- 10.2.0.4 (1)
- 11g (4)
- Allgemein (12)
- BEA (1)
- checkpwd (4)
- CPUApr2008 (3)
- CPUJan2008 (2)
- CPUJul2007 (3)
- CPUOct2007 (1)
- CPUOct2008 (1)
- Data Vault (1)
- Database Vault (2)
- David Litchfield (5)
- DOAG (1)
- Exploit (4)
- Forensics (4)
- Inguma (3)
- MacOS (1)
- Mary Ann (1)
- Oracle (2)
- Oracle Security (52)
- passwords (5)
- Podcast (1)
- rootkits (1)
- Security (9)
- Security Book (1)
- Sentrigo (2)
- software (2)
- Source Code Analysis (1)
- source code audit (3)
- SQL Injection (4)
- Tools (2)
- Trainings (1)
- 30 Dez 2008: Inguma 0.1.0 (R1) released
- 24 Dez 2008: Merry Christmas
- 14 Dez 2008: New version of cain with support for 11g passwords
- 8 Dez 2008: MD5 Bruteforcer - BarsWF
- 7 Dez 2008: GSAuditor - Fastest Oracle 11g password cracker (AFAIK)
- 5 Dez 2008: DOAG 2008 is over
- 27 Nov 2008: David Litchfield has published a whitepaper on Oracle forensics
- 21 Nov 2008: Oracle Database Vault Privilege Escalation Exploit published
- 14 Okt 2008: Oracle Critical Patch Update October 2008 is out
- 20 Aug 2008: New Oracle bugs and BSQL Hacker
THC released the password cracker “OrakelCrackert” for Oracle 11g
Van Hauser from THC told me today that vonjeek/THC from released a password cracker for Oracle 11g on the THC website called OrakelCrackert. OrakelCrackert checks approx. 400.000 passwords/second on my 2 GHz Core2Duo and has a similar speed as checkpwd 2.0 (which will be released next week).
In this blog entry I mentioned that OrakelCrackert comes with the dictionary file from checkpwd. This is not true and I really apologize for this wrong accusation. In the case of OrakelCrackert I was looking for my lastname which is really unusual (not part of a normal dictionary)
But the other sidguessing tools (sidguesser, ora-getsid, coss) took my list of Oracle SIDs. “Taking” such collections without giving credentials is not unusual. The tools for guessing SIDs (e.g. . sidguesser from Cqure or ora-getsid from NGS Software) for example are taking the SID list I composed via Google Hacking, manual editing, …. without mentioning my work.
As a consequence of this wrong accusation of vonJeek I recreated the dictionary file for checkpwd 2.0 and I will document where I took the passwords from. This will become another blog entry.
3 Antworten auf “THC released the password cracker “OrakelCrackert” for Oracle 11g”
Antwort schreiben
Sie müssen als angemeldet sein, um einen Kommentar schreiben zu können.

2 Okt 2007 bei 22:28
Stating that the list is stolen is really easy. To compile a effective password cracking list, using given, famuly and pet names, brands, soccer clubs etc. is common. To harvest words - amongst others - family trees, statistic lists of the most used names are easy targets. Check e.g. and your name is found. Amonst *a lot* of other rarely seen names…
2 Okt 2007 bei 22:30
The link was filters, next try:
http://members.home.nl/jjnaus/TREE.TXT
6 Okt 2007 bei 18:47
Plagarism sucks but became the norm. But remember: there is no higher compliment than being copied.