Quantcast
Channel: THWACK: Message List - Network Configuration Manager
Viewing all articles
Browse latest Browse all 8827

Re: Is it posible to extract usernames and passwords from the NCM database?

$
0
0

I don't believe it to be possible to decrypt the password stored in the Solarwinds database.  However, there are a couple other approaches you could take.

 

#1)

If you have the devices SNMP RW community, get out your Solarwinds Engineers toolkit and using the "Config Viewer" you can change the password, or if its unencrypted on the router you can view it.   If it's a type-7 password you can use a webpage like this to decrypt it from the config on the router (Cisco Type 7 Reverser - PacketLife.net)

 

#2)

This one is a bit trickier, but if Orion is using telnet to get to the devices rather than SSH, you can intercept the password.   Just use wireshark on your Orion server and tell it to go download a config while your monitoring traffic.  The password will be sent in plain-text.

 

#3)

If the devices are older versions of IOS, there are known ways to get in and configure them via HTTP.  You can find it on the internet fairly easy.   Slide 3 on this PPT gives you the basics, if I remember right there is a bit of tweaking you might have to do...  www.blackhat.com/presentations/bh-usa-02/bh-us-02-akin-cisco/bh-us-02-akin-cisco.ppt

 

HTH!


Viewing all articles
Browse latest Browse all 8827

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>