We all know that you should have good secure passwords and you can enforce this in Active Directory, but it is the other applications on the network that might raise a concern.
I got a helpdesk ticket saying that the password for a Peachtree database was not the normal one....the password that was the same as the company name! After trying password, no password I then discovered that a google search for Peachtree password removers comes up with tons of hits but no free ones. The shareware ones were about 60 bucks for a corporate licence but about $30 for personal use. However, one of them would demonstrate that it could actually break the password by revealing the first two characters of the password. I thought this might give me and the user a clue as to what the password could be. When the first two characters were revealed to be 12 it didn't take the user long to realise what the password was and they got it on the first attempt.
Sometimes it is really hard to demonstrate the reasons that passwords should be used and you would have thought that the importance of security and a good password for company financial data would be recognised...
I wonder what will happen if at the next Board meeting I do a demonstration of insecurity with LIVE data.....
Some users w/d on't learn.
Categories:
1 Comments
Categories
- .Net (1)
- 404 pages (4)
- ADP (1)
- ADSL (5)
- AIX (7)
- ASP (4)
- ActiveSync
- Adsense (2)
- AmericanFootball (1)
- AntiSpyware (1)
- AntiVirus (18)
- Apache (5)
- Audible Books (3)
- Audio (4)
- AximElated (13)
- B2 (2)
- Backup (13)
- BackupExec (3)
- Backups (7)
- Banking (3)
- Belkin (2)
- Beta Testing (9)
- Blackberry (7)
- Blog2MT (5)
- Bloggar (2)
- Blogger (4)
- Blogging (52)
- BlueJackq (1)
- Bluetooth (4)
- Books (19)
- Buckeyes (1)
- Bugs (40)
- CSS (23)
- Car (6)
- Cats (6)
- Chat (6)
- Christian (3)
- Church (3)
- Cold (1)
- Computer Hardware (5)
- Concerts (9)
- Control Panel Backup (3)
- Creative Zen (3)
- Customers
- DNS (4)
- DST (6)
- DVD Burning (1)
- Defender (1)
- Deferred
- Dell (16)
- Directories (2)
- Disaster Recovery / Restores (13)
- Domain Names (3)
- Domain migration (1)
- Dreamhost (3)
- Eating Out (1)
- Email (38)
- England (3)
- Evernote (4)
- Exams (5)
- Excel (2)
- Exchange / Outlook (85)
- Extensions (10)
- Facebook (1)
- Films (26)
- Firefox (40)
- Firewalls (9)
- Fitness (1)
- Flash (2)
- Flash Mobs (8)
- Flickr (21)
- Food (10)
- FriendsInTech (9)
- Froderick (1)
- Funny Pages (100)
- GPS (20)
- Games (7)
- Garmin (3)
- Geoblogging (10)
- Geocaching (18)
- Geotagging (3)
- Ghost (2)
- Gmail (9)
- Gnomads (1)
- Google (38)
- GoogleMaps (5)
- Greasemonkey (19)
- Group Policy (2)
- Hacking (10)
- Hasweb (5)
- Holidays (13)
- Home repairs (1)
- Hosting (15)
- Hotfixes (4)
- IBM (1)
- IIS (7)
- ISP's (2)
- Imported Blog (996)
- Installed Greasemonkey Scripts (13)
- Instant Messaging (2)
- Internet Explorer (14)
- Intuit (1)
- Itunes (2)
- Java (1)
- Job Hunting (3)
- KVM (1)
- Laptops (5)
- Library (4)
- Links (4)
- Linux (5)
- Live Communication Server (3)
- Lotus Notes (9)
- MBSA (1)
- MP3 (3)
- Mambo (1)
- Mandrake (6)
- Maps (3)
- Meme (1)
- Microsoft (80)
- Microsoft Max (1)
- MovableType (65)
- Moving to the states (28)
- Mozilla (14)
- Music (35)
- Networking (12)
- News (28)
- ODBC (1)
- Odeo (1)
- Office (20)
- OneCare (4)
- OneNote (4)
- Other Blogs (25)
- PHP (14)
- Patches (13)
- Perl (1)
- Photo Friday (2)
- Photos (76)
- Pipex (3)
- PocketPc (12)
- Podcast (8)
- Popfile (1)
- Powerpoint (1)
- Powershell (2)
- Powertoys (2)
- Privacy (1)
- Productivity (1)
- Programming (2)
- Qiq hosting (1)
- Quickbooks (1)
- RSS Feeds (30)
- RSS Readers (23)
- Rants & Complaints (30)
- Real Life (117)
- Remote desktop control (6)
- Resource Kits (4)
- Restaurants (3)
- RevDrives (2)
- SBS (15)
- SQL (4)
- Sage (2)
- Scenery (1)
- ScreenCaptures (1)
- Scripting (6)
- Search Engines (34)
- Security (84)
- Settling in (27)
- SharedView (1)
- Sharepoint (2)
- Shopping (45)
- Skype (9)
- Software Reviews (3)
- Spam (63)
- Sprint (1)
- Spyware (26)
- Support (4)
- Symantec (27)
- Synctoy (1)
- TV (9)
- Tater (1)
- Taxes (1)
- Technet (4)
- Telephones (36)
- Terminal Services (9)
- Theatre (5)
- Thunderbird (2)
- Timeslips (2)
- Toshiba (12)
- Training (7)
- Tutorials (1)
- UK Locations (2)
- Ubuntu (4)
- Uniform Server (4)
- Utilities (56)
- VOIP (4)
- VPN (7)
- Veritas (2)
- Virtual PC (6)
- Virus (69)
- Visio (1)
- Vista (8)
- Visual Basic (1)
- Visual Studio (1)
- Vmware (1)
- W.Bloggar (2)
- WHS (9)
- WRT54G (1)
- WSUS (26)
- Web Browsers (18)
- Webcams (1)
- Webservers (9)
- Windows 2000 (50)
- Windows 2003 (26)
- Windows NT (6)
- Windows Update (25)
- Windows XP (46)
- Wireless (25)
- Wordpress (13)
- Work (55)
- XPSP2 (16)
- Zoo (1)
- Zooomr (8)
- bookmarking (1)
- ie7 (3)
- ipod (1)
- pumpkin (1)
Monthly Archives
- March 2008 (1)
- February 2008 (11)
- January 2008 (14)
- December 2007 (17)
- November 2007 (26)
- October 2007 (10)
- September 2007 (11)
- August 2007 (12)
- July 2007 (11)
- June 2007 (18)
- May 2007 (19)
- April 2007 (15)
- March 2007 (28)
- February 2007 (26)
- January 2007 (14)
- December 2006 (10)
- November 2006 (13)
- October 2006 (16)
- September 2006 (15)
- August 2006 (24)
- July 2006 (24)
- June 2006 (32)
- May 2006 (19)
- April 2006 (22)
- March 2006 (29)
- February 2006 (30)
- January 2006 (23)
- December 2005 (20)
- November 2005 (35)
- October 2005 (41)
- September 2005 (39)
- August 2005 (63)
- July 2005 (65)
- June 2005 (52)
- May 2005 (30)
- April 2005 (34)
- March 2005 (50)
- February 2005 (57)
- January 2005 (54)
- December 2004 (21)
- November 2004 (33)
- October 2004 (41)
- September 2004 (33)
- August 2004 (46)
- July 2004 (35)
- June 2004 (25)
- May 2004 (37)
- April 2004 (38)
- March 2004 (47)
- February 2004 (58)
- January 2004 (88)
- December 2003 (69)
- November 2003 (65)
- October 2003 (68)
- September 2003 (78)
- August 2003 (129)
- July 2003 (123)
- June 2003 (69)
- May 2003 (78)
- April 2003 (67)
- March 2003 (76)
- February 2003 (77)
- January 2003 (94)
- December 2002 (39)
- November 2002 (43)
- October 2002 (74)
- September 2002 (123)
- August 2002 (70)
- July 2002 (56)
- June 2002 (66)
- May 2002 (91)
- April 2002 (27)
- March 2002 (33)
Pages
Search
About this Entry
This page contains a single entry by published on November 21, 2007 5:10 PM.
Ironic BSOD was the previous entry in this blog.
Happy Thanksgiving. is the next entry in this blog.
Find recent content on the main index or look in the archives to find all content.

Reminds me of the time I had to get into the MIS (computer systems) Director's computer at one place I worked, which was at the parent company offices in another state, while he was on vacation. His computer name and username were(like every other logon in the company except mine, my coworker's, and a handful of machines named by purpose) his first name and the first initial of his last name.
Nobody was in the office at the time, and I needed project files to continue what I was supposed to be working on, so just on a hunch I tried....the username as the password. And got in. Most every other computer in the company also had the same setup of username/password/computer name being identical.
That's not to mention the SQL server with no password that included, among other things, the entire personnel database with names, addresses, phone numbers, social security numbers, and photographs.