lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CAGcecdPYB5kadAyPCF2oP+Knt_19iNM4wnvTE1mzqHg27hcf2g@mail.gmail.com> Date: Tue, 21 Jul 2015 22:07:31 +0200 From: bob secse <bob.security.fr@...il.com> To: fulldisclosure@...lists.org Subject: [FD] RainbowCrack Plugin for Oracle hashes (<=10g) Hello everyone, RainbowCrack (http://project-rainbowcrack.com/) doesn't implement Oracle hashes <=10g (7-10g R2) in last versions. There is a plugin for RainbowCrack that implements this algorithm: https://github.com/quentinhardy/RainbowCrackPlugin This plugin can be used to: - generate Oracle rainbow tables with a fixed username (ex: SYS). - crack Oracle hashes. I have tested this plugin with the latest version of RainbowCrack (1.6.1) on Linux: generation of some rainbow tables and cracking. Multithreading during the generation and the cracking of hashes is very good. Notice that Oracle hashes <=10g are still in latest versions of Oracle Databases (ex: 11g) in the table SYS.USER$. Consequently, to crack Oracle hashes >=11g, you can crack Oracle hashes <=10g (case insensitive) and after Oracle hashes >=11g (case sensitive). Soon, I will create a torrent for some Oracle rainbow tables generated with the SYS user. Good day (or good night) for all, <https://github.com/quentinhardy/RainbowCrackPlugin> _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists