Tomcat Symbolic Links
Posted in Techno Stuffs on August 24th, 2008
I found it weird that after all those years that I had been using Tomcat Java Application Server, I had missed its one important security feature - “by default Tomcat does not allow access to symbolic links outside of its web application folder“.
Read the rest of this entry »