-
Book Overview & Buying
-
Table Of Contents
The Web Application Hacker's Handbook
By :
Even the simplest of web servers comes with a wealth of configuration options that control its behavior. Historically, many servers have shipped with insecure default options, which present opportunities for attack unless they are explicitly hardened.
Many web servers contain administrative interfaces that may be publicly accessible. These may be located at a specific location within the web root or may run on a different port, such as 8080 or 8443. Frequently, administrative interfaces have default credentials that are well known and are not required to be changed on installation.
Table 18.1 shows examples of default credentials on some of the most commonly encountered administrative interfaces.
Table 18.1 Default Credentials on Some Common Administrative Interfaces
| Username | Password | |
| Apache Tomcat | admin | (none) |
| tomcat | tomcat | |
| root | root | |
| Sun JavaServer | admin | admin |
| Netscape Enterprise Server | admin | admin |
| Compaq Insight Manager... |
Change the font size
Change margin width
Change background colour