Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, if it's not running Tomcat.

(Personal opinion: You should never run Tomcat, history of really unsecure development practices)



To my knowledge PiHole uses Ngingx, so that seems ok. Thank you for your response.


PiHole is not usually exposed to the Internet, that's why it's less likely to be attacked at all. But I wouldn't call their nginx+php spaghetti stack "secure" or any less vulnerable.


It isn't exposed indeed, but i'd like to have it as safe as normally possible. Are there items you might suggest in making it more secure?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: