[prev in list] [next in list] [prev in thread] [next in thread] 

List:       jaxlug-list
Subject:    Poor Security [was Re: [JaxLUG] Peter Crafford/Rnd/Intralinks_NY is out of the office.]
From:       Ozz <ozzden () charter ! net>
Date:       2004-04-25 0:34:49
Message-ID: 200404250035.i3P0ZExW071287 () mxsf08 ! cluster1 ! charter ! net
[Download RAW message or body]


On Saturday 24 April 2004 07:50 pm, Jim Wharton wrote:
>
> The mere fact that that is a default Outlook 97/98/2000 "vacation"
> message shows that the sender is not very security conscious... (yep, I
> was forced to use that stuff for a long time.)
>
> try:
>
> user: root
> password: password
>
> That oughta get you a shell...

I recently aquired a pair of drives for a SUN box.  They still had the 
O/S on them (Solaris 2.6), along with the user data.

user: root
password: root

was all that was required to attain God-mode.

And these were from an Internet-connected production server!

And no, I'm not kidding...

Regards,
Ozz.
(Who never allows passwords of less than 8 characters, and runs john 
regularly.)
_______________________________________________
Jaxlug-list mailing list
http://mailman.jaxlug.org/mailman/listinfo/jaxlug-list
Send email to jaxlug-list-admin@jaxlug.org for any problems.
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic