Image

Imageillubrious wrote in Imagelinux

htpasswd

Just downloaded this totally sleazy tutorial on how to crack htpasswd via a common cgi script that interfaces with said password file. Know that htpasswd's encryption is weak, but, wondering if there was an Apache mod to use blowfish encryption with htpasswd? Then, it'd render all the directory traversal that is done via the cgi scripts with htpasswd less fruitful.