Sie befinden sich aktuell in den Archiven des Blogs Alexander Kornbrust Oracle Security Blog für Dezember, 2008.
- 11g (8)
- Allgemein (27)
- checkpwd (4)
- CPUApril2009 (2)
- CPUJan2009 (3)
- CPUJul2009 (2)
- CPUOct2009 (3)
- David Litchfield (7)
- Exploit (20)
- Forensics (4)
- Oracle Security (79)
- passwords (7)
- SAP (1)
- Security (18)
- Sentrigo (5)
- software (8)
- source code audit (5)
- SQL Injection (23)
- Tools (19)
- Trainings (2)
- Tutorial (2)
- 25 Feb 2010: 2 new ways to create error messages
- 24 Feb 2010: How to Prevent a User Granted the ALTER USER Privilege From Changing SYS/SYSTEM password and how to bypass it
- 23 Feb 2010: New Repscan 3.0 is available
- 22 Feb 2010: Really good whitepaper about "Hacking Oracle from the Web"
- 15 Feb 2010: Interesting Article about SQL Injection in Oracle by Mike Smithers
- 5 Feb 2010: Oracle Blackhat video removed from Website
- 4 Feb 2010: Oracle 11g 0day exploit published
- 30 Jan 2010: Selling stolen bank data to the government for 2.5 Million EUR?
- 6 Dez 2009: Dennis Yurichev wrote an article about his FPGA Oracle password cracker
- 29 Nov 2009: IGHASHGPU - Cracking Oracle Passwords with 790 Million Passwords/second
Oracle Security
Other Blogs
SQL Injection
Trainings
- Februar 2010
- Januar 2010
- Dezember 2009
- November 2009
- Oktober 2009
- September 2009
- August 2009
- Juli 2009
- Mai 2009
- April 2009
- März 2009
- Februar 2009
- Januar 2009
- Dezember 2008
- November 2008
- Oktober 2008
- August 2008
- Juli 2008
- Mai 2008
- April 2008
- März 2008
- Februar 2008
- Januar 2008
- Dezember 2007
- November 2007
- Oktober 2007
- September 2007
- August 2007
- Juli 2007
- Juni 2007
- Mai 2007
Archive für Dezember 2008
Inguma 0.1.0 (R1) released
30 Dez 2008 von Alexander Kornbrust.
Yesterday the new version of Inguma (0.1.0 (R1), an exploit framework with support for many systems e.g. Oracle, DB2, Informix,… , was released.
This new version of Inguma comes with a lot of new features. Joxean has added the module liboracleinternals.py. At the moment this script is only creating oracle password files (from version 8 to 11) but in future we will see more…
Geschrieben in Oracle Security | Drucken | Keine Kommentare »
Merry Christmas
24 Dez 2008 von Alexander Kornbrust.
Dear ReaderI wish you (and your families) a merry Christmas and a happy new year.
P.S.: This lovely baby is our daughter Anna. Already 10 months old…
Geschrieben in Allgemein | Drucken | Keine Kommentare »
New version of cain with support for 11g passwords
14 Dez 2008 von Alexander Kornbrust.
2 weeks ago, Massimiliano Montoro aka Mao, released a new version of Cain & Abel.
Here some of the new features of Cain & Abel v4.9.25:
- Oracle 11g (case sensitive) Password Extractor via ODBC.
- Added Oracle 11g Password Cracker (Dictionary and Brute-Force Attacks).
- Added support for Oracle TNS 11g (AES-192) in Oracle TNS Hashes Password Cracker.
- Added support for Oracle TNS 11g (AES-192) in Oracle TNS sniffer filter.
- Experimental SQL Query tool via ODBC.

The AES implementation of Cain is slower than the implementation of GSAuditor (6,172,839 vs 2,654,719 on a 2.4 GHz C2D E4600) but 2.6 Million passwords per second (via brute force) is still quite fast.
Massimilano wrote also 3 interesting whitepapers about the TNS authentication based on László Tóth work. Instead of using the oran10.dll/oran11.dll Mao is using the OpenSSL library:
Oracle 9i TNS 3DES authentication details
Oracle 10g TNS AES-128 authentication details
Oracle 11g TNS AES-192 authentication details
Geschrieben in passwords, 11g, Oracle Security | Drucken | Keine Kommentare »
MD5 Bruteforcer - BarsWF
8 Dez 2008 von Alexander Kornbrust.
Last week at the DOAG conference I published a few numbers about the MD5 cracking speed of BarsWF. Today I found a new record on the web. 3.6 billion (!!!) password hashes per second can calculated with BarsWF. This configuration was using 4x [eVGA 9800GX2] without overclocking.
Here are some calculations how long it takes to break MD5 hashes.All passwords (lowercase or uppercase, alpha, 26^1+26^2+26^3+…)
- up to 8 characters => 60 seconds
- up to 9 characters => 26 minutes
- up to 10 characters => 11 hours
All passwords (mixed case, alphanum, 62^1+62^2+62^3+…)
- up to 7 characters => 16 minutes
- up to 8 characters => 17 hours
- up to 9 characters =>44 days
Several Oracle products like OID, OVS (Oracle Virtual Server) or Apex (until 2.2.) are using plain MD5 for hashing passwords. But even the usage of salt (like Apex 3.0) does not help against this computing power….
Geschrieben in Oracle Security | Drucken | 2 Kommentare »
GSAuditor - Fastest Oracle 11g password cracker (AFAIK)
7 Dez 2008 von Alexander Kornbrust.
Danny boy from evilfingers.com informed me that his tool gsauditor now supports Oracle 11g passwords (+ many other variants of SHA-1). GSAuditor is really fast and with more than 6 million password hashes per second (Core2Quad Q6600 2.4 GHz, Vista 64) it’s currently the fastest Oracle 11g password cracker I know. At the moment GSAuditor is not supporting multiple threads but Danny boy is working on it. The number will increase by 4 (=more than 20 mill hashes/second).

To extract the password hashes from Oracle 11g you can use the following SQL query to retrieve the Oracle password hash + salt from the table sys.user$:
SQL> set linesize 120
SQL> select ‘gsauditor -binary -set:?d -append -salt:’||substr(u.spare4,43,20)||”||substr(u.spare4,3,40)||’ ‘ from sys.user$ u where u.type#>0 and length(spare4) =62;
Geschrieben in Tools, passwords, Oracle Security | Drucken | 1 Kommentar »
DOAG 2008 is over
5 Dez 2008 von Alexander Kornbrust.
Just back from the DOAG 2008 conference. Nearly 2000 attendees came to Nürnberg, Germany. Together with Sentrigo we had a booth at the conference and presented our products like Repscan or Hedgehog and services (Audits, Trainings, …).
I gave a presentation “Best of Oracle Security 2008” and Aviv Pode talked about “Hacking and protecting the Oracle database”.
Today I also uploaded the presentations from Polish Oracle User Group (PLOUG), Deepsec 2008 in Vienna and the iSafe 2008 Conference in Dubai.
Geschrieben in Sentrigo | Drucken | Keine Kommentare »
