Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> RE: password

RE: password

From: <Jared.Still_at_radisys.com>
Date: Tue, 17 Dec 2002 13:19:23 -0800
Message-ID: <F001.0051BEC6.20021217131923@fatcity.com>


No, it isn't.

A password hashes the same regardless of version or database name.

The username though, *is* used as a salt for the hash, which is probably what he told you.

create user t1 identified by testp;
create user t2 identified by testp;

select username, password from dba_users where username in ('T1','T2');

USERNAME PASSWORD

---------- ------------------------------
T2         BAE5ACFD7312C539
T1         CE0DA0802E1EA0F6

Jared

Rachel Carmichael <wisernet100_at_yahoo.com> Sent by: root_at_fatcity.com
 12/17/2002 12:14 PM
 Please respond to ORACLE-L  

        To:     Multiple recipients of list ORACLE-L <ORACLE-L_at_fatcity.com>
        cc: 
        Subject:        RE: password


how does trying a password on your own private database help crack a password on a different database?

I vaguely recall a conversation (I *think* it was with Kevin Loney) that part of the encryption key is the database name as well.


Do you Yahoo!?
Yahoo! Mail Plus - Powerful. Affordable. Sign up now. http://mailplus.yahoo.com
-- 
Please see the official ORACLE-L FAQ: http://www.orafaq.com
-- 
Author: Rachel Carmichael
  INET: wisernet100_at_yahoo.com

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message
to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from).  You may
also send the HELP command for other information (like subscribing).




-- 
Please see the official ORACLE-L FAQ: http://www.orafaq.com
-- 
Author: 
  INET: Jared.Still_at_radisys.com

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message
to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from).  You may
also send the HELP command for other information (like subscribing).
Received on Tue Dec 17 2002 - 15:19:23 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US