Cisco Type 7 Password Decrypter. Small tool to decrypt Cisco IOS type 7 passwords, it can also encrypt clear text passwords if required. There are no specific requirements for this document. Components Used. This document is not restricted to specific software and hardware versions. Conventions. The Cisco Password Decoder Tool (see below) provides readers with the ability to decrypt 'Type 7' cisco passwords.

Router config do sh run i enable enable password 7 F The number '7' indicates that the password has been encrypted. The number that follows F41 is the encrypted version of the password. Cisco Type 7 Password Decryption. Cisco Type 7 Password Decryption Crack Cisco type 7 passwords: enable passwords: username passwords: Service password encryption is just a false sense of security.

Enter encrypted password:. Decrypted password is:. During penetration tests, it is not uncommon to come across a configuration file of a Cisco network device. It may be a configuration backup found laying somewhere on some computer in the network. It may be a console log output e. Or we may just flat out break into some Cisco device configured with default credentials. The first thing attackers do after they gain access to a Cisco device is that they pull current configuration from the device either by running show running or show running-config command.

The attackers are typically looking for sensitive information such as stored credentials, SNMP community strings, network configuration details and so on. Credentials are naturally the most interesting thing to look for and over the years Cisco has developed number of different methods for storing passwords in their devices. Hence the name Cisco password type. In the following sections, we will go through all these password types by order from the least secure most easiest to crack to the most secure hardest to crack :.

Disclaimer: All examples and speed measurements in this article were produced on a standard modern laptop equipped with a GPU and 4 CPU cores. Cisco password type 0 is basically clear text password. There is no encryption nor obfuscation. It is the oldest and the most insecure method of storing passwords in Cisco devices. It should never be used. As you can see, there is really nothing to crack or decrypt. We can clearly see that the admin user has a password of [email protected].

The algorithm is reversible and thus it can be deciphered instantly into a plain text without any need for cracking. There are number of freely available tools for decrypting type 7 password. Here are some examples:. For instance, to decrypt the above type 7 password using Ciscot7 Python script, simply run:.

We can instantly see that the password is [email protected]. There are also numerous decrypters online for this type of password. But we strongly discourage using any them in order to avoid disclosing sensitive customer information credentials to a third party. But due to an implementation issue , it somehow ended up being a mere single iteration of SHA without salt. To crack it, we have to first convert it to the following john friendly format and save it in a file:. Note that since we have 4 CPU cores, we can run john in 4 instances using --fork parameter:.

From the above screenshot we can see that the average speed is around Hashcat recognizes this password type as hash mode To crack it, we can keep using the same john friendly format Then we can crack it like this using a dictionary, for example:. Note that by using the -O parameter optimized kernels , we will greatly increase the speed.

But it will also limit the password length to 31 characters. From the above screenshot we can see that the average speed is around 1. Seems like cracking this hash with john is much faster in our case. This password type was introduced around and it is essentially a 1, iteration of MD5 hash with salt. The salt is 4 characters long 32 bits.

