Re: Vulnerability on Apache Tomcat Default Files

2020-08-12 Thread FANG YAP
hello chris, they only mention on port 8080 and no other info. I will try that telnet command and see. On Thu, 6 Aug 2020 at 23:20, Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > > Fang, > > On 8/5/20 22:16, FANG YAP wrote: > >

Re: Vulnerability on Apache Tomcat Default Files

2020-08-06 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Fang, On 8/5/20 22:16, FANG YAP wrote: > Did that as well, but the scanner still flagged but it is to say is > a false positive result in their scan? Well, they are complaining that Tomcat is revealing its version number (right?). That's not a fal

Re: Vulnerability on Apache Tomcat Default Files

2020-08-05 Thread FANG YAP
Hi Chris, Did that as well, but the scanner still flagged but it is to say is a false positive result in their scan? Regards with Thanks, Fang On Wed, 5 Aug 2020, 04:21 Christopher Schultz, wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Fang, > > On 8/3/20 23:10, FANG YAP wrot

Re: Vulnerability on Apache Tomcat Default Files

2020-08-04 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Fang, On 8/3/20 23:10, FANG YAP wrote: > I have an issue on the subject mentioned as the vulnerability scan > flagged out. > > Plugin: 12085 Plugin Text: Apache Tomcat Default Files Protocol: > TCP Port: 8080 > > Apache Tomcat 8.5.55 (x64-bit machin

Vulnerability on Apache Tomcat Default Files

2020-08-03 Thread FANG YAP
Hello Apache Tomcat, I have an issue on the subject mentioned as the vulnerability scan flagged out. Plugin: 12085 Plugin Text: Apache Tomcat Default Files Protocol: TCP Port: 8080 Apache Tomcat 8.5.55 (x64-bit machines) In my app folder (located in the webapp folder) I already had the necessar