Re: Oracle password cracker

From: Marco Ivaldi (raptor@mediaservice.net)
Date: Sat Jan 26 2008 - 08:35:07 EST


Rehan,

On Fri, 25 Jan 2008, ahgaber_rehan@yahoo.com wrote:

> Hi All , i am auditing Oracle DB , i have requested the DBA to extract
> all Password has in text file, i have the list, any body have a tool
> which can import the file and verify the hash against my dictionary ? i
> have cain , but i couldn’t find the option to import the list of
> passwords, it’s done 1 by 1

Here's a list of Oracle offline password cracking tools:

- bob the butcher (http://btb.banquise.net/)
- hashattack (http://802.11ninja.net/code/hashattack-0.2.0.tgz)
- orabf (http://www.toolcrypt.org/index.html?orabf)
- pass_cracker (http://www.trantechnologies.com/pass_cracker.zip)

I personally use Alexander Kornbrust's excellent checkpwd, in conjuction
with a small helper script i made:

http://www.0xdeadbeef.info/code/oracrack
http://www.red-database-security.com/software/checkpwd.html

You can easily edit your password list to make it fit the format required
by the script (an awk/sed one-liner should be enough;).

Other useful miscellaneous information about Oracle auditing:

http://seclists.org/pen-test/2007/May/0096.html
http://www.vulnerabilityassessment.co.uk/Penetration%20Test.html
http://freeworld.thc.org/thc-orakel/
http://www.milw0rm.com/related.php?program=Oracle

Cheers,

-- 
Marco Ivaldi, OPST
Chief Security Officer    Data Security Division
@ Mediaservice.net Srl    http://mediaservice.net/

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:22 EDT