Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Penetration Testing
Cisco Catalyst 4006 CatOS Password Hash Dec 10 2003 11:32AM
Paul Bakker (bakker fox-it com) (3 replies)
Re: Cisco Catalyst 4006 CatOS Password Hash Dec 12 2003 03:23PM
Frisbie (listasdecorreo wanadoo es)
RE: Cisco Catalyst 4006 CatOS Password Hash Dec 10 2003 06:04PM
Joey Peloquin (jpelo1 jcpenney com)
Re: Cisco Catalyst 4006 CatOS Password Hash Dec 10 2003 05:22PM
Miles Stevenson (miles mstevenson org)
Hi Paul.

I believe $2$ is indicative of an SHA-1 hash, as opposed to MD5.

-Miles

On Wed, 2003-12-10 at 06:32, Paul Bakker wrote:
> During a pentest/audit I received from the client the configurations for their Cisco Catalyst 4006 and their other Cisco IOS switches.
>
> The passwords in the Cisco IOS configuration file are in in the known usual format of the FreeBSD MD5 hash...
> Like $1$xxxx$xxxxxxxxxxxxxxxxxxx
>
> These are easily crackable/recognized by both John the Ripper and Cain&Abel.
>
> The passwords on the Catalyst are in the same format (for the eye), but instead of starting with $1$ they start with $2$..... Both John and Cain do not recognize these hashes.
>
> Can anybody shed some light on the hash function used to create these and any tools that can be used to eudit the password strenght of these passwords (Or how John or Cain can be sed for this...)
>
> --
> Paul Bakker
>
> ------------------------------------------------------------------------
---
> ------------------------------------------------------------------------
----
--
Miles Stevenson
miles (at) mstevenson (dot) org [email concealed]

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus