tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Randy Layman <randy.lay...@aswethink.com>
Subject RE: Security hole
Date Thu, 02 Aug 2001 12:45:44 GMT

	What you are seeing is the AutoSetup component mounting contexts
because it sees these directories and therefore creates the contexts.  Your
best bet is, probably, to go into server.xml and remove the AutoSetup
configuration.  This will disable the auto-mounting or WAR files, however,
so this might not be your best answer if you are using WAR files.

	Randy


> -----Original Message-----
> From: Claus Jul Larsen [mailto:cjlarsen@enovasion.dk]
> Sent: Thursday, August 02, 2001 3:16 AM
> To: Tomcat User (E-mail)
> Subject: Security hole
> 
> 
> Hi,
> 
> I've a strangely problem:
> 
> When I start the tomcat with the ./startup.sh
> 
> Output:
> 
> ----
> 
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( 
> dev.miraculix.dk:
> )
> Starting tomcat. Check logs/tomcat.log for error messages 
> 2001-08-01 11:53:31 - ContextManager: Tomcat classpath =
> /usr/local/jakarta-tomcat/lib/ant.jar:/usr/local/jakarta-tomca
t/lib/jasper.j
> ar:/usr/local/jakarta-tomcat/lib/jaxp.jar:/usr/local/jakarta-t
omcat/lib/pars
> er.jar:/usr/local/jakarta-tomcat/lib/servlet.jar:/usr/local/ja
> karta-tomcat/l
> ib/test:/usr/local/jakarta-tomcat/lib/webserver.jar:/usr/java/
> jdk1.3/lib/too
> ls.jar:/usr/java/jdk1.3
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /admin )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /examples )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx(  )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /test )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /KEYS )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /LICENSE )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( 
> /RELEASE-NOTES )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /bin )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /conf )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /doc )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /lib )
> 2001-08-01 11:53:31 - ContextManager: Adding context Ctx( /src )
> 2001-08-01 11:53:31 - ContextManager: calc work dir
> /usr/local/jakarta-tomcat/work
> 2001-08-01 11:53:32 - PoolTcpConnector: Starting 
> HttpConnectionHandler on
> 8080
> 2001-08-01 11:53:32 - PoolTcpConnector: Starting 
> Ajp12ConnectionHandler on
> 8007
> 
> ----
> 
> But i've only have context for dev.miraculix.dk and no more i 
> server.xml
> 
> The context manager adds /admin /examples /test /KEYS 
> /LICENSE and more.
> These contexts isn't in the Server.xml ... but is still run 
> them ???! I want
> only dev.miraculix.dk on /web-staff/www.miraculix.dk and no 
> more.... This is
> version 3.2.3...
> 
> Thanx
> 
> 
> 
> Med venlig hilsen
> 
>   Claus Jul Larsen
>   |  System Developer
>   |  cjlarsen@enovasion.dk
>   |  Direkte teksttelefon: 7731 2010, ring først til 
>   |  teksttelefoncenteret på 7011 4411 og bed om        
>   |  nummeret.
> 	
>   e|novasion a·s
>   |  store kongensgade 23a
>   |  DK - 1264 københavn k
>   |  tlf: +45 7731 1940  
>   |  fax: +45 7731 1950
>   |  www.enovasion.dk
> 
> 
> > Med venlig hilsen
> > 
> >   Claus Jul Larsen
> >   |  System Developer
> >   |  cjlarsen@enovasion.dk
> >   |  Direkte teksttelefon: 7731 2010, ring først til 
> >   |  teksttelefoncenteret på 7011 4411 og bed om        
> >   |  nummeret.
> > 	
> >   e|novasion a·s
> >   |  store kongensgade 23a
> >   |  DK - 1264 københavn k
> >   |  tlf: +45 7731 1940  
> >   |  fax: +45 7731 1950
> >   |  www.enovasion.dk
> > 
> > 
> 

Mime
View raw message