WebApp Sec mailing list archives

Re: Tomcat on port 80 or Java as root


From: Rajkumar S <listuser () myrealbox com>
Date: Fri, 12 Mar 2004 21:17:36 +0530

Marc Deglos wrote:
The question seems to be:
"What are the implications of allowing web traffic to connect directly to Tomcat, instead of through apache?"

Yes, and unlike apache tomcat cannot drop root privilages, so running as root user also is implied.

raj


Current thread: