Did you Change the Password? E-mail
by David Heath   
Wednesday, 20 February 2008
Too many organisations install the latest wonderful device or piece of software and through neglect or ignorance leave the manufacturer’s default password in place.  Guess what, there’s a website (probably more than one) that is slowly collecting all these default passwords and making them freely available.

Manufacturers haven’t learned much of anything when it comes to shipping systems with default passwords.  How hard would it be to insist on a password change when the device (or software) is first activated, or even print a short random code on the box – make that the first password; and still require an immediate change?

So, do you own a Cisco IDS?  It’s quite a useful little device.  Pity the default administrator username is “root” with a password of “attack.”  What about SAP’s Business Director product?  In version 4.7, there is a default account of “Replicator” with a password of “iscopy.”

Perhaps IBM is more your speed.  The 3534 F08 Fibre Switch has a username of “admin” and a password of “password.”  How wonderfully inventive!  What about IBM’s TotalStorage Enterprise Server?  Username is “storwatch,” password is “specialist.”

So, where would you go for this treasure-trove?  Try RedOracle.  They have over 400 computer hardware and software brands listed, some with over 200 equipment / account combinations.  Having discovered this site, try picking up one of the more obscure default passwords – you’ll find that there are plenty of other sites with the same information, in case you were hoping that this was an obscure one-off. 

In case you’re wondering, no, RedOracle isn’t (or doesn’t seem to be) a hackers site.  They are a group of people based in Italy with a strong interest in security and who operate on the premise that the more everyone knows (including default passwords) the better we will all be at securing out systems.

So, there’s definitely a lesson here – change the default password!  Doing so won’t guarantee that the hackers can’t break in, but why make their like easy.

Perhaps I could suggest you visit this site to see if your closely-guarded administrator password is listed there. 

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter