The owners of those hosts were notified.
Also, this login system works only with APACHE, since lighthttpd and others doesnt recognise .htaccess, thereby /share dir is exposed.
The bad part of basic auth is that you need password a whole domain, a single path doesnt do it, because SCGI is...