.htaccess Passwords
For month I’ve been using the wrong password to access my email administration. Strange thing is, I have not discovered this until just now because the web server granted me access all the time. A quick Google search confirmed my suspicion when I found Franz Seidl describing the same behaviour: By default an access control using .htpasswd files is taking only the first eight characters into consideration when checking passwords! So keep this in mind if you are protecting folders of your web server by setting up .htaccess files.
Addendum: adminblogger just pointed out to me, that you can tell htpasswd which algorithm to use when creating a password hash. See a short example by him at pastebin.
Recently
- Like Christmas
- Exceeding Planned Production Target
- Web 3.0
- Conspirative Meeting
- Miniature Bunny
- Word Of The Day V
- I Love(d) College
- OpenThesaurus
- Long Channels Of Supply
- .htaccess Passwords


english
deutsch
Leave a Reply