Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Keep Your Tomcat Hosting Secure

This guide gives simple steps to make a Tomcat server harder to attack. Most steps need root access to a VPS or dedicated server.

General2 min read10 steps

What is Tomcat?

Tomcat is free software that runs Java web applications. Many sites use it. Like any program on the internet, it needs care. Attackers look for old versions and weak settings.

Warning: Back up your Tomcat folder and your applications before you change anything.

Steps

  1. Keep it updated. New Tomcat releases fix security bugs. Check your version often.
    /opt/tomcat/bin/version.sh
    This prints the version. Your install path may differ.
  2. Run it as a normal user. Never run Tomcat as root. If someone breaks in, they get fewer powers. Create a user such as tomcat for this job.
  3. Remove sample apps. In the webapps folder, delete the docs, examples, host-manager and manager folders if you do not need them.
  4. Protect the Manager app. If you keep it, use a strong password. Limit who can open it by IP address, in the file META-INF/context.xml of that app.
  5. Close the shutdown port. Tomcat listens on port 8005 for a shutdown word. In conf/server.xml, change the word to a long random one, or set the port to -1 to turn it off.
  6. Hide version details. In server.xml, set server="" in the Connector line. This stops Tomcat telling visitors which version it is.
  7. Use HTTPS. Put a TLS certificate on the site, so data is scrambled. Many people put Apache or Nginx in front of Tomcat to handle this.
  8. Block direct access to Tomcat ports. Close 8080 and 8009 in the firewall if Apache or Nginx forwards the traffic.
  9. Turn off directory listing. In conf/web.xml, set the listings value of the default servlet to false.
  10. Restart Tomcat and test your site.
    systemctl restart tomcat
    This applies the changes. Your service name may differ.
Tip: Check the Tomcat logs in the logs folder from time to time. Many failed logins may mean someone is guessing passwords.

Need help? Open a support ticket.

Quick recap

  • Update Tomcat often.
  • Do not run it as root.
  • Remove sample and manager apps you do not use.
  • Close or protect extra ports.
  • Use HTTPS and hide version details.