How to Edit the ApacheAdmin Configuration File to Protect Against Possible Security Vulnerability on NetWare 6.5
TID 7001907 gives details about a potential security vulnerability with Apache, or more specifically ApacheAdmin, on NetWare 6.5 after you''ve installed an OES2 Linux server into the same tree.
However there seems to (currently) be some ambiguity about the actual cause and suggested fix.
Whilst you can use FILTCFG to restrict access to port 2200 (see my other article) this might be too restrictive since other services also use port 2200.
Fortunately it's possible to modify the Apache configuration file that is used to configure ApacheAdmin on a NetWare server.
- edit sys:/adminsrv/webapps/apacheadmin/web-inf/apadmin-apache.conf
- find the <Directory "SYS:/adminsrv/webapps/apacheadmin"> section
- change Allow from all to Allow from network/netmask where network/netmask is the network you want to allow access from