Hardcoded Passwords

Some of these vulnerabilities look more like backdoors

170 points · 6 comments · view on lemmy.world

6 Comments

MajorHavoc@programming.dev · 12 pts · 1y

It's not just hard-coded. That would be dangerous.

We have a backup of it on a post-it attached to the big monitor in the ops center.

MelodiousFunk@slrpnk.net · 11 pts · 1y

I recall many moons ago needing to migrate monitoring software to a new environment, and the original admins were no longer with the company. We didn't have the SQL password, so we couldn't make any changes. After a while in with tech support, we got transferred to someone else. That person let us know where in the file structure the plaintext doc containing the password lived.

I wish I was joking.

dharmacurious@slrpnk.net · 9 pts · 1y (1 reply)

Alternative name for the one labeled migrain: the zuko

Arthurbodhi@lemmy.world · 1 pts · 1y

I hate the lighting zukos (migraine with aura).

Anticorp@lemmy.world · 6 pts · 1y

Fifth type: 2FA for trivial shit you don't care about that you can't opt out of.

Thcdenton@lemmy.world · 1 pts · 1y

If it's hardcoded then I don't know about it, it's not real and it can't hurt me.