The Jerusalem PostPalestinian election candidate warns West Bank could ‘explode’ unless Israel releases tax fundsESPN Deportes¿Quién es el hacker que destapó el dopaje financiero del Man. City?InquirerUnhealthy air quality for sensitive groups in parts of Metro Manila – DENRRTP DesportoEm ambiente conturbado. Portugal defronta Dinamarca após saída de Cristiano RonaldoESPNJoey Porter Jr. traded: What move means for Cowboys, SteelersDaily MaverickLOCAL ELECTIONS 2026: Navigating ballots, candidates, and wards: Your guide to the 2026 local government electionsVarietyParamount, CNN Chief Mark Thompson in ‘Early Stages’ of Discussions to Keep Him in PostIl Sole 24 OreStadi e concerti, con le ondate di calore i raduni accrescono rischi e decessiRai NewsChioggia, viene rimproverato dal padre e lo ferisce con un utensile da cucina: 17enne in casermaSportstarSouth Africa World Cup 2027 Schedule: Full Fixtures, Dates, Venues and OpponentsBBC NewsBurnham's Man City comments 'completely out of touch', Tories sayCBS NewsBolivia's attorney general arrested for alleged money laundering, drug trafficking
The Daily Newsstand · Free, Always
Thursday, October 1, 2026

CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

Translate

Welcome back to PWNED, the weekly column where we warn you about weak security practices. This week’s terrifying tale involves a lack of important patching and a humorously bad password belonging to the person in charge of tech security at a law firm.

Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.

Our story comes courtesy of Joe Brinkley, who also is known as “The Blind Hacker” and has more than two decades of experience in information security. Joe was called in several years ago by a large, national law firm that wanted him to penetration test a smaller business they were about to acquire. What he discovered was a huge security hole and an even bigger embarrassment.

REG AD

Brinkley had audited the same law firm the previous year. At that time, he noted a number of holes and the attorneys had dutifully spent time and money on security software from the likes of Reliaquest and Dell to remediate what he found.

REG AD

“I shredded them. They were not in a very good security posture,” Brinkley told us. “They spent probably a half a million dollars to get patching and get through these things because they were trying to go through a merger and acquisition.”

Unfortunately, even with their investment, the company failed to patch its Windows machines against BlueKeep, a major remote code execution vuln that was discovered, patched, and exploited in 2019. BlueKeep affects many versions of Windows, including Windows 2000, Windows Server 2008 R2, and Windows 7. Related vulns called DejaBlue also affected Windows 10. 

BlueKeep and its related security risks involve a flaw in Windows’ Remote Desktop Protocol that allows attackers to gain entry and execute remote code via port 3389. The vuln is wormable so an attacker could make it spread from one system to another. However, none of this filtered through to become a priority for the law firm.

During his pentest, Brinkley used the BlueKeep vuln to get access to the org’s systems, where he found that the passwords were stored in plain text and easy to dump into a file, no decryption necessary. 

The usernames on the system were cleverly designed for security by obscurity. Instead of using the user’s real name or something like “admin,” they had names like “Yellow Banana” and “Red Apple” so attackers could not guess which one had the most privileges.

Brinkley had no idea who Yellow Banana was, but he found that person’s password and it was perhaps the tackiest idea of a login we’ve ever heard. The password was “r3@lg00dp@$$w0rd,” which is “realgoodpassword” with some symbols and numbers substituted for letters. 

Not knowing who made the security faux pas, he took the password and included a screen shot of it in a presentation he delivered on system vulnerabilities that he gave to the law firm’s execs. While he was explaining that he had managed to penetrate 2,500 of the org’s computers, the CISO suddenly dropped an f-bomb.

“Why the f*** is my password on the screen?” he complained, giving away the fact that he was Yellow Banana and thought that r3@lg00dp@$$w0rd was a good idea.

REG AD

So what can we learn from this tale of legal embarrassment? Always patch your Windows systems as soon as new patches become available and never use a cutesy password. Enabling 2FA and encrypting the passwords would probably have helped too.  ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.