Re: Question on Tomcat 4

2003-11-27 Thread Eduardo Campoy
ecureCookie" in tomcat4, as there is no "un-secure" mode. Perhaps a tomcat 3 guru like Senor Barker can fill in more information... Yoav Shapira Millennium ChemInformatics >-Original Message- >From: Eduardo Campoy [mailto:[EMAIL PROTECTED] >Sent: Wednesday, Novembe

Re: Question on Tomcat 4

2003-11-26 Thread Bill Barker
mcat4, as there is no "un-secure" mode. Perhaps a tomcat 3 guru like Senor Barker can fill in more information... Yoav Shapira Millennium ChemInformatics >-Original Message- >From: Eduardo Campoy [mailto:[EMAIL PROTECTED] >Sent: Wednesday, November 26, 2003 11:33 AM >

RE: Question on Tomcat 4

2003-11-26 Thread Shapira, Yoav
guru like Senor Barker can fill in more information... Yoav Shapira Millennium ChemInformatics >-Original Message- >From: Eduardo Campoy [mailto:[EMAIL PROTECTED] >Sent: Wednesday, November 26, 2003 11:33 AM >To: [EMAIL PROTECTED] >Cc: Jason Rivard >Subject: Question on T

Question on Tomcat 4

2003-11-26 Thread Eduardo Campoy
Hello, I am using Tomcat 3.3.1 with Internet Web Application and after doing a ETHICAL HACKING TEST, they discovered a problem in Tomcat session cookie (JSESSIONID). After reading Tomcat 3.3.2 manual , there is a atribute called "secureCookie" that resolve my issue. BUT tomcat 3.3.2 is not releas