Previous Thread
Next Thread
Print Thread
Rate Thread
#6678 06/29/03 11:02 AM
Joined: Feb 2002
Posts: 7,204
Likes: 11
Community Owner
Community Owner
Joined: Feb 2002
Posts: 7,204
Likes: 11
Ok, I'm getting tired of seeing "How do I hack into a secure site". First off, the majority of "secure" sites use .htaccess for their authentication. In otherwords, if you see a little box pop up that says "password" and "username" chances are it's .htaccess and .htpasswd that are blocking your way.

Now, how .htaccess looks is as follows:
Code
AuthUserFile /var/www/html/members/.htpasswd
AuthName Paid Member 
AuthType Basic

<Limit GET POST>
require valid-user
</Limit>
See that, pretty basic 'eh? And I'll bet you that the majority of 'em look the same way too...

Now, the .htpasswd file looks totally differant, the passwords are encrypted, the username is not...

Code
gizmo:gikZbrq7ZFQJ.
gizzy:gieKOUmNNB7go
giz:giL8X53UiINbs
neo:nenIgi4UdbW.M
weeve:we7dyaNzlm.Ag
newbies:neZgxh60ynKGU
See, the thing is, you don't need either of the two files to bruit force a thing... Their just given here as an example of how things work (when you learn, thats how you learn, otherwise you get left behind).

Now, theirs really only a couple of things you need...
1. A couple of proxy servers (if you want to remain anonymous)...
2. A bruit force program (We recommend www.accessdiver.com for all of your Bruit Force needs)...
3. A members URL which uses .htaccess (for example: http://www.yourvictem.com/members/ )
4. A wordlist (you're on your own there, my wordlist is my baby).

Basically, in AD you load your wordlist, load your proxys, drop in your URL, click standard. After many hours of grueling work, if you have a good wordlist, you'll have a user/pass...


Donate to UGN Security here.
UGN Security, Back of the Web, and VNC Web Services Owner
Sponsored Links
▼ Sponsored Links ▼ ▲ Sponsored Links ▲
#6679 06/29/03 03:56 PM
Joined: Jun 2003
Posts: 807
Likes: 2
G
UGN Super Poster
UGN Super Poster
G Offline
Joined: Jun 2003
Posts: 807
Likes: 2
How would you go about requesting these files?

#6680 06/29/03 05:37 PM
Joined: Feb 2002
Posts: 7,204
Likes: 11
Community Owner
Community Owner
Joined: Feb 2002
Posts: 7,204
Likes: 11
you're pretty much on your own there... We'll teach you to do some stuff but we won't hold your hand while you piss...


Donate to UGN Security here.
UGN Security, Back of the Web, and VNC Web Services Owner
#6681 06/30/03 07:47 AM
Joined: Mar 2002
Posts: 508
Likes: 1
UGN Super Poster
UGN Super Poster
Joined: Mar 2002
Posts: 508
Likes: 1

#6682 07/01/03 09:52 PM
Joined: Jun 2003
Posts: 807
Likes: 2
G
UGN Super Poster
UGN Super Poster
G Offline
Joined: Jun 2003
Posts: 807
Likes: 2
ahem thanx ahem


Link Copied to Clipboard
Member Spotlight
Gremelin
Gremelin
Portland, OR; USA
Posts: 7,204
Joined: February 2002
Forum Statistics
Forums41
Topics33,839
Posts68,797
Members2,177
Most Online73,244
Nov 9th, 2025
Latest Postings
Top Posters
UGN Security 41,392
Gremelin 7,204
SilentRage 1,273
Ice 1,146
pergesu 1,136
Infinite 1,041
jonconley 955
Girlie 908
unreal 860
Top Likes Received
Ghost 2
unreal 1
Crime 1
Ice 1
Dartur 1
Powered by UBB.threads™ PHP Forum Software 8.0.0