Decrypting / recovering mRemote passwords

I just simply love mRemoteNG as a management tool. However they do say all passwords are securely stored! I’ve learned that it’s quiet easy to decrypt them. Just by performing these simple steps:

  1. Open mRemote and go to “Tools” > “External Tools”
  2. Right-click in the white space and choose “New External Tool”
  3. In the External Tools Properties, fill in a “Display Name”, “Filename” and some “arguments”.
    In this scenario I filled in "Password lookup", CMD and "/k echo %password%".
  4. Go to the connection where you would like to reveal the connection and right-click on it and choose “External tools” > “Password lookup.

You successfully decrypted the password:
mremote-decrypt password

Advice: keep your mRemote files on a secure location, such as a encrypted stick (with bitlocker or truecrypt).