Re: Oracle password cracker



If it's Oracle 11g try

vonjeek/THC is proud to release thc-orakelcrackert11g, the first
publicly available full blown cracker for Oracle 11g. This tool can
crack passwords which are stored using the latest SHA1 based password
hashing algorithm. To speed up cracking, the tool exploits a weakness
in the Oracle password storage strategy. Therfore, cracking - for most
passwords - is still just as fast as it was before the introduction of
Oralce 11g.

http://freeworld.thc.org/thc-orakelcrackert11g/


Regards,

Rodrigo Montoro (Sp0oKeR)

On 25 Jan 2008 08:25:31 -0000, <ahgaber_rehan@xxxxxxxxx> wrote:

Hi All ,

i am auditing Oracle DB , i have requested the DBA to extract all Password has in text file, i have the list, any body have a tool which can import the file and verify the hash against my dictionary ?

i have cain , but i couldn't find the option to import the list of passwords, it's done 1 by 1


regards,





------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------





--
=========================
Rodrigo Ribeiro Montoro
Analista de Segurança
SnortCP / RHCE / LPIC-I
http://spookerlabs.multiply.com
=========================


Relevant Pages

  • Oracle 8 - revealing clear text passwords from the SGA
    ... Oracle 8 - revealing clear text passwords from the SGA ... needs to have been set to the same directory as the trace file location ... SQL> select name,value ...
    (Pen-Test)
  • Re: Exciting Oracle News :: Oracle DB Worm Code Published :: Oracle Passwords Crack in Mere Minutes
    ... Note the cross-posts on the original. ... And yes, there are dangers. ... or making sure they have non-default passwords. ... Perhaps Oracle should put a warning on the install: ...
    (comp.databases.oracle.server)
  • RE: Oracle Bruteforce
    ... You need to know the IP and Port where the Oracle DB server is running ... I'd be interested in tools/techniques for testing "default" oracle passwords from remote ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • Oracle clear text passwords (#NISR2122004D)
    ... NGSSoftware Insight Security Research Advisory ... Oracle 10g on all operating systems ... The 10g Oracle database server may have passwords in clear text in world ... are for these powerful accounts. ...
    (NT-Bugtraq)
  • Oracle clear text passwords (#NISR2122004D)
    ... NGSSoftware Insight Security Research Advisory ... Oracle 10g on all operating systems ... The 10g Oracle database server may have passwords in clear text in world ... are for these powerful accounts. ...
    (Bugtraq)