Full Disclosure mailing list archives

Re: Re: IRCXpro 1.0 - Clear local and default remote admin passwords


From: "morning_wood" <se_cur_ity () hotmail com>
Date: Tue, 3 Jun 2003 10:40:32 -0700

2. Remote default admin enabled
Our Reply: The user is prompted before the server starts for the first
time
to set their own Operator Name and Password during the Initial Wizard for
their administrator account.  (See initial.gif file attachment)

Look in your .gif and you will note
user:admin
password:password

with a "next" prompt. 90% of users will select "next" blindly.

Donnie Werner
http://exploitlabs.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: