thainnos / LICSTER

A Low-cost ICS Security Testbed for Education and Research
Other
100 stars 33 forks source link

Hardcoded Account leftover #33

Closed minkione closed 4 years ago

minkione commented 4 years ago

Hi guys Just FYI I found these creds in there and looks still valid (of course 2FA for the rescue :) ) https://github.com/hsainnos/LICSTER/blob/406b4fa1049f7159a5138ae92a144b92a0968147/devices/hmi/LogReader/breachmail.py#L9

mniedermaier commented 4 years ago

Thanks,

yes I think this is the test account of my student group :) I removed the credentials in 781e163bef6809242ef7830a428afa538f8ec060 and let them change the password.