|
|
|
|
|
by HenryBemis
2003 days ago
|
|
In most decent frameworks (NIST, COBIT, PCI-DSS) the changing of default passwords, removal of (unecessary) default accounts, and similar controls is a MUST. The network admin who doesn't do that the minute they add a new device on their network should lose their job. The companies who have IT Sec, and IT Auditors who don't check for this should also lose their jobs (or they should all get educated and keep their jobs). These are basic stuff, a newbie IT should know these things. I will also assume that (large) organizations test the updates, and have an action plan in place (i.e. apply fix/patch/update XYZ, study what it does, read the documentation, make the future-state-config, deploy that config, validate the config). I know, simple words, we 'all' (in the profession) know this but when you need to patch x1000, and the boss is barking....... |
|
Therefore auditors will look and find nothing, but the accounts are buried there within the system if you know about them (i.e. by exploring a firmware dump and finding the password hash and reversing it).