CCNA Security Exam Tutorial:When It’s Good To Add Salt

When you started studying for your CCNA certification exam, one of the very first things you learned was the major difference between the enable password and the enable secret – the enable secret is encrypted by default, where the enable password is just sitting there in clear text, waiting to be read!

When you look at the enable secret in a Cisco router configuration, it looks like it would be impossible to guess. 640-802:Cisco Certified Network Associate(CCNA) After setting the enable secret on this router to the word security, here’s how it appears in the configuration:enable secret 5 $1$24me$gVFxUOI4gYp0IQbhtH8Rz0.That password has been encrypted by MD5, the Message Digest 5 algorithm. The result of the MD5 algorithm being applied to the password is a 32-character hexadecimal value.

That password is hard to guess, but not terribly hard to crack. Anyone looking over your shoulder would not be able to come up with that password, but there are readily-available password cracking software devices that can crack that encryption in a matter of minutes. That’s true of any MD5-encrypted password, not just those on Cisco routers.So what can we do about this? We can add SALT to our MD5.

The salt itself is simply a string of random characters that are added to the encryption process. Salting makes it much more difficult for a hacker to come up with the password; each bit added by the salt process literally makes it twice as difficult for the password to be compromised. A recent Wikipedia entry states that if a password was one of 200,000 words, a 32-bit salt would require 800 trillion hashes for a full-blown brute force attack.

The actual creation and application of a salt is beyond the scope of the CCNA Security exam, but once you’ve earned that valuable certification – or maybe while you’re preparing for it – do a Google search on “salt md5” and read up on this powerful security tool. In the meantime, look for more CCNA Security tutorials on the site you’re on now as well as my website!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available! Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, “How To Pass The CCNA”, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!

CCNA Security Commands

#01 solara

As part of my study for CCNA Security I have been making a list of all the commands I need to be adept with. I thought I would share this list of commands with others who may be interested.

For simplicty the list doesn’t offer explanations and in most cases there are a variety of options that could be used with each command that are not shown. It is also not suitable for copy/paste into a router or switch. However, I think it is still a useful quick reference sheet.

#02 B Haines

You are running both RADIUS as well as TACACS+ servers in your example configuration. I was wondering what RAD/TACS you were running on those two servers? FreeRadius? And what Tac Plus? Just trying to determine what software you are using for your lab studies! Thanks!

By the way, thanks for sharing your config!

#03 solara

The previous example isn’t my config but rather just a list of commands to be familiar with and so I’m not actually running TACACS+ and RADIUS on the separate server addresses that I have shown.

I do my lab work using GNS3 with the C3745-ADVENTERPRISEK9_SNA-M IOS and currently I’m using the 90-day trial version of Cisco ACS 4.2 running on a Win2k3 VMWare box.

Just for interest I’ve attached a text file showing a basic config I’ve used for testing TACACS+. I have enabled debugs on aaa authentication and IP packets between the router and the ACS server and then attempted to logon to the router via SSH.

642-652:Wide Area Application Services for Field Engineers

Cisco認證是世界著名的計算機廠商——思科公司推出的壹套測試和評估專業技術人員技術水平的認證體系,可以證明技術人員具有精通Cisco公司某項產品的安裝、維護、開發和支持計算機系統工作的能力。Cisco認證是在互聯網界具有極大聲望的網絡技能認證。其總體認證體系包括路由和交換網絡支持(售後工程師認證體系),路由和交換網絡設計(售前工程師認證體系)和廣域網交換網絡設計和支持幾大部分。同時,Cisco公司還新增了有關網絡安全方面的認證。在前面幾項認證考試中,目前國內外需求量最大,也是參加人數最多的,是路由和交換網絡支持認證,即Cisco的售後工程師認證體系!目前在國內的市場也日漸擴大!

642-652屬於Cisco WAASSE認證方面的壹項考試科目,642-652題庫涵蓋60道真題,642-652:Wide Area Application Services for Field Engineers。考綱的更新,Killtest IT認證題庫也隨著考試大綱的更新而更新,642-652題庫更新時間:2008-11-12,目的是為了保證考生通過642-652考試。WAASSE 642-652考試題庫由KillTest認證題庫網資深IT認證講師和WAASSE產品專家結合PROMETRIC或VUE的真實642-652考試環境最新原題傾心打造。

目前國內網絡安全人才,在網絡安全需求的擴大中顯得越來越匱乏,思科公司也加大了對網絡安全培訓及人才就業的投入。思科在2003年年中的調查也顯示思科安全培訓越來越重要:75%的被調查者希望在未來的6個月內參加壹個諸如SECUR、CSPFA、CSVPN、CSIDS等思科的安全培訓課程;61%的被調查者表示將通過網絡安全認證作為他們參加這些課程的最主要的動力。而這個需求的動力就是人才需求空缺,加上網絡安全明晰化後,對於網絡職位的崗位上對於安全應用的需求也出現增長的趨勢,所以網絡人才壹條必然的出路擺在了眼前—網絡安全工程師!ccsp的專業技能:實施和使用Cisco PIX防火墻的用戶;對PIX防火墻產品進行銷售和維護的Cisco渠道夥伴;銷售、實施和維護VPN網的Cisco的渠道夥伴。