Talk about not security conscious. As recent as 2006 I was at a hotel that will remain unnamed.... at the most boring conference ever. I climbed on the public wifi and did a quick scan to see what was out there and what I saw made my day. What I would estimate was the entire hotel LAN including backoffice... and some Windows 98 machines.
All the office machines were running VNC for remote support and some poep had C: drive on just one of the 98 machines open for read. I took a look around for the Windows registry file, made a copy of that and loaded it using the hive load feature of regedit to see what I could see. I grabbed the encrypted VNC password - which was encrypted using 3DES and a static key which had been reverse engineered at that stage. I quickly decrypted it with a free tool off the web and got to work seeing just how many machines shared the same password... and would you believe it, it was the only password they used
Of course, not being a malicious guy, I decided to lend a hand and hopped onto what looked to be a manager of sort's PC while he was in the middle of putting together a word document and released the contents of my clipboard with Ctrl-V over and over. "I WILL SECURE MY WIRELESS NETWORK, I WILL SECURE MY WIRELESS NETWORK!!!!". I just wish I could have seen his face....