Win a copy of Penetration Testing Basics this week in the Security forum!
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic

global.jsa source viewable?!!?

Scott Nesin
Posts: 1
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
I'm using JRun 3.0 Service Pack 2a, Version 3.02a.11614 running on a Windows 2000 server.
I'm using a global.jsa file to initialize some classes, in particular, I'm creating a list of database connection strings. This is all working perfectly.
However, if I key in the URL to the global.jsa file directly, it sends the SOURCE of the code to the browser! This includes the database connection strings, usernames and passwords!
As you can imagine, this is not good. Is there a way to prohibit JRun from serving up requests for global.jsa files? Is there a trick around this?
Thanks for any help,
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic