There should be an option which allows to bind ServerSocket to localhost. It also should be default to enforce security.