in reply to Brute forcing account logins.

I can't speak for the switches or routers, but you have a list you can't trust for passwords on servers whose status you don't know. I'd be thinking about live disks and commenting out the root password in /etc/shadow.

Replies are listed 'Best First'.
Re^2: Brute forcing account logins.
by plobsing (Friar) on Apr 29, 2008 at 19:03 UTC
    If he had access to the shadow file, he could just hash the passwords and create a lookup table to run on the shadow files.