tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Dennis Muhlestein <den...@zserve.com>
Subject Re: prohibit stopping tomcat by generic user
Date Tue, 04 Jun 2002 15:14:16 GMT
Even if the permissions are set correctly you could just

telnet localhost 8005 and type SHUTDOWN.

If your worried about users that much, I'd rethink their account on that
box.  And do make sure port 8005 is not available where someone can send
the shutdown command!

-Dennis

On Mon, 2002-06-03 at 17:18, Leland Chen wrote:
> 
> Hi,
> 
>     I have tomcat web server configured run as "nobody",
>     but it can be stoped by any generic user using "shutdown.sh"
>     script. Even the CATALINA_BASE is not set correctly, tomcat
>     web server can be shutdown by any user account.
> 
>     Is there any way to prohibit this ?
> 
>     Thanks,
> 
>     Leland
> 
> 
> 
> <html><DIV>&nbsp;</DIV></html>
> 
> 
> _________________________________________________________________
> Join the worldÂ’s largest e-mail service with MSN Hotmail. 
> http://www.hotmail.com
> 
> 
> --
> To unsubscribe, e-mail:   <mailto:tomcat-user-unsubscribe@jakarta.apache.org>
> For additional commands, e-mail: <mailto:tomcat-user-help@jakarta.apache.org>
> 



--
To unsubscribe, e-mail:   <mailto:tomcat-user-unsubscribe@jakarta.apache.org>
For additional commands, e-mail: <mailto:tomcat-user-help@jakarta.apache.org>


Mime
View raw message