Guys, Htacces passwords are "quite" easily gathered with Accessdiver(.com). With a good wordlist and weak passwords is easy to find some passes.
I would advise every paysite owner to use accessdiver yourself to see for yourself. Best defence would be a (custom) php/cgi/whatever login instead of htacces imo. Or atleast make sure you block IP's that do over 5 attemps in 24 hours or so.
Just my 2 cents.
|