Dutch ISP Discovers 140,000 Customers With Default Password
bs0d3 writes "In Holland, a major ISP (KPN) has found a major security flaw for their customers. It seems that all customers have had the same default password of 'welkom01'. Up to 140,000 customers had retained their default passwords. Once inside attackers could have found bank account and credit card numbers. KPN has since changed all the passwords of the 140,000 customers with weak passwords. They also do not believe anyone has actually been burglarized since discovering this weak spot in security."
had to ban the password abc123 on thier ADSL network years ago..
It's their fault for not (1) randomizing the initial password, and (2) forcing new subscribers to immediately change their password after the first login, both of which are standard practices on properly secured systems.
When I was a sysadmin at a certain Bible college known for its weak security, I collected the password hashes of the students & faculty and ran them through a cracker (John the Ripper if I remember correctly), then sent out a mass email with the decrypted passwords, sorted by the amount of time it took to crack them.
Yeah, the majority of them were cracked within five seconds. Of course, I omitted the information on just whose passwords they were.
Dunno if it resulted in anyone actually doing something about their passwords though.
In times of universal deceit, telling the truth gets you modded -1 Troll
For heaven's sake what's wrong with burgled?
All offending passwords were changed to "welkom02." Crisis averted!
"We have discovered you have been using default password 'welkom01'. This represents a grave security risk. Therefore, we have changed your password to 'welkom02'."
how many pairs of boxer shorts should you own?
Just lost about 140K bots on my net...
No. Well...maybe. Actually, yes. It really just depends.
The only thing missing from your post is something about wooden shoes and windmills. Thanks for the generalization, again.
Just for the record, it's no a normal or common thing to have sex with underage eastern european girls here.
The only thing missing from your post is something about wooden shoes and windmills. Thanks for the generalization, again.
This, and that war-driving has to be done on a bicycle.
KPN didn't discover it themselves. An ICT company did (accidentally even), and reported the flaw to an IT site (webwereld.nl) instead of contacting KPN directly.
Dutch link: http://tweakers.net/nieuws/82955/kpn-maakt-blunder-met-standaardwachtwoord-z-adsl-accounts.html and http://webwereld.nl/nieuws/111057/140-000-kpn-adsl-accounts-lek-door-welkom01-fail.html