<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Java-Monitor Forum</title>
		<link>http://java-monitor.com/forum/</link>
		<description>This is a discussion forum about monitoring, tuning and troubleshooting Java application servers.</description>
		<language>en</language>
		<lastBuildDate>Fri, 18 May 2012 14:36:00 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>15</ttl>
		<image>
			<url>http://www.java-monitor.com/forum/images/styles/java/misc/rss.jpg</url>
			<title>Java-Monitor Forum</title>
			<link>http://java-monitor.com/forum/</link>
		</image>
		<item>
			<title>Liferay Portal Privilege Escalation</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2423&amp;goto=newpost</link>
			<pubDate>Thu, 17 May 2012 11:14:36 GMT</pubDate>
			<description>Topic: Liferay Portal Privilege Escalation Risk: Medium Text:Liferay users can assign themselves to organizations, leading to  possible privilege...</description>
			<content:encoded><![CDATA[<div>Topic: Liferay Portal Privilege Escalation Risk: Medium Text:Liferay users can assign themselves to organizations, leading to  possible privilege escalation    Description:  <a href="https://bugzil" target="_blank">https://bugzil</a>... <a href="http://feedads.g.doubleclick.net/~a/oc04I53YuEewEJLdsfNp3y6HxRE/0/da" target="_blank"><img src="http://feedads.g.doubleclick.net/~a/oc04I53YuEewEJLdsfNp3y6HxRE/0/di" border="0" alt="" /></a><br />
<a href="http://feedads.g.doubleclick.net/~a/oc04I53YuEewEJLdsfNp3y6HxRE/1/da" target="_blank"><img src="http://feedads.g.doubleclick.net/~a/oc04I53YuEewEJLdsfNp3y6HxRE/1/di" border="0" alt="" /></a><br />
<br />
<img src="http://feeds.feedburner.com/~r/securityalert_database/~4/K7TnWYu0cK0" border="0" alt="" /><br />
<br />
<a href="http://feedproxy.google.com/~r/securityalert_database/~3/K7TnWYu0cK0/WLB-2012050109" target="_blank">More...</a></div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=6">Java Security Advisories</category>
			<dc:creator>Java-monitor RSS bot</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2423</guid>
		</item>
		<item>
			<title>Liferay 5.x / 6.x Cross Site Scripting</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2422&amp;goto=newpost</link>
			<pubDate>Thu, 17 May 2012 11:14:36 GMT</pubDate>
			<description>Topic: Liferay 5.x / 6.x Cross Site Scripting Risk: Low Text:Multiple xss issues in Liferay    Description:    Liferay Portal is an enterprise portal...</description>
			<content:encoded><![CDATA[<div>Topic: Liferay 5.x / 6.x Cross Site Scripting Risk: Low Text:Multiple xss issues in Liferay    Description:    Liferay Portal is an enterprise portal written in Java    Multiple xss vulner... <a href="http://feedads.g.doubleclick.net/~a/jo7-fWXsCXmGBUNKiUOl6RNohXU/0/da" target="_blank"><img src="http://feedads.g.doubleclick.net/~a/jo7-fWXsCXmGBUNKiUOl6RNohXU/0/di" border="0" alt="" /></a><br />
<a href="http://feedads.g.doubleclick.net/~a/jo7-fWXsCXmGBUNKiUOl6RNohXU/1/da" target="_blank"><img src="http://feedads.g.doubleclick.net/~a/jo7-fWXsCXmGBUNKiUOl6RNohXU/1/di" border="0" alt="" /></a><br />
<br />
<img src="http://feeds.feedburner.com/~r/securityalert_database/~4/fAvbx_NUYus" border="0" alt="" /><br />
<br />
<a href="http://feedproxy.google.com/~r/securityalert_database/~3/fAvbx_NUYus/WLB-2012050113" target="_blank">More...</a></div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=6">Java Security Advisories</category>
			<dc:creator>Java-monitor RSS bot</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2422</guid>
		</item>
		<item>
			<title>Liferay 6.1 No Account Access Bypass</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2421&amp;goto=newpost</link>
			<pubDate>Thu, 17 May 2012 11:14:36 GMT</pubDate>
			<description>Liferay version 6.1 suffers from a circumvention issue when restricting access to ip blocks. Proof of concept exploit included. 
 
More......</description>
			<content:encoded><![CDATA[<div>Liferay version 6.1 suffers from a circumvention issue when restricting access to ip blocks. Proof of concept exploit included.<br />
<br />
<a href="http://packetstormsecurity.org/files/112735/liferay-bypass.tgz" target="_blank">More...</a></div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=6">Java Security Advisories</category>
			<dc:creator>Java-monitor RSS bot</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2421</guid>
		</item>
		<item>
			<title>Liferay 5.x / 6.x Cross Site Scripting</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2420&amp;goto=newpost</link>
			<pubDate>Thu, 17 May 2012 11:14:36 GMT</pubDate>
			<description>Liferay versions 5.x and 6.x suffer from multiple cross site scripting vulnerabilities. 
 
More......</description>
			<content:encoded><![CDATA[<div>Liferay versions 5.x and 6.x suffer from multiple cross site scripting vulnerabilities.<br />
<br />
<a href="http://packetstormsecurity.org/files/112737/liferay6-xss.txt" target="_blank">More...</a></div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=6">Java Security Advisories</category>
			<dc:creator>Java-monitor RSS bot</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2420</guid>
		</item>
		<item>
			<title>Liferay 6.1 Name / Email Address Disclosure</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2419&amp;goto=newpost</link>
			<pubDate>Thu, 17 May 2012 11:14:36 GMT</pubDate>
			<description>Liferay version 6.1 suffers from a vulnerability where it is possible to retrieve the names and email addresses of all users. Proof of concept code...</description>
			<content:encoded><![CDATA[<div>Liferay version 6.1 suffers from a vulnerability where it is possible to retrieve the names and email addresses of all users. Proof of concept code included.<br />
<br />
<a href="http://packetstormsecurity.org/files/112740/liferay-disclose.tgz" target="_blank">More...</a></div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=6">Java Security Advisories</category>
			<dc:creator>Java-monitor RSS bot</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2419</guid>
		</item>
		<item>
			<title>Liferay 6.1 Cross Site Request Forgery</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2418&amp;goto=newpost</link>
			<pubDate>Thu, 17 May 2012 11:14:36 GMT</pubDate>
			<description>Liferay version 6.1 is vulnerable to JSON-related cross site request forgery attacks. Proof of concept code is included. 
 
More......</description>
			<content:encoded><![CDATA[<div>Liferay version 6.1 is vulnerable to JSON-related cross site request forgery attacks. Proof of concept code is included.<br />
<br />
<a href="http://packetstormsecurity.org/files/112746/liferay-xsrf.tgz" target="_blank">More...</a></div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=6">Java Security Advisories</category>
			<dc:creator>Java-monitor RSS bot</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2418</guid>
		</item>
		<item>
			<title>This probe was hit by an unexpected exception</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2401&amp;goto=newpost</link>
			<pubDate>Tue, 15 May 2012 21:49:55 GMT</pubDate>
			<description><![CDATA[Image: http://java-monitor.com/postedimages/71e9ea36-4203-40b3-ac35-c14155417d8a.png  
 
Kees Jan, 
 
I'm getting the following from all my servers: ...]]></description>
			<content:encoded><![CDATA[<div><div align="center"><img src="http://java-monitor.com/postedimages/71e9ea36-4203-40b3-ac35-c14155417d8a.png" border="0" alt="" /></div><br />
Kees Jan,<br />
<br />
I'm getting the following from all my servers: <br />
May 15, 2012 4:30:55 PM com.javamonitor.JavaMonitorCollector$CollectorDriv  er run<br />
SEVERE: This probe was hit by an unexpected exception: Connection reset<br />
java.net.SocketException: Connection reset<br />
        at java.net.SocketInputStream.read(SocketInputStream.  java:168)<br />
        at java.io.BufferedInputStream.fill(BufferedInputStre  am.java:218)<br />
        at java.io.BufferedInputStream.read1(BufferedInputStr  eam.java:258)<br />
        at java.io.BufferedInputStream.read(BufferedInputStre  am.java:317)<br />
        at sun.net.<a href="http://www.http.HttpClient.parseHTTPHeader(HttpClient.java:687" target="_blank">http://www.http.HttpClient.parseHTTP...lient.java:687</a>)<br />
        at sun.net.<a href="http://www.http.HttpClient.parseHTTP(HttpClient.java:632" target="_blank">http://www.http.HttpClient.parseHTTP...lient.java:632</a>)<br />
        at sun.net.<a href="http://www.http.HttpClient.parseHTTP(HttpClient.java:652" target="_blank">http://www.http.HttpClient.parseHTTP...lient.java:652</a>)<br />
        at sun.net.<a href="http://www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1072" target="_blank">http://www.protocol.http.HttpURLConn...tion.java:1072</a>)<br />
        at com.javamonitor.Collector.push(Collector.java:332)<br />
        at com.javamonitor.Collector.push(Collector.java:140)<br />
        at com.javamonitor.JavaMonitorCollector$CollectorDriv  er.run(JavaMonitorCollector.java:150)<br />
        at java.lang.Thread.run(Thread.java:619)<br />
<br />
<br />
This happens frequently throughout the day from all my servers. WEB1, WEB2, and STG are hosted with Rackspace and the DEVx servers are here in our data center. <br />
<br />
As you can see from this thread graph, I'm missing several reports throughout the day and this is typical on all servers in both data centers.<br />
<br />
Any idea of what could be happening and how to fix it?<br />
<br />
Thanks...Ron</div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=3">Java Administration</category>
			<dc:creator>ron</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2401</guid>
		</item>
		<item>
			<title>Monitoring Hibernate statistics (JMX) and security</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2355&amp;goto=newpost</link>
			<pubDate>Sun, 06 May 2012 18:50:33 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I want to collect hibernate-statistics and I'm considering enabling JMX to do this with the java-monitor-probe. 
 
However i need some advice...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I want to collect hibernate-statistics and I'm considering enabling JMX to do this with the java-monitor-probe.<br />
<br />
However i need some advice on security.<br />
<br />
If i enable JMX without any form of security, what will this mean? Anyone can access my statistics? Or anything more severe?<br />
<br />
And if I choose to implement some form of security. How would i set this up so only the probe gets access?<br />
<br />
Using Tomcat 6 btw.<br />
<br />
Thanks!</div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=5">Tomcat Administration</category>
			<dc:creator>erkdahl</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2355</guid>
		</item>
		<item>
			<title>Problems?</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2340&amp;goto=newpost</link>
			<pubDate>Fri, 04 May 2012 15:29:25 GMT</pubDate>
			<description><![CDATA[Hello, 
 
are there any problems since last week? From about last Thursday I'm constantly getting "server offline" messages immediately followed by...]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
are there any problems since last week? From about last Thursday I'm constantly getting &quot;server offline&quot; messages immediately followed by &quot;server back online&quot; at least a few times a day, which was never happening before (at least not from the start of February when I activated the monitoring). The internet connectivity on the server is never down when I receive these messages, so it has to be the network problem between my server and the monitoring server specifically which is not very likely in my opinion, or it has to be some problem with the monitoring tool itself... <br />
For now, I can of course increase the timeout from 2 minutes to 5 minutes or even 20 minutes, but I wonder if there are any known issues which might cause this...<br />
<br />
Thanks.</div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=15">Monitoring Tool Questions</category>
			<dc:creator>dopicechodte</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2340</guid>
		</item>
		<item>
			<title>Login problems</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2319&amp;goto=newpost</link>
			<pubDate>Wed, 02 May 2012 12:59:37 GMT</pubDate>
			<description>I have this problem. 
 
Any solutions? 
 
Thank You 
 
Image: http://www.coolwebsolutions.net/loginError.png</description>
			<content:encoded><![CDATA[<div>I have this problem.<br />
<br />
Any solutions?<br />
<br />
Thank You<br />
<br />
<img src="http://www.coolwebsolutions.net/loginError.png" border="0" alt="" /></div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=15">Monitoring Tool Questions</category>
			<dc:creator>mikycol</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2319</guid>
		</item>
		<item>
			<title><![CDATA["PS Survivor Space" stops "normal swapping"]]></title>
			<link>http://java-monitor.com/forum/showthread.php?t=2309&amp;goto=newpost</link>
			<pubDate>Tue, 01 May 2012 18:24:41 GMT</pubDate>
			<description>Hi, we have a performance problem in production. we are getting out of memory error.  
Setting in production is  
-Xmx1024m -Xms256m...</description>
			<content:encoded><![CDATA[<div>Hi, we have a performance problem in production. we are getting out of memory error. <br />
Setting in production is <br />
-Xmx1024m -Xms256m -XX:MaxPermSize=320m.<br />
<br />
When i monitor the memory usage using Jconsole. <br />
I noticed that &quot;PS Survivor Space&quot; stops &quot;normal swapping&quot;.<br />
<br />
I tested Development environment.<br />
it has better performance. &quot;PS Survivor Space&quot; has normal swapping.<br />
<br />
Dev setting: -Xmx1024m -Xms512m -XX:MaxPermSize=320m.<br />
<br />
I noticed that -Xms in dev and prod are different.<br />
I am not sure why &quot;PS Survivor Space&quot; stops &quot;normal swapping&quot; in production.<br />
Production become very slow after two or three weeks..<br />
<br />
thank you!<br />
Siva</div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=15">Monitoring Tool Questions</category>
			<dc:creator>Siva</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2309</guid>
		</item>
		<item>
			<title>missing J2EEApplication</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2306&amp;goto=newpost</link>
			<pubDate>Sun, 29 Apr 2012 18:57:44 GMT</pubDate>
			<description><![CDATA[I deployed a JCAPS application on a gfish2, the application is deployed as "disabled". The normal situation is that the key...]]></description>
			<content:encoded><![CDATA[<div>I deployed a JCAPS application on a gfish2, the application is deployed as &quot;disabled&quot;. The normal situation is that the key com.sun.appserv:j2eeType=J2EEApplication,name=MyDi  sabledApp is created and I can retrieve some informations through VisualVM<br />
<br />
For some reasons, I have few cases where the app is deployed successfully as said by asadmin and read in the gfish log but the app is not visible (1) in the admin console and (2) in the JMX keys.<br />
<br />
By the way, restarting the gfish instance shows us (1) that the app is deployed, (2) as disabled and (3) the keys are created.<br />
<br />
Do you know a particular tip to receive the &quot;error&quot; possibly occurred (through the log or the asasdmin return e.g.) ?<br />
<br />
Thanks for your time,<br />
<br />
Christophe.</div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=10">Glassfish Administration</category>
			<dc:creator>cfd</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2306</guid>
		</item>
		<item>
			<title>Outage..</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2291&amp;goto=newpost</link>
			<pubDate>Fri, 27 Apr 2012 03:25:35 GMT</pubDate>
			<description>I noticed in the Maintenance forum that there has been an outage for the last two days.  I have 2 separate probes (for two separate companies) and...</description>
			<content:encoded><![CDATA[<div>I noticed in the Maintenance forum that there has been an outage for the last two days.  I have 2 separate probes (for two separate companies) and neither one of them appear to be working.  Is anyone else having any problems?</div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=15">Monitoring Tool Questions</category>
			<dc:creator>thcampbell</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2291</guid>
		</item>
		<item>
			<title>Facelet problem</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2267&amp;goto=newpost</link>
			<pubDate>Mon, 23 Apr 2012 22:53:37 GMT</pubDate>
			<description>Actually i have a problem tomcat throw FileNotFoundException after about 5hours from correct working. 
 
After the error occurs if we restarted the...</description>
			<content:encoded><![CDATA[<div>Actually i have a problem tomcat throw FileNotFoundException after about 5hours from correct working.<br />
<br />
After the error occurs if we restarted the server it goes to work fine, also if we removed the doctype from the template client it goes to work fine.<br />
<br />
tomcat version: 6.0.35<br />
Jsf2, spring 3 and jpa2.<br />
<br />
Error Screen Shoot.<br />
<a href="https://docs.google.com/open?id=0B2BVGDhe2Wm2M3Bla2toSWswNUE" target="_blank">https://docs.google.com/open?id=0B2B...3Bla2toSWswNUE</a><br />
<br />
Thanks.<br />
Nabil</div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=5">Tomcat Administration</category>
			<dc:creator>nabilTawfik</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2267</guid>
		</item>
		<item>
			<title>Memory/CPU Notifications</title>
			<link>http://java-monitor.com/forum/showthread.php?t=2261&amp;goto=newpost</link>
			<pubDate>Mon, 23 Apr 2012 07:58:49 GMT</pubDate>
			<description>First of all, great piece of software, beats the hell out of ssh tunnels, jstatd, remote jmx and all that other messy stuff.  I am putting together...</description>
			<content:encoded><![CDATA[<div>First of all, great piece of software, beats the hell out of ssh tunnels, jstatd, remote jmx and all that other messy stuff.  I am putting together my own probe for our WebObjects applications hosted on EC2.  <br />
<br />
Was just wondering if a feature request to get notifications on memory or cpu usage had ever come up?  i.e. send a notification if heap memory or cpu gets to 90%.  For our applications that usually means excess load on the system usually due to crawlers, which needs attention.  If we get notified when the heap starts to approach 100% then we can take corrective action before the entire app goes down.<br />
<br />
Thanks<br />
Gerard</div>

]]></content:encoded>
			<category domain="http://java-monitor.com/forum/forumdisplay.php?f=15">Monitoring Tool Questions</category>
			<dc:creator>gerarddougan</dc:creator>
			<guid isPermaLink="true">http://java-monitor.com/forum/showthread.php?t=2261</guid>
		</item>
	</channel>
</rss>

