[WSS] Security Labs
~/blog ~/consulting ~/huntdb ~/github
Blog Consulting HuntDB GitHub
Decoding a $😱,000.00 htpasswd bounty
BugBounty

Decoding a $😱,000.00 htpasswd bounty

tldr; A Private Bug Bounty Program had a globally readable .htpasswd file. I cracked the DES hash, got access to development and staging environments and was rewarded a shitload of$. [Tools used] dirbuster https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project John http://www.openwall.com/john/ [\Tools

September 08, 2016 • 3 min read min read
Page 1 of 1

Stay Updated

Get the latest security research and insights directly in your inbox.

Get in Touch

Have a security concern? Let's discuss how we can help.

patrik@wss.sh LinkedIn @patrikfehrenbach
WSS Security Labs

Professional security research and technical insights about penetration testing and cloud security.

GitHub Twitter

Products

  • HuntDB
  • WSS Consulting

Security Services

  • Penetration Testing
  • Security Consulting
  • Code Review