lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 21 Jul 2015 22:07:31 +0200
From: bob secse <>
Subject: [FD] RainbowCrack Plugin for Oracle hashes (<=10g)

Hello everyone,

RainbowCrack ( doesn't implement Oracle
hashes <=10g (7-10g R2) in last versions.

There is a plugin for RainbowCrack that implements this algorithm:
This plugin can be used to:
- generate Oracle rainbow tables with a fixed username (ex: SYS).
- crack Oracle hashes.

I have tested this plugin with the latest version of RainbowCrack (1.6.1)
on Linux: generation of some rainbow tables and cracking.
Multithreading during the generation and the cracking of hashes is very

Notice that Oracle hashes <=10g are still in latest versions of Oracle
Databases (ex: 11g) in the table SYS.USER$.
Consequently, to crack Oracle hashes >=11g, you can crack Oracle hashes
<=10g (case insensitive) and after Oracle hashes >=11g (case sensitive).

Soon, I will create a torrent for some Oracle rainbow tables generated with
the SYS user.

Good day (or good night) for all,

Sent through the Full Disclosure mailing list
Web Archives & RSS:

Powered by blists - more mailing lists