Router Pasword Breaking
Router Pasword Breaking
Requirements
There are no specific requirements for this document.
Components Used
The information in this document is based on these hardware versions:
Cisco 2600 Series Router
Cisco 2800 Series Router
The information in this document was created from the devices in a specific lab
environment. All of the devices used in this document started with a cleared (de
fault) configuration. If your network is live, make sure that you understand the
potential impact of any command.
Related Products
Refer to Password Recovery Procedures for information on how to recover password
s for related products.
Conventions
Refer to Cisco Technical Tips Conventions for information on document convention
s.
Step-by-Step Procedures
This section describes two procedures to recover your passwords.
Procedure 1
Complete these steps in order to recover your password:
Attach a terminal or PC with terminal emulation to the console port of the route
r.
Use these terminal settings:
9600 baud rate
No parity
8 data bits
1 stop bit
No flow control
Refer to these documents for information on how to cable and connect a terminal
to the console port or the AUX port:
Cabling Guide for Console and AUX Ports
Connecting a Terminal to the Console Port on Catalyst Switches
Connect a Terminal to Catalyst 2948G-L3, 4908G-L3, and 4840G Series Switches
If you can access the router, type show version at the prompt, and record the co
nfiguration register setting. See Example of Password Recovery Procedure in orde
r to view the output of a show version command.
Note: The configuration register is usually set to 0x2102 or 0x102. If you can n
o longer access the router (because of a lost login or TACACS password), you can
safely assume that your configuration register is set to 0x2102.
Use the power switch in order to turn off the router, and then turn the router b
ack on.
Important Notes:
In order to simulate this step on a Cisco 6400, pull out and then plug in the No
de Route Processor (NRP) or Node Switch Processor (NSP) card.
In order to simulate this step on a Cisco 6x00 with NI-2, pull out and then plug
in the NI-2 card.
Press Break on the terminal keyboard within 60 seconds of power up in order to p
ut the router into ROMmon.
If the break sequence does not work, refer to Standard Break Key Sequence Combin
ations During Password Recovery for other key combinations.
Type confreg 0x2142 at the rommon 1> prompt in order to boot from Flash.
This step bypasses the startup configuration where the passwords are stored.
Type reset at the rommon 2> prompt.
The router reboots, but ignores the saved configuration.
Type no after each setup question, or press Ctrl-C in order to skip the initial
setup procedure.
Type enable at the Router> prompt.
You are in enable mode and should see the Router# prompt.
Type configure memory or copy startup-config running-config in order to copy the
nonvolatile RAM (NVRAM) into memory.
warning Warning: Do not type copy running-config startup-config or write. These
commands erase your startup configuration.
Type show running-config.
The show running-config command shows the configuration of the router. In this c
onfiguration, the shutdown command appears under all interfaces, which indicates
all interfaces are currently shut down. In addition, the passwords (enable pass
word, enable secret, vty, console passwords) are in either an encrypted or unenc
rypted format. You can reuse unencrypted passwords. You must change encrypted pa
sswords to a new password.
Type configure terminal.
The hostname(config)# prompt appears.
Type enable secret <password> in order to change the enable secret password. For
example:
hostname(config)#enable secret cisco
Issue the no shutdown command on every interface that you use.
If you issue a show ip interface brief command, every interface that you want to
use should display up up.
Type config-register <configuration_register_setting>. Where configuration_regis
ter_setting is either the value you recorded in step 2 or 0x2102 . For example:
hostname(config)#config-register 0x2102
Press Ctrl-z or end in order to leave the configuration mode.
The hostname# prompt appears.
Type write memory or copy running-config startup-config in order to commit the c
hanges.
Procedure 2
Complete these steps in order to recover your password:
Shut down the router.
Remove the compact flash that is at the back of the router.
Power on the router.
Once the Rommon1> prompt appears, enter this command:
confreg 0x2142
Insert the compact flash.
Type reset.
When you are prompted to enter the initial configuration, type No, and press Ent
er.
At the Router> prompt, type enable.
At the Router# prompt, enter the configure memory command, and press Enter in or
der to copy the startup configuration to the running configuration.
Use the config t command in order to enter global configuration mode.
Use this command in order to create a new user name and password:
router(config)#username cisco privilege 15 password
cisco
Use this command in order to change the boot statement:
config-register
0x2102
Use this command in order to save the configuration:
write
memory
Reload the router, and then use the new user name and password to log in to the
router.