Penetration Testing mailing list archives

Re: Default Admin Account


From: David Howe <DaveHowe.Pentest () googlemail com>
Date: Wed, 11 Feb 2009 10:12:18 +0000

J. Oquendo wrote:
If you leave your front door open, you'd be the idiot
in the sense of being so trusting that anyone driving
down your street isn't going to enter your home. Whether
its a curious neighbor checking inside to see if all is
alright with you, to the curious and mischievious teens
walking by on their way home, to the opportunistic
thieve looking to run in and out, to the professional
burglar coming by with a moving van.

I am not sure that this amounts to leaving it open - more like you have
a standard issue lock with its key number clearly printed on the front,
and the burgler turned up with a dozen of the most common keys already
in his pocket so he could look though them to see if he had that one....
The sytsem was clearly locked, that the password could be easily
discovered didn't alter the fact you still had to take deliberate steps
to discover it. Its not like telnet to the system gave you "hit any key
to start".



Current thread: