Penetration Testing mailing list archives

Re: [PEN-TEST] Router Password Recovery


From: Leif Sawyer <lsawyer () GCI COM>
Date: Tue, 30 Jan 2001 08:19:26 -0900

Lonnie Smith [lonnie.smith () VICORP COM] wrote:

  Does anyone have any way to do Password recovery on a Cisco router
without having to reboot a Cisco 3600 series? I have local access and
telnet access. Thanks!


Lonnie --

The only way I know of to perform a password recovery on ANY cisco
gear is to perform a reboot at the local console, and interrupt the
boot cycle to get into the prom mode.

From there, it's generally a register tweak to allow you to boot
into a mode where the passwords are not used, so you can peek
at the configs.  Of course, if you're using encrypted passwords,
you'll need a cisco password decryptor, and if it's enable secrets,
then you're only going to bypass it by entering in a new one...

Cisco password recovery:
http://www.cisco.com/warp/public/474/index.shtml

Cisco enable secret recovery:
http://www.cisco.com/warp/public/779/smbiz/service/knowledge/general/recover
y1.htm


Current thread: