Welcome | Sign In
ECommerceTimes.com
Security

Administrators Urged To Defend Systems Passwords

Print Version
E-Mail Article
Reprints
Administrators Urged To Defend Systems Passwords

A cursory online search will reveal numerous sites giving the default user and password combinations for thousands of devices and applications. This data is handy when inheriting or resetting old applications or devices. But it is also a free library for those who pursue the intrusion of others' networks for fun or theft.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

A recent vulnerability found in the popular open-source database MySQL revealed a persistent problem for IT managers: password management among administrators.

Most talk about password security traditionally centers around end users and the use of weak, easy-to-guess passwords. In companies where administrators have policies dictating more difficult passwords, one can stroll around and find passwords on sticky notes hanging from monitors.

What may go ignored are the passwords of administrators who have access to the most critical systems in a business, often containing the most sensitive data. While at a minimum administrators should be required to use more complex passwords, it is the default password on hardware and in software applications that may slip through the due diligence of installation and deployment.

System Default Passwords

Most software and hardware comes with some sort of default administrative account to enable initial setup.

A cursory online search will reveal numerous sites giving the default user and password combinations for thousands of devices and applications.

This data is handy when inheriting or resetting old applications or devices. But it is also a free library for those who pursue the intrusion of others' networks for fun or theft.

Thomas Kristensen, chief technology officer for security firm Secunia, said his firm does not usually make a big deal Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse about default passwords, because they expect administrators will change them.

"However, we do write about certain types of these issues when the user names and passwords are undocumented, hidden or not easily changed," he said.

Larry Rogers, senior technical staff member at the CERT Coordination Center at Carnegie Mellon University, believes failing to change default passwords is a symptom of a larger problem among system administrators.

"It seems that defaults of many kinds are not changed by system administrators when they install systems. Passwords are only one good example," he said.

Forcing Password Change

Kristensen thinks the best approach is to have default accounts either disabled by default or to force password changes during configuration.

"At the very least, the documentation should clearly list and identify the default accounts and how to change them," Kristensen added.

CERT's Rogers agrees that it is a better practice to enable technology, where present, to force password changes, especially if that technology remembers previous passwords and disallows their reuse. However, that comes with a caveat.

"On the downside, this practice can force [administrators] to manufacture hard-to-remember passwords. These in turn may force them to commit those passwords to paper which at times is attached to a monitor or hidden under a keyboard."

Rogers said one has to decide if the cure is worse than the disease.

The Pass Phrase

The concept of the pass-phrase replacing the password has been an item of discussion in many circles. Instead of using "P@ssworD" one could use "My favorite book is Fahrenheit 451," for example.

Rogers suggests that a pass-phrase slows down a cyber-intruder by being less guess-able than a traditional six or seven-character password. However, he sees this as a short-term fix.

"If those pass phrases traverse a network whose traffic can be captured and therefore reused, the difference between a password and pass-phrase is negligible," Rogers said.

Kristensen suggests that administrators migrating to pass-phrases would improve security to some extent.

More important to Kristensen is using a variety of passwords. "While it may be tempting to use the same password or slights variants of the same for many different places and systems, it could lead to an easy and wide-scale intrusion if the password was compromised."

User Credentials

The MySQL incident very likely caused systems managers to step back and consider evaluations of the hardware and software in production for other possible weak default accounts.

In his view, Kristensen encourages a best-practice policy of ensuring proper configuration at deployment. And a regular audit of system credentials is a good habit, with the frequency decided based on the sensitivity of the systems and available resources.

"A regular scan or audit using a good vulnerability scanner ought to aid in the detection of default accounts and accounts with weak passwords," Kristensen added.


Print Version E-Mail Article Reprints More by Blane Warrene


More by Blane Warrene

New Book Offers Tips for Aspiring OS X Experts
March 17, 2005
Mac OS X Power Hound, Panther Edition. By Rob Griffiths. Pogue Press/O'Reilly, 2004. 538 pages. Paperback. US$24.95.
Navigating Open-Source Licenses Can Be Tough Task
February 21, 2005
Eric Raymond, founder of the Open Source Initiative, thinks the only strategy that makes sense in the environment created by modern intellectual property law is to do just enough of a pro forma review to have it on the record that you did one, then basically ignore your risks until and unless you get sued.
The US Copyright Office's Rob Kasunic on Internet Law
February 08, 2005
In the digital environment, where massive infringement is so easy to accomplish with the click of a mouse, enforcement alone is seldom enough to reassure creators. Adequate legal and technological protection for copyrighted works is important.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network