Is there any reason why Tomcat 5 runs as root? I was able to display my /etc/shadow through a servlet of mine that did not screen for "../". Through some minor twiddling I have it running as nobody now, with no ill-effect. Eric