Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Mailing Lists -> Oracle-L -> Re: Risk Of Knowing Password Hash Value

Re: Risk Of Knowing Password Hash Value

From: Pete Finnigan <oracle_list_at_peterfinnigan.demon.co.uk>
Date: Wed, 24 Dec 2003 06:24:31 -0800
Message-ID: <F001.005DB00F.20031224062431@fatcity.com>


Hi

If you go to my website http://www.petefinnigan.com/orasec.htm there are links to papers and default password lists i wrote at a previous employer that list known default users and their hashes. I also have a bigger and corrected list with the code that can be downloaded for the SANS step-by-step guide which is available at http://www.petefinnigan.co m/sans/orastepcode.htm

hth

kind regards

Pete

In article <F001.005DAEB2.20031223145924_at_fatcity.com>, Dennis Heisler <oracle_at_the-heislers.net> writes
>Take a look at Metalink note 227010.1. It provides a script with the
>hash values for the default passwords. It's good for checking database
>security.
>
>
>Dennis
>
>--
>Please see the official ORACLE-L FAQ: http://www.orafaq.net

-- 
Pete Finnigan
email:pete_at_petefinnigan.com
Web site: http://www.petefinnigan.com - Oracle security audit specialists
Book:Oracle security step-by-step Guide - see http://store.sans.org for details.

-- 
Please see the official ORACLE-L FAQ: http://www.orafaq.net
-- 
Author: Pete Finnigan
  INET: oracle_list_at_peterfinnigan.demon.co.uk

Fat City Network Services    -- 858-538-5051 http://www.fatcity.com
San Diego, California        -- Mailing list and web hosting services
---------------------------------------------------------------------
To REMOVE yourself from this mailing list, send an E-Mail message
to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in
the message BODY, include a line containing: UNSUB ORACLE-L
(or the name of mailing list you want to be removed from).  You may
also send the HELP command for other information (like subscribing).
Received on Wed Dec 24 2003 - 08:24:31 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US