Guessable credentials found

Published on 24 Jun 2018
Vulnerability

The guessable credentials can find in most of the application. It may add for the testing purpose or an initial setup and later forget about it and added to the production server. Usage of common usernames and password leads to a successful brute-force attack. The most common used username and password combos gave below.

  • admin: admin
  • admin: password
  • admin: 12345
  • Administrator: password

Even if it have brute-force prevention mechanism, most of the attackers first check manually with above credentials or use the framework default username and password.

Impact

Chances of a high success rate in the brute-force attack

Mitigation / Precaution

Beagle recommends the following fixes:-

  • Implement a strong password policy consisting of a combination of alphanumeric characters and a minimum length of 8 characters.
  • Use an anti-brute-force mechanism like captcha.
Febna V M
Written by
Cyber Security Engineer

Febna once spent an entire evening arguing with an AI chatbot just to prove that machines can be confidently wrong. The debate ended with no clear winner, but it did spark her curiosity for the fascinating world of artificial intelligence. Today, she works at the intersection of AI and cybersecurity, helping build smarter systems while making sure they don’t become too smart for their own good. When she’s not exploring the future of technology, she’s probably asking “but what if?” one more time.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo