Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suggestion: condense "weak password finding" #84

Open
7MinSec opened this issue Jan 26, 2025 · 0 comments
Open

Suggestion: condense "weak password finding" #84

7MinSec opened this issue Jan 26, 2025 · 0 comments

Comments

@7MinSec
Copy link

7MinSec commented Jan 26, 2025

Hello!

On a recent pentest I did an invoke-sqlaudit with a cred I found on a file share and that server had ~50 accounts on it, 30 of which had default/weak creds. The PowerUpSQL report then has 30 entries talking about the weak login password vulnerability. It would kind of be nice if the vulnerability was listed once and then said something at the end like "Here are a list of the affected credentials:

  • Username: test, password: test
  • Username: dbguy, password: dbguy
  • etc.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant