Article

smflood's picture
article
Reads:

3827

Score:
3
3
2
 
Comments:

0

How to Edit the ApacheAdmin Configuration File to Protect Against Possible Security Vulnerability on NetWare 6.5

Author Info

3 February 2009 - 12:03pm
Submitted by: smflood

(View Disclaimer)

TID 7001907 gives details about a potential security vulnerability with Apache, or more specifically ApacheAdmin, on NetWare 6.5 after you''ve installed an OES2 Linux server into the same tree.

However there seems to (currently) be some ambiguity about the actual cause and suggested fix.

Whilst you can use FILTCFG to restrict access to port 2200 (see my other article) this might be too restrictive since other services also use port 2200.

Fortunately it's possible to modify the Apache configuration file that is used to configure ApacheAdmin on a NetWare server.

  1. edit sys:/adminsrv/webapps/apacheadmin/web-inf/apadmin-apache.conf
  2. find the <Directory "SYS:/adminsrv/webapps/apacheadmin"> section
  3. change Allow from all to Allow from network/netmask where network/netmask is the network you want to allow access from
Note: If you want to allow access from more than one network/netmask just add additional Allow from ... lines.

Disclaimer: As with everything else at Cool Solutions, this content is definitely not supported by Novell (so don't even think of calling Support if you try something and it blows up).

It was contributed by a community member and is published "as is." It seems to have worked for at least one person, and might work for you. But please be sure to test, test, test before you do anything drastic with it.




User Comments

© 2013 Novell