Robert Hansen htaccess Scripts in Apache Environments
Robert Hansen,
Hardening .htaccess scripts in Apache environments.
Htaccess is an out of the box method to secure portions of websites using a username/password combination. Several solutions will be presented, both theoretical and practical on hardening htaccess authentication. In its natural form, it has serious flaws that will be explained in detail. In addition a variation on Morris' attack will be used to show one method on how to break IP based authentication methods used by many of the third party on-line credit card clearing companies.
Robert, known formerly as RSnake and currently as RSenic, has worked for a major banner advertising company as an Information Specialist and for several start-up companies as Chief Operations Officer and Chief Security Officer. He devised a method by which to make credit card clearing faster, more secure, and save large amounts of transaction costs. He successfully negotiated a bridge financing round. He has founded several security sites and organizations, and has been interviewed by many international magazines, newspapers, and television networks
Black Hat - USA - 2001 Hacking conference
#hacking, #hackers, #infosec, #opsec, #hardening, #htaccess