Apache htpasswd Hashed Credential
Detects Apache htpasswd file entries containing hashed passwords in MD5 ($apr1$), bcrypt ($2y$, $2b$, $2a$), or SHA ({SHA}) formats. Mirrors Snaffler rule KeepConfigByName.
- Type
- regex
- Engine
- boost_regex
- Confidence
- high
- Confidence justification
- High confidence: the combination of a username and a well-known password hash format marker ($apr1$, $2y$, $2b$, $2a$, {SHA}) is highly specific to htpasswd files. These hash prefixes are not found in other common file formats.
- Jurisdictions
- global
- Regulations
- Criminal Code Act 1995 (Cth)
- Frameworks
- CIS Controls, ISO 27001, NIST CSF
- Data categories
- credentials
- Scope
- specific
- Risk rating
- 8
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Compatible, Netskope: Unsupported
Pattern
[A-Za-z0-9_.-]{1,64}:(?:\$apr1\$|\$1\$|\$5\$|\$6\$|\$2[aby]\$|\{SHA\})[^\s:]{1,255}
Corroborative evidence keywords
htpasswd, AuthUserFile, AuthType Basic, Require valid-user
Proximity: 300 characters
Should match
legacy:$apr1$short— Low-tier probe - recognized marker with incomplete hash structure# /srv/www/.htpasswd webuser:{SHA}qUqP5cyxm6YcTAhz05Hph5gvu9M=— Medium-tier probe - complete SHA1 entry bound to an htpasswd fileAuthUserFile /etc/apache2/.htpasswd AuthType Basic Require valid-user admin:{SHA}qUqP5cyxm6YcTAhz05Hph5gvu9M= deploy:$2y$10$abcdefghijklmnopqrstuuWOOj3U5X5bF5lrfH2jk8VeQ0k.YIVUC— High-tier probe - Apache directives and two complete credential entrieshtpasswd /srv/www/.htpasswd deploy deploy:$6$rounds=5000$saltsalt$abcdefghijklmnopqrstuvwxyz0123456789ABCDEF— Medium-tier probe - complete SHA-512 crypt entry with htpasswd binding
Should not match
admin:plaintextpassword— No hash marker prefix, plaintext passworduser:secret123— Plaintext password, no hash formatadmin:$2y$10$short— Malformed bcrypt entry with truncated digest# .htpasswd PLACEHOLDER admin:{SHA}AAAAAAAAAAAAAAAAAAAAAAAAAAA=— Placeholder hash entry must not enforceDocumentation example: AuthUserFile /etc/apache2/.htpasswd AuthType Basic admin:{SHA}qUqP5cyxm6YcTAhz05Hph5gvu9M= deploy:$2y$10$abcdefghijklmnopqrstuuWOOj3U5X5bF5lrfH2jk8VeQ0k.YIVUC— Documentation quoting a populated htpasswd file must not enforceroot:$6$rounds=5000$saltsalt$abcdefghijklmnopqrstuvwxyz0123456789ABCDEF:19800:0:99999:7:::— Sibling Unix shadow entry lacks Apache htpasswd binding
Known false positives
- Documentation or code examples showing htpasswd format with placeholder hashes. Mitigation: Require proximity to Apache configuration directives (AuthUserFile, AuthType Basic) to confirm htpasswd context.
- Other systems that coincidentally use similar username:hash colon-separated format with the same hash prefixes. Mitigation: The specific hash marker prefixes ($apr1$, $2y$, $2b$, $2a$, {SHA}) are sufficiently distinctive to minimise false positives from non-htpasswd sources.