[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20060613132615.11022.qmail@securityfocus.com>
Date: 13 Jun 2006 13:26:15 -0000
From: jn@....de
To: bugtraq@...urityfocus.com
Subject: Re: PHP Advanced Transfer Manager Download users password hashes
The phpatm support forum (currently down) advises administrators to put a .htaccess into the users directory with the following content:
# no one gets in here!
order allow,deny
deny from all
Furthermore the website recommends to rename the "users" directory and change the corresponding variable in the config-file.
These two things done, it is no longer possible to download the hashes.
Powered by blists - more mailing lists