<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gravo.co.uk &#187; Passwords</title>
	<atom:link href="http://gravo.co.uk/wordpress/category/passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://gravo.co.uk/wordpress</link>
	<description>gravo: to oppress, burden, make suffer.</description>
	<lastBuildDate>Thu, 26 Jan 2012 10:23:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Cisco Type 7 Passwords</title>
		<link>http://gravo.co.uk/wordpress/2009/04/27/cisco-type-7-passwords/</link>
		<comments>http://gravo.co.uk/wordpress/2009/04/27/cisco-type-7-passwords/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 11:33:48 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[In Progress]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://projects.gravo.co.uk/?p=16</guid>
		<description><![CDATA[The built in &#8216;cracker&#8217; isn&#8217;t working at the moment but the process still stands. There are plenty of other sites/tools that can decrypt this type of password. Hash Recovery Instructions Connect the console cable, power on the router and hit break a few times to enter monitor mode At the rommon prompt type confreg 0&#215;2142 [...]]]></description>
			<content:encoded><![CDATA[<p>The built in &#8216;cracker&#8217; isn&#8217;t working at the moment but the process still stands. There are plenty of other sites/tools that can decrypt this type of password.</p>
<li>Hash Recovery Instructions
<ol>
<li>Connect the console cable, power on the router and hit break a few times to enter monitor mode</li>
<li>At the <i>rommon</i> prompt type <i>confreg 0&#215;2142</i> and hit enter</li>
<li>Type <i>i</i> and hit enter to restart the router.</li>
<li>When it has started up type <i>enable</i> to enter privileged mode</li>
<li>Type <i>copy start run</i> and hit enter</li>
<li>Type <i>show run</i> and look for an entry like this <i>password 7 0235105A19005E3244</i></li>
<li>Put the long number string into the top box on this page (ignore <i>password 7)</i></li>
<li>Hit <i>Crack Password</i> and marvel in your newly recovered password</li>
<li>Go back to the router and type <i>conf t</i> to switch to global configuration mode</li>
<li>Type <i>config-register 0&#215;2102</i> and hit enter</li>
<li>Press Ctrl-Z and type <i>reload</i> then hit enter and your done.</li>
</ol>
</li>
<p>Type 5 Passwords</p>
<p>Don&#8217;t be fooled type 5 passwords can be cracked, it just takes a bit longer. You may have noticed an entry in your config that looked like this <i>enable secret 5 $1$uWd7$maP6Byq6ETXegoZXG8vbZ0</i>. This is a type 5 password.</p>
<li>Type 5 Recovery Instructions
<ol>
<li>Get a copy of John the Ripper</li>
<li>Create a text file with your hash in it, in the following format <i>enable_secret_5:$1$uWd7$maP6Byq6ETXegoZXG8vbZ0</i></li>
<li>Save the text file as pass.txt</li>
<li>Assuming pass.txt is in the same folder as John type <i>john-mmx.exe -inc:all pass.txt</i></li>
<li>After a while depending on the length of the password you will/should be presented with the passwords.</li>
</ol>
</li>
<p>
Obviously that&#8217;s how to do it in Windows but the Linux version is very similar.</p>
<p>
Note: If you recognise the type 7 password from above then one of your old routers now belongs to me. Change your passwords because you&#8217;ve been owned.</p>
]]></content:encoded>
			<wfw:commentRss>http://gravo.co.uk/wordpress/2009/04/27/cisco-type-7-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

