Re: libapache2-mod-jk2 configuration -- Do NOT do that!

From: Paul D. Bain (paulbain_at_pobox.com)
Date: 06/24/05

  • Next message: Mr Mike: "Re: APT can't recognize Packages.gz?"
    Date: Thu, 23 Jun 2005 20:12:25 -0400
    To: Alan Chandler <alan@chandlerfamily.org.uk>
    
    

    Alan Chandler wrote:
    > I am trying to add tomcat4 into my existing apache2 system so that I can
    > experiment with java (in the form of servlets and jsp).
    >
    > Although in reality I only have a single computer, for learning purposes I
    > want to similate the situation where I have potentially split web and
    > application servers.
    >
    > So this server has two ethernet cards - one facing the outside world with an
    > address assigned by my isp using dhcp. www.chandlerfamily.org.uk points at
    > this address.
    >
    > On the other side, my lan side, I have allocated myself a range of io
    > addresses using eth1 (192.168.0.20) eth1:0 (192.168.0.30) eth1:1
    > (192,168.0.31) as the devices (and their ip addresses) created via iface
    > stanzas in /etc/networking/interfaces.
    >
    > Bind is used to provide different names to the different lan-based ip
    > addresses.
    >
    > An iptables firewall protects the addresses and does NAT.
    >
    > Using Apache2, I then use ip based virtual hosts, so the external address has
    > one web site for http and two of the internal addresses support two other
    > http web sites. https is allocated a further host on the external address to
    > replicate one of the internal sites and providing secure access to webmail.
    >
    > I would like to set up tomcat so that it acts as though it were running on the
    > single ip address 192.168.0.31 (although appropriate requests to my external
    > web site - are routed through to it via apache).

    Alan,

            I am not an expert on network security, but, IIRC, putting a web server
    on the same physical box as a firewall is an incredibly _bad_ idea, at
    least from a security point of view. Why? Well, if your web server is
    compromised (via the box's "external address," as you term it), and if
    the attacker then gains root access to the box on which the web server
    runs (which he can do with a root kit), he can then either (a) attack
    machines that lie _behind_ the firewall (the ones with IP addresses
    beginning with "192.168") or (b) install a packet sniffer to gather
    passwords and other sensitive information. Furthermore, here, you are
    proposing to run not one, but _two_, web servers (Apache and Tomcat) on
    your firewall box, increasing the chances of compromise (simply because
    twice the servers means twice the security vulnerabilities in the server
    software).

            If I were you, I would have a security expert give a quick opinion on
    the soundness of your proposed configuration.

    Sincerely,
    Paul Bain

    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Mr Mike: "Re: APT can't recognize Packages.gz?"

    Relevant Pages

    • Re: WSS v.3 BETA 2 - FQDN REQUIRED for external access?
      ... I know that's bad but again this is a test server. ... I just get "page cannot be displayed" and in the firewall log only the pop-up ... Web Site http://bobfox.net ... login window and it shows up in the firewall log as an "allow", ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: outside Access to IIS server
      ... I created, with your help, a virtual server that answers to the right address. ... I also need him to have the ability to do an ODBC connection and to run CDONTS. ... > I am having a gentleman, emhasis on MAN and not kid, working on my web site. ... If you have a firewall, it would be easy to allow him VPN (even a simple ...
      (microsoft.public.inetserver.iis)
    • Re: Firewall problem
      ... So the firewall ... generally don't allow programs to have server rights. ... If you have an IIS Web server running on the machine as an example and you ... making a solicitation to the Web site for traffic. ...
      (alt.comp.anti-virus)
    • Re: publishing web with symantec 320 firewall
      ... >how cononfigure symantec sgs 320 publishing a web site on a server in the ... >I tried configuring inbound rule http but it does'nt work. ... Are you on the _outside_ of the firewall trying to publish to a web ...
      (comp.security.firewalls)
    • Re: CEICW fails at firewall config
      ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
      (microsoft.public.windows.server.sbs)