How to make EP safe? What should be done before allowing using portal for end-users? How to prevent EP from being hacked? How to disable dangerous packages like /irj/servlet/prt/portal/prtroot/com.sap.portal.runtime.system.console.ArchiveUploader?
What should be forbidden and what not?