

The very first time we saw a FortiGate configuration file (2014), we knew it had to be reversible encryption and we therefore knew we could reverse it, too! This story is all about “the proof of the pudding is in eating”. Did you ever wonder about the following type of passwords in FortiGates? config wireless-controller vap edit "dummy-decrypt" set vdom root set passphrase ENC umGOJVCWhGhoiuY/EjTZcZKjuuIkusDNkvdvUkU3awr5TGudxfmidR2bOyoBlQgHho0DuORJafh1WiCzaoBpRNv/gHCFC5mlPVcjjpHXTUvG47/qlBusgELO1ctsLt/4RVjov2S5R7+6DdkU/PbSZVoNkeINDQBsP3TTm圎z9+YyPleLzBZh4RKU2OKTsqe6TF/uHA= next end
