• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 375
  • Last Modified:

How to prevent .war from being downloaded?

I am new to Java programming and have a web app on my server. I upload it to my public_html folder and it is then automatically deployed.  It works fine that way, except nothing is preventing someone from downloading the .war directly from public_html.  How would I prevent this from happening?

The project is running on tomcat.
2 Solutions
Make the perms on the war file to be readable by the tomcat user only
You must be deploying this a strange way - the war should be placed in the webapps folder in tomcat,which then automatically deploys and expands the webapp contents into a folder, which becomes the context. Tomcat does not allow the war file to be downloaded when this deployment occurs, as the war file is not *inseide* the context folder.
don't deploy it to public_html, thats for html and other publicly accessible resources.
instead setup tomcats webapp directory somewhere that is not accessible (and let tomcat handle serving the files from there)
Cloud Class® Course: Certified Penetration Testing

This CPTE Certified Penetration Testing Engineer course covers everything you need to know about becoming a Certified Penetration Testing Engineer. Career Path: Professional roles include Ethical Hackers, Security Consultants, System Administrators, and Chief Security Officers.

If your war can be downloaded then there is a problem with your setup, by the sound of it you are deploying it in a directory being servered by apache. You do not want to do that, nor do you need to. And things like changing the permissions is not going to help.

Simply moving the location of your webapps directory will fix the problem.
jwarpAuthor Commented:
got it working... thanks!
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now