OSVDB ID: 870

Title: Enhydra Multiserver Default Password

Info

Disclosure

Feb 18, 2003

Discovery

Feb 18, 2003

Dates

Exploit

Unknown

Solution

Unknown

Description

By default, Enhydra Multiserver installs with a default password. The admin account has a password of enhydra which is publicly known and documented. This allows attackers to trivially access the program or system.

Classification

Attack Type: Authentication Management
Solution: Change Default Setting

Solution

Immediately after installation, change all default install passwords to a unique and secure password. When possible, change default accounts to custom names as well.

Products

Enhydra

Enhydra Multiserver

All Versions

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/870