Re: svn commit: r701507 - in /tomcat/connectors/trunk/jk/native/common: jk_ajp_common.c jk_ajp_common.h jk_util.c jk_util.h

2008-10-04 Thread Mladen Turk
[EMAIL PROTECTED] wrote: Author: rjung Date: Fri Oct 3 12:37:13 2008 New Revision: 701507 URL: http://svn.apache.org/viewvc?rev=701507view=rev Log: Add retry_wait for AJP13 workers. If a request fails, sleep a configurable time before each following retry. Remember: this has nothing to do with

[EMAIL PROTECTED]: Project jakarta-tomcat (in module jakarta-tomcat) failed

2008-10-04 Thread Stefan Bodewig
To whom it may engage... This is an automated request, but not an unsolicited one. For more information please visit http://gump.apache.org/nagged.html, and/or contact the folk at [EMAIL PROTECTED] Project jakarta-tomcat has an issue affecting its community integration. This issue

Active malware exploits of tomcat manager app

2008-10-04 Thread David Tyler
There are increasing reports starting in July of 2008 and rising through August and September of an active exploit involving the default credentials for the tomcat manager app (not version specific). I am writing to suggest the the tomcat devs take some simple steps to help prevent novice

Re: Active malware exploits of tomcat manager app

2008-10-04 Thread Mark Thomas
David Tyler wrote: Given the widespread and increasing nature of this exploit, I think it would be prudent of the tomcat devs to alter the default installation to disable the tomcat manager by default or otherwise somehow require a non-default password to be set. True, this is not a bug of

[EMAIL PROTECTED]: Project jakarta-tomcat (in module jakarta-tomcat) failed

2008-10-04 Thread Stefan Bodewig
To whom it may engage... This is an automated request, but not an unsolicited one. For more information please visit http://gump.apache.org/nagged.html, and/or contact the folk at [EMAIL PROTECTED] Project jakarta-tomcat has an issue affecting its community integration. This issue