Vulnerability Development mailing list archives

Re: Default passwords using Cisco ConfigMaker


From: gaus () CISCO COM (Damir Rajnovic)
Date: Wed, 5 Jul 2000 11:54:28 +0100


Hello there,

I was hoping that someone will made a remark but there was no takers.

There is no default passwords in Cisco IOS.

It is true that 'cisco/cisco' or 'cc' or 'c' are probably the most
likely candidates but that is up to the users. It is how they are
choosing their passwords.

I would also like to ask authors of web pages with default passwords
to insert a comment in this sense on those pages. Please do differ
the default password from a common user setting. We are trying to
discourage users from using cisco/cisco but it is hard. I am thinking
to put a code into IOS that will reject cisco as a password.

At 09:29 05/07/2000 +0200, Runar Jensen wrote:
Regarding the default passwords thread, I seem to remember noticing some
rather annoying
behavior when testing Cisco's ConfigMaker to configure a Cisco router.

I will take a look into this and, if this is true, I will see that
it is changed and default password removed.

Cheers,

Gaus
==============
Damir Rajnovic <psirt () cisco com>, PSIRT Incident Manager, Cisco Systems
<http://www.cisco.com/warp/public/707/sec_incident_response.shtml>
Phone: +44 7715 546 033
4 The Square, Stockley Park, Uxbridge, MIDDLESEX UB11 1BN, GB
==============
There is no insolvable problems. Question remains: can you
accept the solution?


Current thread: