Home page logo

pen-test logo Penetration Testing mailing list archives

Re: Oracle password cracker
From: Marco Ivaldi <raptor () mediaservice net>
Date: Sat, 26 Jan 2008 14:35:07 +0100 (ora solare Europa occidentale)


On Fri, 25 Jan 2008, ahgaber_rehan () yahoo com wrote:

Hi All , i am auditing Oracle DB , i have requested the DBA to extract all Password has in text file, i have the list, any body have a tool which can import the file and verify the hash against my dictionary ? i have cain , but i couldn?t find the option to import the list of passwords, it?s done 1 by 1

Here's a list of Oracle offline password cracking tools:

- bob the butcher (http://btb.banquise.net/)
- hashattack (http://802.11ninja.net/code/hashattack-0.2.0.tgz)
- orabf (http://www.toolcrypt.org/index.html?orabf)
- pass_cracker (http://www.trantechnologies.com/pass_cracker.zip)

I personally use Alexander Kornbrust's excellent checkpwd, in conjuction with a small helper script i made:


You can easily edit your password list to make it fit the format required by the script (an awk/sed one-liner should be enough;).

Other useful miscellaneous information about Oracle auditing:



Marco Ivaldi, OPST
Chief Security Officer    Data Security Division
@ Mediaservice.net Srl    http://mediaservice.net/

This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]