The risks of using default passwords
Any systems that use password authentication processes are at risk of being attacked and hacked. This is not just limited to local area networks, but expands to the Internet as well.
Attackers can easily obtain default passwords and identify internet-connected target systems. Passwords can often be found in product documentation and compiled into lists that are readily available on the Internet. It is also possible to identify such systems using specialized search engines, or viruses that are programmed to exploit any or all of the following:
- Security flaws in universal plug and play devices.
- Security flaws in serial port servers.
- Browser flaws.
- Utility program flaws.
Some ways that you can prevent attacks from being successful are:
- Use unique default complex passwords.
- Use alternative authentication methods such as Kerberos, x.509 Certificates, public
- keys, or multi-factor authentication.
- Force default password changes for all users and systems where this will is allowed.
- Restrict Network access as appropriate.
It’s important to Identify affected products and secure them as appropriate.
Some examples of these are:
- Routers, access points, switches, firewall’s, and other network equipment.
- Databases.
- Web applications – This would include Web browser vulnerabilities
- Industrial Control Systems (ICS).
- Other embedded systems and devices.
- Remote Terminal interfaces like Telnet and SSH.
- Administrative Web Interfaces.
- VPN’s
If you would like regarding the above, please contact the CCS Retail Systems Support Department.
– John
