wwwrun user on UnitedLinux 1.0

2003-06-19 Thread Hayo Schmidt
I have installed an Apache Tomcat/4.1.24-LE-jdk14 on a UnitedLinux 1.0 (UL) system (which is very much alike to SuSE Linux 8.x). UL contains a Tomcat 4.0 distribution. UL also has a custom startup script /etc/init.d/tomcat. The script starts Tomcat with a user wwwrun: su wwwrun -c "$TOMCAT_HOME/b

Re: wwwrun user on UnitedLinux 1.0

2003-06-19 Thread John Turner
Its never a good idea to run public services as root, which is probably why the script chooses another username. There are only a few known vulnerabilities in Tomcat, and none are related to Tomcat running as root, though I guess there's always the chance someone will find one. A couple of thi