0x00 what is a weak password
The weak password is not strictly or accurately defined. Generally, it is considered that the password that is easily cracked by someone else (they may know you well) is weak.
Weak passwords refer to passwords that only contain simple numbers and letters, such as "123" and "abc", because such passwords are easily cracked by others, in this way, the user's Internet account is controlled by others, so it is not recommended for users.
0x01 why weak passwords are generated
This should be related to personal habits and consciousness. To avoid forgetting the password, use a password that is easy to remember, or directly use the default password of the system.
Lack of security awareness, I always think that no one will guess my weak password.
0x02 hazards of weak passwords
In today's world where user names (Accounts) and passwords are used as authentication, the importance of passwords can be imagined.
The password is equivalent to the key to enter the home. When someone else has a key to enter your home, think about your security, your belongings, and your privacy.
Because weak passwords are easily guessed or cracked by others, it is very dangerous if you use weak passwords, like placing the house key under the mat at the door.
How many weak passwords or default passwords exist on the Internet?
As of the beginning of this article, wooyun has submitted as many as 778 weak password vulnerabilities on the platform. In addition to data leakage, many of them can use weak passwords to obtain server permissions.
Most of the vulnerabilities reported here are weak passwords such as background management and O & M servers.
What about the personal accounts of netizens?
After 11 years of CSDN plaintext password leakage, several large Internet enterprise user data were leaked one after another.
A large number of internet users share the same account and password, leading to a data leak. Other Internet accounts are also affected.
The author thinks that your password is not a weak password on the surface, but it has been known by others and can be within the weak password range.
After reading this, you should know that after such a long period of time, many users still haven't changed their common passwords when many Internet vendors have notified users to change their passwords.
0x03 Solution
The weak password for the background or network administrator is better solved, and the password strength of all management system accounts must reach a certain level.
You cannot use weak passwords such as admin and 123456. A list of frequently used passwords is provided for you to search for your own weak passwords (for illegal purposes ).
Weak Password top100:
123456789a123456123456a1234567891234567890woaini1314qq123456abc123456123456a123456789a147258369zxcvbnm98765432112345678910abc123qq123456789123456789.7708801314520woaini5201314520q123456123456abc1233211234567123123123123456.0123456789asd123456aa123456135792468q123456789abcd12345612345678900woaini520woaini123zxcvbnm1231111111111111111w123456aini1314abc123456789111111woaini521qwertyuiop13145205201234567891qwe123456asd12300000014725836901357924680789456123123456789abcz1234561234567899aaa123456abcd1234www123456123456789q123abcqwe123w1234567897894561230123456qqzxc123456123456789qq111111111111111111100000000000000001234567891234567qazwsxedcqwerty123456..zxc123asdfghjkl00000000001234554321123456q123456aa9876543210110120119qaz123456qq52013141236987455201314000000000as1234561231235841314520z12345678952013145201314a123123caonimaa5201314wang123456abcd123123456789..woaini1314520123456asdaa123456789741852963a12345678
In the case that leaked databases cause Internet accounts for Internet users to be stolen, in addition to teaching Internet users to modify common passwords, website passwords should be as general as possible.
Internet companies also have some technical restrictions to prevent Account Verification in batches.
For example, unified logon interfaces, frequent logon errors, verification codes triggered, too many blocked ip addresses verified per unit time, and so on.
I believe that many Internet enterprise security personnel have fought with people who hit numbers in batch to obtain user value for a long time :)