Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

Re: Oracle password cracker

Subject: Re: Oracle password cracker
Date: Sat, 26 Jan 2008 10:41:03 -0200
If it's Oracle 11g try

vonjeek/THC is proud to release thc-orakelcrackert11g, the first
publicly available full blown cracker for Oracle 11g. This tool can
crack passwords which are stored using the latest SHA1 based password
hashing algorithm. To speed up cracking, the tool exploits a weakness
in the Oracle password storage strategy. Therfore, cracking - for most
passwords - is still just as fast as it was before the introduction of
Oralce 11g.

http://freeworld.thc.org/thc-orakelcrackert11g/


Regards,

Rodrigo Montoro (Sp0oKeR)

On 25 Jan 2008 08:25:31 -0000,  <ahgaber_rehan@yahoo.com> wrote:

Hi All ,

i am auditing Oracle DB , i have requested the DBA to extract all Password 
has in text file, i have the list, any body have a tool which can import the 
file and verify the hash against my dictionary ?

i have cain , but i couldn't  find the option to import the list of 
passwords, it's done 1 by 1


regards,





------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------





-- 
=========================
     Rodrigo Ribeiro Montoro
      Analista de SeguranÃa
    SnortCP / RHCE / LPIC-I
 http://spookerlabs.multiply.com
=========================

<Prev in Thread] Current Thread [Next in Thread>