i know of a place where anytime a new user is added to Active Directory the default password is "testing1". User logs on for first time and is requested to change there password etc so they just go "testing2" and simply increase the number by one everytime they are asked to change it and the admins know this and leave them off. iv seen employees that have changed it from "testing" but right it on a lable at the back of they're clock card holders. If anyone found the holder they would have there username AND password, admins know that aswell. It amazes me that these people spend time in college getting qualifications and then dont bother with rule 1 of security
