| ★ wanayoo — archive 1999 http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html | Nouvelle recherche | Portail wanayoo |
![]() |
| |||||||||||||
|
|
|
|||||||||||||
| ||||||||||||||||||||||||||||||||||
|
CERT Advisory CA-2000-02 CERT Advisory CA-2000-02 (Malicious Scripting Tags Embedded in Client Web Requests) discusses how malicious scripts can be introduced into dynamically generated web pages based on unvalidated input from untrustworthy sources (typically web browsers). Most of the advisory addresses issues concerning browsers and web site developers. The portion of the advisory that concerns web servers has to do with dynamically generated pages that the web server may install by default. Java Web Server ships with some example servlets and CGI scripts that dynamically generate content and could potentially be exploited because they echo portions of the URL that invoked them back to the browser. The core functionality of Java Web Server is secure -- it is only the examples that need to be addressed. While only a couple of the examples could be exploited we have always recommended that all examples and unnecessary servlets be disabled before deploying Java Web Server into a production environment. This not only addresses the recent CERT advisory, but also makes Java Web Server more secure and efficient in general. We reiterate that recommendation here. Removing Examples and Unnecessary ServletsJava Web Server 2.0:
Java Web Server 1.1.3
In the Java Web Server administration applet (under "Setup"), remove the following Servlet Aliases:
/ca/servlet CA
/loganalyzer loganalyzer
/sessionSSL.html sessionSSL
Under "Servlets" remove the following: certAuthority loganalyzer sessionSSL For More Information
For further information on securing a Java Web Server web site see:
www.sun.com/software/jwebserver/techinfo/security_howto.html
|
|||||||||||||||||||||||||||||||||
Java Web Server : Overview | Key Features | FAQ | Download | ||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||