The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


[TOOL] Hashattack - Auditing Privilged Oracle Passwords


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
From: SecuriTeam <support@securiteam.com.>
To: [email protected]
Date: 10 Jul 2005 11:27:18 +0200
Subject: [TOOL] Hashattack - Auditing Privilged Oracle Passwords
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-Id: <20050710090018.12ECE580E@mail.tyumen.ru.>
X-Virus-Scanned: antivirus-gw at tyumen.ru

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -




  Hashattack - Auditing Privilged Oracle Passwords
------------------------------------------------------------------------


SUMMARY



DETAILS

Hashattack is a tool that can be used to build a table of Oracle password 
hashes from a dictionary file for a designated username.
Hashes are calculated by creating a user account similar to the target 
account to be audited and repeatedly changing the password with "ALTER 
USER" for each dictionary word, storing the hash for each password in a 
table.

Once the table of hashes is built, a simple SELECT can be issued to 
determine if the password hash for a target user is a simple dictionary 
word:
SQL> select h.username, h.password, h.hash
  2  from hashattack h, dba_users d
  3  where d.password = h.hash and h.username = 'SYS';

USERNAME   PASSWORD             HASH
---------- -------------------- --------------------
SYS        KILTPLEAT            2BBDC477FFB28563

SQL>

Download Information:
The tool is written in PL/SQL, and can be downloaded from the project's 
homepage at:  <http://802.11ninja.net/code/hashattack-0.1.tgz>; 
http://802.11ninja.net/code/hashattack-0.1.tgz


ADDITIONAL INFORMATION

The information has been provided by  <mailto:jwright@hasborg.com.> Joshua 
Wright.




This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] In order to subscribe to the mailing list, simply forward this email to: [email protected]

DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру