;-)
(For people who weren't Perl hackers in the mid-late '90s, Randal pretty much did exactly that while contracting at Intel, and got 3 felony convictions and 5 years probation, and it took him 12 years of fighting to get the felonies expunged. Be very very careful "trying out" security related things at your employer, without very clear written instruction showing it was authorised - you do not want to be the guy in front of a judge saying "it's part of my job description as a sysadmin!" when your employer is claiming otherwise....)
https://www.washingtonpost.com/archive/business/1997/09/15/t...
"He installed a program called "Crack" that automatically guesses passwords. Like most tools, it's used by both good guys and bad guys, by those who abuse computer systems and by system administrators who want to find out whether users are avoiding such easy targets as plain English words. It's even distributed by the Computer Emergency Response Team at Carnegie Mellon University.
He installed the program without telling his boss, something that he today admits was "stupid." But the program proved his point: Crack quickly guessed nearly 50 passwords of the 600 users of that system -- one belonging to a company vice president. Instead of reporting the company's security problem right away, Schwartz has said, he decided to continue testing. Again, he admits in hindsight, "stupid."
Other system administrators discovered the program and traced it back to Schwartz.
Schwartz insisted he never used the passwords for any nefarious purpose, and said he only acted because the company's lax security bugged him."