security - what is a auth_user_file.txt? -


I was reading about a security vulnerability and found that many sites are crawling this file and in the search results Are looking. It seems important, but I do not know what's in it / is included and I can not find any information in it.

What is this file, what's in it, and what is its purpose?

I think searching for crawler auth_user_file.txt Because its name is probably given in some tutorials for Apache modules; When an administrator makes a mistake in putting the file in the DOCROOT of the webserver, then whatever you ask for is free to download.

Once downloading an attacker file, they may be brutal, strengthen password hashes, and access server resources (or, perhaps, by using broken passwords and stolen user names Based on the list of known usernames, people will be guessing passwords, people have the habit of selecting password and abc123 ...)

Comments