RE: Beware of Phishing Attacks 04-20-2016, 11:45 PM
#8
(04-20-2016, 11:42 PM)m0dem Wrote: I don't really understand what you mean by htaccess/htpasswd.
But anyway, that's scary.
If someone falls for it though... idk what to say.
He is basically saying that by using a HTPASSWD (http://www.colostate.edu/~ric/htpass.html)
the guy was able to lock down his image with a valid .png so therefore it bypassed the image filters,
But due to the bypass working he could throw a custom message in attempt to gain failed HTACCESS attempts storing user creds,
Its quit a smart attack actually but poorly managed and I assume not very organised by not even using a domain.


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)