Hacker News new | ask | show | jobs
by jlgaddis 2373 days ago
Yep, I personally bought a Cisco firewall off of eBay several years ago that still had its entire configuration on it, including the PSKs for several IPSec VPN connections as well as SNMP (v2) communities, weak "type 7" hashes for local user accounts, the shared secrets for a pair of RADIUS servers, and so on.

Pretty much all of them (with the exception of the VPN PSKs) were sufficiently "generic" enough that I was convinced that they weren't device-specific, i.e., they were probably shared across many such devices.

According to the login banner, the firewall came from a casino.

I'm certain that my experience was not a unique one.