Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Jetty Vulnerabilities?

 
Thread Tools Search this Thread
Old 06-08-2005, 10:12 PM   #1
Default Jetty Vulnerabilities?


Hi,
The Jetty HTTP server is supposed to be more secure and robust than
APACHE, Tomcat. Is there any place where i could find what attacks
Jetty is vulnerable to and if there are any holes which would
compromise the security of the web applications.

Thanks.



Clementine
  Reply With Quote
Old 06-08-2005, 10:41 PM   #2
Unruh
 
Posts: n/a
Default Re: Jetty Vulnerabilities?
"Clementine" <> writes:

>Hi,
>The Jetty HTTP server is supposed to be more secure and robust than
>APACHE, Tomcat. Is there any place where i could find what attacks
>Jetty is vulnerable to and if there are any holes which would
>compromise the security of the web applications.


If they knew what holes there were they would presumably be plugged.
Certainly the known holes in apache are plugged. It is the unknown holes
that are the problem. And you will have a hard time finding a list of the
unknown holes.



Unruh
  Reply With Quote
Old 06-09-2005, 03:07 AM   #3
Winged
 
Posts: n/a
Default Re: Jetty Vulnerabilities?
Clementine wrote:
> Hi,
> The Jetty HTTP server is supposed to be more secure and robust than
> APACHE, Tomcat. Is there any place where i could find what attacks
> Jetty is vulnerable to and if there are any holes which would
> compromise the security of the web applications.
>
> Thanks.
>

http://secunia.com/product/376/

They only show one unfixed vulnerability relating to directory
transversal and reading of arbitrary files on the web server that has a
partial fix. in 3.0/4.0. This is considered a medium critical flaw that
has not been patched. The vulnerability has been open since March 04.
They don't appear to have a great record fixing the issue since it
occurred inversion 3.x and 4.0 and in excess of a year old. That said,
it may be they can't fix the vulnerability due to how the product operates.

I would have to weigh the criticality and data exposure against my needs
before I used it. I would be very careful in my considerations with
mission critical, sensitive applications, or with private data. But
Jetty might be ideal for an easy to use/maintain application for
inter-office/ subnet communications for example.I would not use this for
any server requiring medium to high security.

Looking at the numbers it will not handle industrial strength workloads
but for light loads it appears to be more than adequate.

Not sure how valuable my feed back is as I have never "used" the
product. I will remedy this as I have just downloaded the product to
get familiar with. There may be niches jetty might be useful for. Thanks,

Winged




Winged
  Reply With Quote
Old 06-09-2005, 10:20 PM   #4
Clementine
 
Posts: n/a
Default Re: Jetty Vulnerabilities?
Thanks winged!
>I would not use this for any server requiring medium to high security.


I tried some of the XSS attacks and SQL injections in my own network
which uses a jetty server and I can say it does a good job of escaping
HTML and javascript even in its error pages and takes care of other
things which make such servers vulnerable. I'm not quite sure if this
server is more secure than Tomcat and other servers...but looks pretty
good.



Clementine
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer Security Information and What You Can Do To Keep Your SystemSafe! Ann.Anderson.group.com@gmail.com A+ Certification 0 12-06-2007 01:55 AM
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 02:11 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46