Apache htpasswd Password Entropy Weakness...

- AV AC AU C I A
发布: 2003-09-25
修订: 2025-04-13

A weakness has been discovered in the way that the Apache 'htpasswd' utility generates salts. Specifically, the salt is generated based of the current system time. As a result, salts generated within the same second will be identical. This may pose a security weakness if the server were implementing default passwords and an attacker were capable of obtaining the contents of htpasswd.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息