Community discussions

MikroTik App
 
marekm
Member
Member
Topic Author
Posts: 391
Joined: Tue Feb 01, 2011 11:27 pm

Password in cleartext in SwOS 1.6 config backup file

Tue Jun 05, 2012 8:59 am

I've just discovered that it's simply ASCII encoded in hex, near the end of *.swb file - for example, 'password' is '70617373776f7264'.
It would be nice if future versions (if any development is still being done on SwOS) could use a proper hash function like Unix crypt().
Until then, be careful not to leak the config files, and better use a separate password (not used anywhere else) for RB250GS switches.
 
User avatar
cbrown
Trainer
Trainer
Posts: 1839
Joined: Thu Oct 14, 2010 8:57 pm
Contact:

Re: Password in cleartext in SwOS 1.6 config backup file

Tue Jun 05, 2012 9:56 pm

I am pretty sure you can also get the password out of routerboard backup files with a certain tool. I thought I had saw something about this somewhere but I can't seem to find it again.

I guess that is a good thing :lol:
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26377
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: Password in cleartext in SwOS 1.6 config backup file

Wed Jun 06, 2012 9:19 am

Keep your backup files safe, and don't leave them in your router

Who is online

Users browsing this forum: No registered users and 16 guests