Yes, when you start opening ports and running servers you start to have to thing about security, but so long as you ensure you always install the latest versions and follow security advisories as and when they are released, you minimize you chances of having your machine compromised. Having said that, you are making your machine more vunerable, I definately would not store any personal/private data on the machine and I would be monitoring it for unusual activity.
I'm sorry I barely know what Tomcat is though, something to do with java, webpages and apache :P; but Apache documentation is so complete I doubt you'll have to worry about that ;)
Good luck
Steve
|