The report collects 1.8 million leaked information from administrator accounts, with more than 40,000 using "admin" passwords
CTOnews.com, Oct. 18, the network security company collected more than 1.8 million system administrator credentials from January to September this year and found that more than 40,000 administrator passwords are "admin", indicating that many IT administrators have not changed the default password.
Outpost24 said that the 1.8 million administrator account credentials collected this time came from various malware that stole information. After analyzing the collection of authentication credentials of the management portal, Outpost24 summed up the top 20 weakest authentication credentials. CTOnews.com attached the following list:
01. Admin
02. 123456
03. 12345678
04. 1234
05. Password
06. one hundred and twenty three
07. 12345
08. Admin123
09. 123456789
10. Adminisp
11. Demo
12. Root
13. 123123
14. Admin@123
15. 123456aA@
16. 01031974
17. Admin@123
18. 111111
19. Admin1234
20. Admin1
The researchers warn that the above entries are "limited to known and predictable passwords", but these are administrator account passwords, and if the attacker successfully invades, more user information will be affected.
To protect against information theft malware, Outpost24 recommends using endpoints and detection response solutions, disabling password saving and auto-filling options in web browsers, checking domains in the event of redirects, and staying away from cracked software.