Re: Tomcat JSP source code disclosure

2008-04-16 Thread Mark Thomas
Christopher Schultz wrote: Mark, Mark Thomas wrote: | My best guess from | the limited information is that you are using httpd and mod_jk and your | configuration isn't secure. Agreed. You should always lock-down Apache httpd by prohibiting access to, say, "*.jsp" in your webapp directory /from

Re: Tomcat JSP source code disclosure

2008-04-16 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mark, Mark Thomas wrote: | My best guess from | the limited information is that you are using httpd and mod_jk and your | configuration isn't secure. Agreed. You should always lock-down Apache httpd by prohibiting access to, say, "*.jsp" in your web

Re: Tomcat JSP source code disclosure

2008-04-16 Thread Mark Thomas
Sameer Naik wrote: Our Tomcat 5.0.28 running on RHEL (2.4.21-32.0.1.ELsmp) is showing source code of JSP if characters %c0%80 are appended to the URL. I could not find a fix for this behavior. I am playing around with caseSensitive and allowLinking directives but did not have any success. Any

Tomcat JSP source code disclosure

2008-04-15 Thread Sameer Naik
(Sorry if this message is posted multiple times. I posted same message couple of times before subscribing to the list, but not sure if it went through) Hi, Our Tomcat 5.0.28 running on RHEL (2.4.21-32.0.1.ELsmp) is showing source code of JSP if characters %c0%80 are appended to the URL. I cou