Hack Tool Repository Logo

Hack Tool Repository

white curve white curve

THC-ORACLE

This site is no longer maintained and kept for archiving purposes.

THC-ORACLE

THC presents a crypto paper analyzing the database authentication mechansim used by oracle. THC further releases practical tools to sniff and crack the password of an oracle database within seconds.

One of the network authentication modes used by Oracle databases uses a weak key exchange mechanism. This mechanism is still used on the newest database versions using Oracle's JAVA drivers. Also, for native Oracle drivers an attack is known to downgrade the authentication mode to the vulnerable version. The orakelsniffert article documents the mechanism used by the weak authentication mode, the complexity and impact of the attack and an example of an attack in the field. A Windows based cracker and a simple JAVA based client application are included to verify the results. Also, a supporting crypto utility is released.



Site: http://freeworld.thc.org/thc-orakel/
Category: Database
Hits: 899
Rating: 0
Added: 2009-11-01 19:46:09
Updated: 2009-11-01 19:50:50
Tested on:
Windows
XP
 
Olderchurch Web Site About Us | Site Map | Contact Us | ©2012 Olderchurch Security Consultancy