?
Solved

CISCO IOS Enable secret and password?

Posted on 2006-11-29
6
Medium Priority
?
2,361 Views
Last Modified: 2012-08-13
What is the different between those 2?
enable password and enable secret?

I often see that enable password 7 <password>
what is the number stand for? Based on my research 7 is a weak encryption algorithim? why they don't use the strongest one?
say enable password 5 <passsword>

0
Comment
Question by:kecoak
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 28

Accepted Solution

by:
mikebernhardt earned 2000 total points
ID: 18042072
Enable secret uses "5". You are correct in what those numbers mean in terms of the encryption level. Regular enable password is a reversible encryption, enable secret is not reversible. There are plenty of utilities out there to decrypt the former for you. this isn't always a bad thing- If you break into a router and need to get the password without changing it, it's helpful. But for best security, always use enable secret.
0
 
LVL 5

Expert Comment

by:WGhen
ID: 18042187
Might want "service password encryption" too

WGhen
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 18042307
That is what activates that reversible encryption. Without it, everything but enable secret will be in clear text.
0
Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

 

Author Comment

by:kecoak
ID: 18042314
Is that possible to have enable password 5 <password>?
I don't understand whether "5" is always combine with "secret" ? or can it be combine with any other number? any references for this?
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 18042357
No, it isn't. IOS puts it in there as a reference when it reads the password so it knows how to interpret it.
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 18045201
Mike has it all, So just to add;

7 means MD7 and 5 means MD5

There are so many sites/programs out there which will decrypt an MD7 password in seconds.

Cheers,
Rajesh
0

Featured Post

[Webinar] Lessons on Recovering from Petya

Skyport is working hard to help customers recover from recent attacks, like the Petya worm. This work has brought to light some important lessons. New malware attacks like this can take down your entire environment. Learn from others mistakes on how to prevent Petya like worms.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question