A recent report by the cyber security firm Rapid7 lists the top usernames and passwords used by hackers to attack your servers. During the past 334 days, the firm placed honeypots to collect such login attempts and record the data.
Under this project, Rapid7’s servers collected 221,203 login attempts that were spread across 119 countries and came from 5,076 IP addresses. During these attempts, hackers tried to break the system using 1,809 different usernames and 3,969 passwords.
The test also measured the complexity of the passwords. The findings showed that the majority of passwords attempted were very simple, indicating the widespread use of convenient passwords and ignorance of security risks.
If we look at the username attempts that were made, a similar trend was observed. The top most tried out usernames were “administrator” (77, 125 times), “Administrator” (53,427 times), and “user1” (8,575 times). Here’s the complete top 10 list of most attempted usernames by hackers:
It should be noted that most of the login attempts came from China (88,227 attempts), followed by the US, (54,977) and South Korea (13,182). The other countries in the top 10 are Netherlands, Vietnam, the UK, Taiwan, France, Germany, and Canada.
Have something to add? Share your views in the comments below.
During the past one year, the cyber security firm Rapid7 has been collecting data from Heisenberg — its public-facing network of low-interaction honeypots. The honeypots were made to look like the real-life office, PoS, and kiosk payment systems with their RDP port open.
The test also measured the complexity of the passwords. The findings showed that the majority of passwords attempted were very simple, indicating the widespread use of convenient passwords and ignorance of security risks.
Easy-to-use passwords are easy-to-hack!
Surprisingly, the most tried password was “x” (11,865 times), followed closely by “Zz” (10,591 times) and “St@rt123” (8,014 times). Here’s the top to most attempted passwords by hackers:- x
- Zz
- St@rt123
- 1
- P@ssw0rd
- bl4ck4ndwhite
- admin
- alex
- …….
- administrator
If we look at the username attempts that were made, a similar trend was observed. The top most tried out usernames were “administrator” (77, 125 times), “Administrator” (53,427 times), and “user1” (8,575 times). Here’s the complete top 10 list of most attempted usernames by hackers:
- administrator
- Administrator
- user1
- admin
- alex
- pos
- demo
- db2admin
- Admin
- sql
It should be noted that most of the login attempts came from China (88,227 attempts), followed by the US, (54,977) and South Korea (13,182). The other countries in the top 10 are Netherlands, Vietnam, the UK, Taiwan, France, Germany, and Canada.
Have something to add? Share your views in the comments below.
एक टिप्पणी भेजें