The only manufacturer default passwords I am aware
of are 'hponly', for mgr.telesup, 'lotus', for mgr.sys, and
'hpword' for field.support.
Just remember to try the various parts of the account as a
password, and anything else along those lines.
If you need a password for the following user.accounts &
groups, try the various parts of the name plus any
combinations of it or names with obvious links to it(ie:
field=service).
COMMON ACCOUNTS:
Username.Account
----------------
mgr.3000devs
mgr.acct
mgr.backup
manager.blast
manager.blast1
mgr.ccc
spool.ccc
mgr.cnas
manager.cognos
mgr.cognos
operator.cognos
mgr.common
mgr.company
mgr.conv
mgr.corp
mgr.cslxl
mgr.demo
operator.disc
mgr.easy
mgr.easydev
mgr.extend
mgr.hpdesk
mgr.hplanmgr
field.hpncs
mgr.hpncs
advmail.hpoffice
deskmon.hpoffice
mail.hpoffice
mailman.hpoffice
mailroom.hpoffice
mailtrck.hpoffice
manager.hpoffice
mgr.hpoffice
openmail.hpoffice
pcuser.hpoffice
spoolman.hpoffice
x400fer.hpoffice
x400xfer.hpoffice
wp.hpoffice
mgr.hponly
mgr.hpoptmgt
field.hpp187
mgr.hpp187
mgr.hpp189
mgr.hpp196
mgr.hppl85
mgr.hppl87
mgr.hppl89
mgr.hppl96
mgr.hpskts
mgr.hpspool
mgr.hpword
mgr.hpx11
dpcont.hq
mgr.hq
mgr.indhpe
mgr.infosys
mgr.intx3
manager.itf3000
mail.mail
mgr.netbase
mgr.netware
operator.netware
mgr.orbit
mgr.prod
mgr.rego
mgr.remacct
mgr.rje
manager.security
mgr.security
mgr.sldemo
mgr.snads
mgr.softrep
mgr.speedwre
mgr.spool
manager.starbase
field.support
mgr.support
operator.support
exploit.sys
manager.sys
mgr.sys
operator.sys
pcuser.sys
rsbcmon.sys
operator.syslib
sysrpt.syslib
mgr.sysmgr
operator.system
mgr.tech
mgr.techxl
mgr.telamon
field.hpword
mgr.opt
manager.tch
field.telesup
mgr.telesup
sys.telesup
mgr.tellx
monitor.tellx
mgr.utility
mgr.vecsl
manager.vesoft
mgr.vesoft
mgr.word
field.xlserver
mgr.xlserver
mgr.xpress
COMMON GROUPS:
admin
advmail
ask
brwexec
brwonlne
brwspec
bspadmin
bspdata
bspinstx
bsptools
catbin1
catbin2
catlib
classes
config
console
convert
creator
curator
currarc
current
dat
data
database
delivery
deskmon
devices
diadb
diag
diafile
diaipc
doc
docxl
document
dsg
easy
ems
emskit
etdaemon
example
examples
ezchart
galpics
graphics
hold
hpaccss
hpadvlk
hpadvml
hpdesk
hpdraw
hpecm
hpemm
hpenv
hpgal
hphpbkp
hplibry
hplist
hplt123
hpmail
hpmap
hpmenu
hpprofs
hpsw
hptelex
ibmpam
idl
idlc
idpxl
include
infoxl
instx
internal
itpxl
job
lib
libipc
library
mailconf
maildb
mailhelp
mailjob
maillib
mailserv
mailstat
mailtell
mailxeq
mediamgr
memo
memory
mgr
mmgrdata
mmgrxfer
mmordata
mmorxfer
monitor
mpexl
ndfiles
ndports
net
network
nwoconf
office
oldmail
oper
operator
out
pascalc
patchxl
pcbkp
ppcdict
ppcsave
ppcutil
prntmate
prog
prvxl
pub
pubxl
qedit
ref
request
restore
sample
sbase
sfiles
signal
sleeper
snax25
sql
sruntime
subfile
suprvisr
sx
sys
sysmgr
sysvol
tdpdata
telex
telexjob
text
tfm
ti
tools
transmit
user
users
validate
viewlib
visicalc
wp
wp3
x400data
x400db
x400fer
x400file
xspool
VM/CMS- The VM/CMS Operating System is found on IBM mainframes, and
while there are quite a few out there, they are commonly left
alone by hackers who prefer Unix or VMS.
VM/CMS systems are commonly found gated off Sim3278 VTAMs and
ISM systems as well.
The login prompt for CMS is '.', but additional information
might be given before the prompt, such as;
Virtual Machine/System Product
!
.
or;
VM/370
!
.
and frequently over to the side;
LOGON userid
DIAL userid
MSG userid message
LOGOFF
but they all represent a VM/CMS system.
To logon, type 'logon' followed by the username, which is
usually 1 to 8 characters in length.
To be sure it is a CMS, type 'logon' followed by some random
garbage. If it is a VM/CMS, it will reply;
Userid not in CP directory
This is one of the great things about CMS, it tells you if
the login ID you entered is incorrect, thus making the
finding of valid ones fairly easy.
One thing to watch out for.. if you attempt brute forcing
some systems will simply shut the account or even the login
facility for some time. If that is the case, find out the
limit and stay just underneath it.. drop carrier or clear the
circuit if necessary, but if you continually shut down the
login facilities you will raise a few eyebrows before you
even make it inside.
Once inside, typing 'help' will get you a moderate online
manual.
COMMON ACCOUNTS
Username Password
-------- --------
$aloc$
admin operator, manager, adm, sysadmin, sysadm
alertvm alert
ap2svp
apl2pp
autolog1 autolog
autolog2 autolog
batch
batch1 batch
batch2 batch
botinstl
ccc
cms
cmsbatch cms, batch, batch1
cmsuser cms, user
cpms
cpnuc
cprm
cspuser user, csp
cview
datamove
demo1 demo
demo2 demo
direct
dirmaint dirmaint1
diskcnt
entty
erep
formplus
fsfadmin fsf, adm, sysadmin, sysadm, admin, fsfadm
fsftask1
fsftask2
gcs
gcsrecon
idms
idmsse
iips
infm-mgr infm, man, manager, mgr
inoutmgr mgr, manager
ipfappl
ipfserv
ispvm
ivpm1
ivpm2
maildel
mailman
maint service
moeserv
netview network, view, net, monitor
oltsep
op1
opbackup backup
operatns op, operator, manager, admin
operator op, operatns, manager, admin
opserver
pdm470
pdmremi
peng
presdbm dbm
procal
prodbm prod
promail
psfmaint maint
pssnews news
pvm
router
rscs
rscsv2
savsys
sfcm1 sfcm
sfcntrl
sim3278
smart
sna
sqldba database
sqluser user, sql
syncrony
sysadmin admin, adm, sysadm, manager, operator
sysckp