Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability: Default configuration allows to download the htpasswd file over HTTP #12

Open
ypid opened this issue Mar 15, 2015 · 1 comment

Comments

@ypid
Copy link
Contributor

ypid commented Mar 15, 2015

Hi

in the default configuration, it is pretty easy to download the htpasswd file containing the hashes of the user passwords.

See: nginx configuration

@jaysh
Copy link
Contributor

jaysh commented Apr 24, 2015

Assuming you already have the password. If you already have the password, you don't actually need to open the .htpasswd file to get the password :-)

Until the time comes where multiple user accounts are supported, I'd close this as a non-issue or leave it as an enhancement. That said, I'm sure the author won't decline a PR to fix it 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants