Apache htpasswd Password Entropy Weakness
BID:8707
Info
Apache htpasswd Password Entropy Weakness
| Bugtraq ID: | 8707 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 25 2003 12:00AM |
| Updated: | Feb 15 2008 11:45PM |
| Credit: | The discovery of this weakness has been credited to Andreas Steinmetz <[email protected]>. |
| Vulnerable: |
Posadis Posadis 1.3.31 Apache Apache 2.2.6 Apache Apache 2.2.5 Apache Apache 2.2.4 Apache Apache 2.2.3 Apache Apache 2.2.2 Apache Apache 2.2 Apache Apache 2.1.8 Apache Apache 2.1.7 Apache Apache 2.1.6 Apache Apache 2.1.5 Apache Apache 2.1.4 Apache Apache 2.1.3 Apache Apache 2.1.2 Apache Apache 2.1.1 Apache Apache 2.1 Apache Apache 2.0.59 Apache Apache 2.0.58 Apache Apache 2.0.56 -dev Apache Apache 2.0.55 Apache Apache 2.0.54 Apache Apache 2.0.53 Apache Apache 2.0.52 Apache Apache 2.0.51 Apache Apache 2.0.50 Apache Apache 2.0.49 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Beta Apache Apache 2.0.28 Apache Apache 2.0 a9 Apache Apache 2.0 Apache Apache 1.3.39 Apache Apache 1.3.37 Apache Apache 1.3.36 Apache Apache 1.3.35 -dev Apache Apache 1.3.35 Apache Apache 1.3.34 Apache Apache 1.3.33 Apache Apache 1.3.32 Apache Apache 1.3.31 Apache Apache 1.3.29 Apache Apache 1.3.28 Apache Apache 1.3.27 Apache Apache 1.3.9 Apache Apache 1.3.7 -dev Apache Apache 1.3.6 Apache Apache 1.3.4 Apache Apache 1.3.3 Apache Apache 2.3.38-dev Apache Apache 2.2.7-dev Apache Apache 2.2.6-dev Apache Apache 2.2.5-dev Apache Apache 2.0.62-dev Apache Apache 2.0.61-dev Apache Apache 2.0.60-dev Apache Apache 1.3.40-dev |
| Not Vulnerable: | |
Discussion
Apache htpasswd Password Entropy Weakness
A weakness has been discovered in the way that the Apache 'htpasswd' utility generates salts. Specifically, the salt is generated based of the current system time. As a result, salts generated within the same second will be identical. This may pose a security weakness if the server were implementing default passwords and an attacker were capable of obtaining the contents of htpasswd.
A weakness has been discovered in the way that the Apache 'htpasswd' utility generates salts. Specifically, the salt is generated based of the current system time. As a result, salts generated within the same second will be identical. This may pose a security weakness if the server were implementing default passwords and an attacker were capable of obtaining the contents of htpasswd.
Exploit / POC
Apache htpasswd Password Entropy Weakness
No exploit required.
No exploit required.
References
Apache htpasswd Password Entropy Weakness
References:
References:
- Apache Homepage (Apache Software Foundation)
- [[email protected]: Apache web server 2.2: htpasswd predictable salt weakness] (Peter Watkins
) - minor apache htpasswd problem (Andreas Steinmetz
) - Re: Apache web server 2.2: htpasswd predictable salt weakness (3APA3A <[email protected]>)
- Re: Apache web server 2.2: htpasswd predictable salt weakness (Peter Watkins
)