Calendar
Oktober 2007
M D M D F S S
« Sep   Nov »
1234567
891011121314
15161718192021
22232425262728
293031  

THC released the password cracker “OrakelCrackert” for Oracle 11g

Van Hauser from THC told me today that vonjeek/THC from released a password cracker for Oracle 11g on the THC website called OrakelCrackert. OrakelCrackert checks approx. 400.000 passwords/second on my 2 GHz Core2Duo and has a similar speed as checkpwd 2.0 (which will be released next week).

THC Orakelcrackert 1.00

In this blog entry I mentioned that OrakelCrackert comes with the dictionary file from checkpwd. This is not true and I really apologize for this wrong accusation. In the case of OrakelCrackert I was looking for my lastname which is really unusual (not part of a normal dictionary)

But the other sidguessing tools (sidguesser, ora-getsid, coss) took my list of Oracle SIDs. “Taking” such collections without giving credentials is not unusual. The tools for guessing SIDs (e.g. . sidguesser from Cqure or ora-getsid from NGS Software) for example are taking the SID list I composed via Google Hacking, manual editing, …. without mentioning my work.

As a consequence of this wrong accusation of vonJeek I recreated the dictionary file for checkpwd 2.0 and I will document where I took the passwords from. This will become another blog entry.

3 Antworten auf “THC released the password cracker “OrakelCrackert” for Oracle 11g”

  1. Cracker sagt:

    Stating that the list is stolen is really easy. To compile a effective password cracking list, using given, famuly and pet names, brands, soccer clubs etc. is common. To harvest words - amongst others - family trees, statistic lists of the most used names are easy targets. Check e.g. and your name is found. Amonst *a lot* of other rarely seen names…

  2. Cracker sagt:

    The link was filters, next try:
    http://members.home.nl/jjnaus/TREE.TXT

  3. FX sagt:

    Plagarism sucks but became the norm. But remember: there is no higher compliment than being copied.

Antwort schreiben

Sie müssen als angemeldet sein, um einen Kommentar schreiben zu können.