Penetration Testing mailing list archives

Default Account scanning


From: p1g <killfactory () gmail com>
Date: Thu, 28 Feb 2008 21:39:31 -0500

A few years ago, an audit was performed on the netowrk i worked on.
A tool was use to crawl the network and attempt a login to systems
using the default user name and password.

I have perform this manually by enumerating systems (switches.routers,
appliances) and testing them against default password lists, but I was
wondering if there was a tool out there that handled this type of
automated scan.

I know that Nessus will handle some of this.

Any other tools that come to mind?


TIA

-- 
-p1g
SnortCP, C|HFI, TNCP, TECP, NACP, A+
  ,,__
o"     )~  oink oink
   ' ' ' '

If you spend more on coffee than on IT security, you will be hacked.
What's more, you deserve to be hacked.
-- former White House cybersecurity czar Richard Clarke

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: