LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-26-2005, 02:40 PM   #1
namit
Member
 
Registered: Aug 2005
Distribution: Debian
Posts: 355

Rep: Reputation: 30
htpasswd convert


is there anyway of converting the password file back to the password?
 
Old 12-26-2005, 04:11 PM   #2
megaspaz
Senior Member
 
Registered: Nov 2002
Location: Silly Con Valley
Distribution: Red Hat 7.3, Red Hat 9.0
Posts: 2,054

Rep: Reputation: 46
what's up with these script kiddie kind of questions, today?

You don't need to uncode htpasswd for a user. If you need to change this users password, you just change it.
 
Old 12-26-2005, 06:15 PM   #3
namit
Member
 
Registered: Aug 2005
Distribution: Debian
Posts: 355

Original Poster
Rep: Reputation: 30
yes just wondering if someone get there hands on the password file for it would they be able to convert it back?
 
Old 12-26-2005, 06:24 PM   #4
megaspaz
Senior Member
 
Registered: Nov 2002
Location: Silly Con Valley
Distribution: Red Hat 7.3, Red Hat 9.0
Posts: 2,054

Rep: Reputation: 46
how would someone get their hands on the .htpasswd file?
The only way would be if you're running some old unpatched apache version that has some kind of remote exploit or if you allow something like ssh and haven't changed the permissions on your .htpasswd file. If someone has gotten a hold of your .htpasswd, you need to to upgrade to the latest apache version and change the passwords on your .htpasswd file for that directory and change the permissions of the .htpasswd files to be inaccessible to others.
 
Old 12-26-2005, 06:33 PM   #5
int0x80
Member
 
Registered: Sep 2002
Posts: 310

Rep: Reputation: Disabled
What if I owned your Red Hat 7.3?
 
Old 12-26-2005, 07:06 PM   #6
megaspaz
Senior Member
 
Registered: Nov 2002
Location: Silly Con Valley
Distribution: Red Hat 7.3, Red Hat 9.0
Posts: 2,054

Rep: Reputation: 46
what if you did? the last thing you need to do is to convert .htpasswd... you have complete access to the system.
 
Old 12-26-2005, 07:15 PM   #7
int0x80
Member
 
Registered: Sep 2002
Posts: 310

Rep: Reputation: Disabled
Precisely. So stop throwing a tantrum in this thread.

namit: The premise of htpasswd is similar to system passwords in Unix/Linux. A hash of the password is made. The password can be cracked, but the hash cannot be reversed to enumerate the password.
 
Old 12-26-2005, 07:23 PM   #8
megaspaz
Senior Member
 
Registered: Nov 2002
Location: Silly Con Valley
Distribution: Red Hat 7.3, Red Hat 9.0
Posts: 2,054

Rep: Reputation: 46
I was throwing a tantrum? I'm just trying to understand why this question was asked. There's no real way to get someone's .htpasswd file unless someone's machine got owned. And if someone's machine got owned, an attacker's not going to bother with .htpasswd. The parent poster's question seemed more like wanting some tool or some way of breaking htpasswd. If this is the poster's own system, there's ways of making it so no one other than the apache process and/or the root user can see the .htaccess file. In other words, I felt I answered the question in such a way that you wouldn't have to worry about a compromised .htpasswd file.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
.htaccess .htpasswd plisken Linux - General 5 05-21-2006 01:44 PM
htpasswd integra_twinz Linux - Newbie 10 11-01-2005 10:08 AM
htpasswd... not in effect 3AM Fedora 1 06-11-2004 12:02 PM
Help with .htpasswd and .htaccess MikeeX Linux - General 3 03-25-2003 10:41 AM
htpasswd steve_c Linux - General 10 04-16-2002 10:15 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration