Good Passwords for Bad Bots: A Look at Over Half a Million Passwords

Logo
Presented by

Tod Beardsley - Director of Research, Rapid7 and Erick Galinkin - Principal Artificial Intelligence Researcher, Rapid7

About this talk

With the increasing adoption of both remote work and cloud infrastructures, the number of people accessing corporate information systems across the internet has skyrocketed. Many of these systems leverage Remote Desktop Protocol (RDP) and Secure Shell (SSH) for interaction and management. The number of assets that employees connect to from untrusted networks has jumped. As with so many things in security, the addition of convenience and complexity has made the task of protecting these systems far more challenging. Rapid7 recently analyzed a year’s worth of username and password data, with over tens of millions of connection attempts to our RDP and SSH honeypots. After observing 512,002 unique passwords across our RDP and SSH honeypots, we want to share our findings with you. Join this webcast, where we’ll discuss: - What has changed in RDP since 2016 - How the most complete, well-known dictionary used by attackers compares to the corpus of passwords in our honeypots - Recommendations to help organizations do better with passwords
Related topics:

More from this channel

Upcoming talks (34)
On-demand talks (573)
Subscribers (49521)
Rapid7 is creating a more secure digital future for all by helping organizations strengthen their security programs in the face of accelerating digital transformation. Our portfolio of best-in-class solutions empowers security professionals to manage risk and eliminate threats across the entire threat landscape from apps to the cloud to traditional infrastructure to the dark web. We foster open source communities and cutting-edge research–using these insights to optimize our products and arm the global security community with the latest in attackers methods. Trusted by more than 10,000 customers worldwide, our industry-leading solutions and services help businesses stay ahead of attackers, ahead of the competition, and future-ready for what’s next.