If we encounter a situation where we need to revel Cisco 7 password but we don’t have access to the internet (sound like science fiction!) or to utility which do that we can use Cisco IOS for reveling the password.
Let’s say we logged in into R1 and as we can see there is a password on the BGP peer to R2:
R1#sh run | s bgp
router bgp 65000
neighbor 126.96.36.199 remote-as 65002
neighbor 188.8.131.52 password 7 106D000A061843595F
In order to revel the password follow these steps:
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)#key chain decrypt
R1(config-keychain-key)#key-string 7 106D000A061843595F
Note that in the key-string we start with 7 follow by the hash password we copy from the BGP peer password.
Now to see the password type:
R1#show key chain decrypt
key 1 -- text "Cisco123"
accept lifetime (always valid) - (always valid) [valid now]
send lifetime (always valid) - (always valid) [valid now]
The password is “Cisco123”