Re: Security of WEB-INF content

2010-11-01 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Peter, On 10/29/2010 7:57 AM, Mark Thomas wrote: > On 29/10/2010 12:30, Haledor wow wrote: >> Hi, >> >> I have read in various forums that there are situations where the content of >> WEB-INF can be accessed. Some people say that it is good practice t

Re: Security of WEB-INF content

2010-10-29 Thread Mark Thomas
On 29/10/2010 12:30, Haledor wow wrote: > Hi, > > I have read in various forums that there are situations where the content of > WEB-INF can be accessed. Some people say that it is good practice to hide > sensitive files in WEB-INF and some say it might not be... > > I am using Tomcat 6.0 and I a

Security of WEB-INF content

2010-10-29 Thread Haledor wow
Hi, I have read in various forums that there are situations where the content of WEB-INF can be accessed. Some people say that it is good practice to hide sensitive files in WEB-INF and some say it might not be... I am using Tomcat 6.0 and I am worried someone could access some of my sensitive fi