Cisco Password Encryption reversed

The Cisco VPN Client uses weak encryption to store user and group passwords in your local profile file.

I coded a little tool to reveal the saved passwords from a given profile file.

The Cisco Password Revealer along with the source code can be downloaded here.

The main problem of the method used to encrypt the passords is, that
the whole procedure is deterministically and no user input is used.
This effectively means that the encryption keys the Cisco Client
calculates can also be calculated by any other program whensoever this
programm knows the algorithm. This algorithm was now reversed.

Found on Evil Scientists.


Author: Xavier Ashe

Entrepreneur, Infosec Executive, CISSP, CISM, Ironman triathlete, traveler, UU, paleo, father of 8, goyishe, gamer, & geek.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s