[Full-disclosure] New Tool: Oracle Password Checker

From: Kornbrust, Alexander (ak_at_red-database-security.com)
Date: 08/23/05

  • Next message: J.A. Terranson: "Re: [Full-disclosure] I am not at the office"
    Date: Tue, 23 Aug 2005 14:23:30 +0200
    To: <full-disclosure@lists.grok.org.uk>
    
    

    Hello

    We have implemented a free dictionary based Oracle password checker for
    Oracle databases called checkpwd. This is a useful and fast (150.000
    pw/sec) tool for DBAs to identify Oracle accounts with weak or default
    passwords.

    Details & Download
    http://www.red-database-security.com/software/checkpwd.html

    ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
    Usage with Oracle database connect (requires installed Oracle client)

    C:\>checkpwd system/!strongpw@database password_list.txt

    Checkpwd 1.00 - (c) 2005 by Red-Database-Security GmbH

    initializing Oracle client library
    connecting to the database
    retrieving users and password hash values
    opening weak password list file
    reading weak passwords list
    checking passwords
    SYSTEM OK
    SYS OK
    MGMT_VIEW OK
    DBSNMP OK
    SYSMAN OK
    KORNBRUST OK
    INTERNET_APPSERVER_REGISTRY has weak password
    INTERNET_APPSERVER_REGISTRY
    WIRELESS has weak password WIRELESS
    PORTAL_APP has weak password PORTAL
    PORTAL_PUBLIC has weak password PORTAL
    WCRSYS has weak password WCRSYS
    UDDISYS has weak password UDDISYS

    Done. Summary:
    Passwords checked : 13230016
    Weak passwords found : 6
    Elapsed time (min:sec) : 1:42
    Passwords / second : 138152

     

    Usage standalone

    c:\>checkpwd SCOTT:F894844C34402B67 default_passwords.txt
    Checkpwd 1.00 - (c) 2005 by Red-Database-Security GmbH

    opening weak password list file
    reading weak passwords list
    checking passwords
    SCOTT has weak password TIGER

    Done. Summary:
    Passwords checked : 595
    Weak passwords found : 1
    Elapsed time (min:sec) : 0:0
    Passwords / second : 595
    ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

    Regards

     Alexander Kornbrust
     ak at red-database-security.com
      
     Red-Database-Security GmbH
     http://www.red-database-security.com

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: J.A. Terranson: "Re: [Full-disclosure] I am not at the office"

    Relevant Pages

    • Oracle Password Checker
      ... we have implemented a free dictionary based Oracle password checker ... for Oracle databases called checkpwd 1.0. ... INTERNET_APPSERVER_REGISTRY has weak password INTERNET_APPSERVER_REGISTRY ...
      (Bugtraq)
    • New tool: Oracle Password Checker
      ... We have implemented a free dictionary based Oracle password checker for Oracle databases called checkpwd. ... INTERNET_APPSERVER_REGISTRY has weak password INTERNET_APPSERVER_REGISTRY ...
      (Pen-Test)
    • Re: oracle VA/PT
      ... Oracle Security Consulting, ... MDSYS has weak password MDSYS ... Up to 75% of cyber attacks are launched on shopping ... > locked-down servers are futile against web application hacking. ...
      (Pen-Test)