Oracle toplink mapping workbench password algorithm

From: Pete Finnigan (plsql_at_petefinnigan.com)
Date: 01/28/04

  • Next message: ZetaLabs: "ZH2004-01SA (security advisory): Web Blog 1.1 Remote arbitrary files retrieving"
    Date: Wed, 28 Jan 2004 00:05:50 +0000
    To: BUGTRAQ@securityfocus.com
    
    

    Hi

    I thought readers here might be interested in this item. Today I found
    that a website has posted the algorithm and sample code for the
    encryption algorithm used in Oracles toplink mapping workbench. This
    code can be used to decrypt the passwords held in the xml file easily. A
    link to the details can be found on my website at
    http://www.petefinnigan.com/orasec.htm

    If you use this tool beware of this fact and protect the files used.

    kind regards

    Pete

    -- 
    Pete Finnigan
    email:pete@petefinnigan.com
    Web site: http://www.petefinnigan.com - Oracle security audit specialists
    Book:Oracle security step-by-step Guide - see http://store.sans.org for details.
    

  • Next message: ZetaLabs: "ZH2004-01SA (security advisory): Web Blog 1.1 Remote arbitrary files retrieving"
    Loading