Mothers, don’t let your babies grow up to use the ‘admin’ username

Share this post

There are many blog posts, articles, training materials and all sorts of content admonishing people to pick good passwords. But there is not nearly the same volume of content discussing good username selection. Administrators especially should be cognizant of good usernames to reduce the risk of an attack.

Here at Fractional CISO we took a look at a week’s worth of failed logins on our website and the username distribution is stunning.

admin failed username login

 

For a given week there are a large number of failed logins for administrative usernames that do not exist on the website. Presumably these are malicious attacks by outsiders. (We know that we didn’t unsuccessfully try to login.) Furthermore the distribution of those usernames is remarkably narrow. Sixty-plus percent of the failed logins use the ‘admin’ or ‘administrator’ username on the site. Many of the other usernames are website name related. Only a small percentage of the attempted hacks are with other types of logins. This week’s data was typical of the failed login data on the site.

From this data we can learn a lot about good username selection. Don’t create users with the admin or administrator name. Don’t create users with a variation of the website or system name. Additionally, although it is buried in other category don’t use ‘www’ or a name of one of the bloggers on the site.

Do you think that these recommendations are specific to one website? Looking at the data from other attacks such as the mirai botnet we can confirm that ‘admin’ or a variant is a common username attack. Eighty-five percent of the mirai usernames were ‘admin’, ‘administrator’, an admin variant, ‘root’ or ‘guest’. The mirai botnet was able to successfully attack thousands of devices trying only a small number of usernames.

Unlike password selection, username selection need not be complex. Pick a name, uncommon word or made-up word  as your username. Simple preventative measures such as these can radically reduce the risk of website or system compromise.

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales