viviotech / lucee-installer

BitRock Installer XML config and files for the Lucee installers
http://lucee.viviotech.net/
9 stars 2 forks source link

Disable MessageBrokerServlet by default for increased security #68

Closed utdream closed 9 years ago

utdream commented 9 years ago

Since very few use it, and following the example of Igal's express installer, we should disable the MessageBrokerServlet by default so that it is removed as a default attack vector. However, we will leave commented configuration in-line so that it can be re-enabled somewhat easily.

utdream commented 9 years ago

updated for Lucee installers 4.5.1.022

utdream commented 9 years ago

https://github.com/utdream/CFML-Installers/wiki/Lucee-Installer-Release-Notes