Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: Crack Oracle Security like a peanut!

Re: Crack Oracle Security like a peanut!

From: Chuck <skilover_nospam_at_softhome.net>
Date: Mon, 22 Aug 2005 10:47:14 -0400
Message-ID: <1124717939.b0dc41d4163b229d347dc0c0e16bd296@bubbanews>


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

DA Morgan wrote:
> DAMorgan wrote:
>

>> Oracle's Password Transform
>>
>> Goals:
>>  - Authentication information ("encrypted password") shall be portable
>>    between machines with different character sets (ebcdic and ascii).
>>  - It should handle non-enlish languages including those that require
>>    16 bits per character.
>>  - If a user has the same password on two databases, the authentication
>>    information will be the same on both machines.
>>  - It should be hard to tell if two users have the same password.
>>  - The password transform should be as hard to break as DES.
>>
>>
>> The Algorithm:

>
>
> .. most snipped.
>
>> Convert the second checksum value into a machine independent form.
>> Since we are not short on characters, express it as a hex string.

>
>
> Just in case anyone misunderstood ... I have been in Japan and did not
> write this drivel.

The headers added by his news service (talkaboutdatabases.com) indicate who he/she is and provide an avenue for reporting abuse. If you feel so inclined drop them an email. At least you'll be able to find out who's impersonating you.

Message-ID:
<b735dd778d20ab60f86f760a014ffa5c_at_localhost.talkaboutdatabases.com>

X-Newsreader: www.talkaboutdatabases.com
X-Problems-To: info at talkaboutnetwork.com
X-Posted-By: USERID-67788




iEYEARECAAYFAkMJ5XIACgkQzIf+rZpn0oRwXgCggZcEQZbSe9zEUaPlDZrH3iOD ldoAmwdoSul+p/Amvk9pfE26ZSSWm17S
=ubjp
-----END PGP SIGNATURE----- Received on Mon Aug 22 2005 - 09:47:14 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US