导航

Web安全手册

分享本身就是件快乐的事 我因别人得到帮助而感到幸福

« 国庆礼物——su提权通杀asp脚本PhpCms2007 sp6 SQL injection 0day »

Oracle Password Cracker

Hi Guys,

I have just released a free Oracle password cracker written completely
in PL/SQL on my website. The reason for doing this is to try and
encourage people to "test" passwords for strength in their own
databases. I am not seeing any real improvements in password strength
generally across the industry over the last 8 years.

It is not the intention to replace the fast C based crackers such as
woraauthbf but instead to suppliment it. In my experience I find that
people have not covered the bases yet, that is they still have passwords
set to usernames, passwords set to defaults and also extremely weak
passwords.

I often suggest to people to download binary based crackers but there is
often a reticence to do this. Hence I decided to create a PL/SQL based
one. This way there is no excuse, its a SQL script that can be run in
SQL*Plus and also its going to find the core issues anyway before you
need a faster cracker.

Some details on how it works and what it does are included in the page
http://www.petefinnigan.com/oracle_password_cracker.htm for the cracker.
You can also download it from the same page.

hope its useful

cheers

Pete
  • 相关文章:

发表评论:

◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。

Powered By Z-Blog .Theme from Google黑板报 By Washun

Copyright 2008-2009 Pcsec.org. Some Rights Reserved.苏ICP备08110306号

Search

网站分类

文章归档

最新评论及回复

最近发表