Re: Limiting RMI to localhost



On Jun 30, 3:12 pm, Lew <l...@xxxxxxxxxxxxx> wrote:

Simply block the RMI port with the firewall from non-localhost access.  You'll
have to look the port up, I don't remember which one it is off the top of my
head.  It'll be a different port than the ones you expose "in the server process".

This is an OS-specific operation, but most Windows "personal firewall"
products and any Linuxen have the capability.

--
Lew

Thanks for the answer.
I'm searching for a way to control it from the server process.
It is possible to do it from the firewall but this is not in my hands
and it leaves the administrator with the responsibility to do it.
That way my application has a security hole and the administrator can
workaround it.

Any way to do it from the server process?
.



Relevant Pages

  • Re: block_ssh_guessers
    ... I haven't seen the need to go beyond a single knock - as I've only seen ... logging "I blocked this - ain't I a good firewall" to disk is ... is not a "knock," but just an open port. ... The "personal firewall" forgets that it had sent a DNS query several ...
    (comp.os.linux.security)
  • Re: sudo without password
    ... unless you're setting up server process. ... If you're setting up an IMAP ... connection to a remote machine and it wants to talk to port 25. ... malware designed to attack Linux will start to ...
    (Ubuntu)
  • RE: XP
    ... The firewall I am using is Tiny Personal Firewall ... During my install of the Windows XP Plus! ... but I do recall it contacting a server on port 80, ... and it is likely the same server. ...
    (Security-Basics)
  • Re: A poor mans activity check :)
    ... >> software making itself accessible from the Internet in the first ... Since many insecure Microsoft services use this port, ... you will need a personal firewall to block it ... I wonder which Microsoft services he's referring to. ...
    (comp.security.firewalls)
  • Re: Disable LPT1 script
    ... "When a user who is not an administrator tries to use the ... and the LPT port is already assigned to the local parallel ... >> work in a group policy startup script. ...
    (microsoft.public.win2000.networking)