troubleshooting Question

How do I prevent access to JBoss configuration files?

Avatar of alphawiz1
alphawiz1 asked on
Java App ServersApplication ServersVulnerabilities
6 Comments1 Solution801 ViewsLast Modified:
The company I work for has an application that allows users to view files (PDF's etc).  There is a bug in it that our security audit discovered that allows someone to enter something like ../../datasource-ds.xml   and view the contents of the config files.

This is being fixed by our developers, but I'd like to make sure that the vulnerability doesn't exist in some other way.  How can I lock down the conf and deploy directories so that no one else can do this?  I'm still relatively new to JBoss and could use some help locking things down.

Would putting an .htaccess file in the conf and deploy directories be enough to keep people out of them without impacting application functionality?  

Any suggestions would be appreciated.
ASKER CERTIFIED SOLUTION
btanExec Consultant
Join our community to see this answer!
Unlock 1 Answer and 6 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 6 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros