any help: THANKS.

We want offert TOMCAT to new customers is all. But we unknow ALL about of security of TOMCAT.

Our VPS run with APACHE PHP-Suexec.
Exist some similar to "Apache TOM-Suexec"? We no believe but our fear is users from TOM/JAVA can read /etc/passwd or some actions similar.

Newly THANKS.

nimbar
06-05-2008, 06:32 AM
Hello, I would suggest you to edit your post and delete that password from it...a forum is not a good place to public such stuff. Good luck with your Tomcat!.
:)

Mr Sanchez
06-08-2008, 05:14 AM
Thanks Nimbar.
(Hablas espaņol?)

Some help to config the "Panel Manager"?