Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Ginski, Richard J.
    Oracle Question  Slightly OT
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Oracle Question Slightly OT

    Forgive me for this being slightly off topic. We've checked Oracle's
    site, including posting to their "Technology Network", and have yet to
    find a best practices document for securing Oracle databases. Am I
    missing something? ... Or should something this obvious be available on
    Oracle's site? Can anyone provide links to such information?

    -----Original Message-----
    From: Joshua Wright [mailto:jwright@hasborg.com]=20
    Sent: Wednesday, June 29, 2005 10:16 AM
    To: bugtraq@securityfocus.com
    Subject: Auditing Privilged Oracle Passwords - hashattack

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    I've put together a tool that can be used to build a table of Oracle
    password hashes from a dictionary file for a designated username.
    Hashes are calculated by creating a user account similar to the target
    account to be audited and repeatedly changing the password with "ALTER
    USER" for each dictionary word, storing the hash for each password in a
    table.

    Once the table of hashes is built, a simple SELECT can be issued to
    determine if the password hash for a target user is a simple dictionary
    word:

    SQL> select h.username, h.password, h.hash
    2 from hashattack h, dba_users d
    3 where d.password =3D h.hash and h.username =3D 'SYS';

    USERNAME PASSWORD HASH
    - ---------- -------------------- --------------------
    SYS KILTPLEAT 2BBDC477FFB28563

    SQL>


    Written in PL/SQL, available at
    http://802.11ninja.net/code/hashattack-0.1.tgz,
    http://802.11ninja.net/code/hashattack-0.1.tgz.asc

    Comments, questions, concerns welcome.

    - -Josh
    - --
    - -Joshua Wright
    jwright@hasborg.com

    2005-2006 pgpkey: http://802.11ninja.net/pgpkey.htm
    fingerprint: F00E 7A42 8375 0C55 964F E5A4 4D2F 22F6 3658 A4BF

    Today I stumbled across the world's largest hotspot. The SSID is
    "linksys".
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.1 (MingW32)
    Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

    iD8DBQFCwq0QTS8i9jZYpL8RApOqAKCnTqrAwCaqKT3KALl0b8 CDRo9I0QCfRKnB
    LcY+tDFFcNAeMbsIg7YWe88=3D
    =3DL/x5
    -----END PGP SIGNATURE-----

  2. #2
    Susan Bradley
    Oracle Question  Slightly OT
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Oracle Question Slightly OT

    www.cisecurity.org has documents.

    http://www.cisecurity.org/bench_oracle.html

    Ginski, Richard J. wrote:

    >Forgive me for this being slightly off topic. We've checked Oracle's
    >site, including posting to their "Technology Network", and have yet to
    >find a best practices document for securing Oracle databases. Am I
    >missing something? ... Or should something this obvious be available on
    >Oracle's site? Can anyone provide links to such information?
    >
    >-----Original Message-----
    >From: Joshua Wright [mailto:jwright@hasborg.com]
    >Sent: Wednesday, June 29, 2005 10:16 AM
    >To: bugtraq@securityfocus.com
    >Subject: Auditing Privilged Oracle Passwords - hashattack
    >
    >-----BEGIN PGP SIGNED MESSAGE-----
    >Hash: SHA1
    >
    >I've put together a tool that can be used to build a table of Oracle
    >password hashes from a dictionary file for a designated username.
    >Hashes are calculated by creating a user account similar to the target
    >account to be audited and repeatedly changing the password with "ALTER
    >USER" for each dictionary word, storing the hash for each password in a
    >table.
    >
    >Once the table of hashes is built, a simple SELECT can be issued to
    >determine if the password hash for a target user is a simple dictionary
    >word:
    >
    >SQL> select h.username, h.password, h.hash
    > 2 from hashattack h, dba_users d
    > 3 where d.password = h.hash and h.username = 'SYS';
    >
    >USERNAME PASSWORD HASH
    >- ---------- -------------------- --------------------
    >SYS KILTPLEAT 2BBDC477FFB28563
    >
    >SQL>
    >
    >
    >Written in PL/SQL, available at
    >http://802.11ninja.net/code/hashattack-0.1.tgz,
    >http://802.11ninja.net/code/hashattack-0.1.tgz.asc
    >
    >Comments, questions, concerns welcome.
    >
    >- -Josh
    >- --
    >- -Joshua Wright
    >jwright@hasborg.com
    >
    >2005-2006 pgpkey: http://802.11ninja.net/pgpkey.htm
    >fingerprint: F00E 7A42 8375 0C55 964F E5A4 4D2F 22F6 3658 A4BF
    >
    >Today I stumbled across the world's largest hotspot. The SSID is
    >"linksys".
    >-----BEGIN PGP SIGNATURE-----
    >Version: GnuPG v1.4.1 (MingW32)
    >Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
    >
    >iD8DBQFCwq0QTS8i9jZYpL8RApOqAKCnTqrAwCaqKT3KALl0b 8CDRo9I0QCfRKnB
    >LcY+tDFFcNAeMbsIg7YWe88=
    >=L/x5
    >-----END PGP SIGNATURE-----
    >
    >
    >


  3. #3
    Joshua Wright
    Oracle Question  Slightly OT
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Oracle Question Slightly OT

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Ginski, Richard J. wrote:
    > ... have yet to find a best practices document for securing Oracle
    > databases. Am I missing something?


    Two excellent resources for securing Oracle databases includes the
    Center for Internet Security benchmark (www.cisecurity.org) and the
    "Securing Oracle: Step-by-Step" book at the SANS School Store
    (https://store.sans.org/store_item.php?item=80).

    Also, the SANS Institute recently started offering a 6-day class on
    Securing Oracle database written by Oracle security expert Pete
    Finnigan. More information is available at
    http://www.sans.org/washington2005/d...n.php?tid=168.

    I've also been very happy with "Oracle Security Handbook" by Theriault
    and Newman (although a bit dated now) and "Effective Oracle Database 10g
    Security by Design" by Knox (both published by Oracle Press).

    NB: I work for the SANS Institute, and I am an instructor for the
    Securing Oracle class.

    - -Josh
    - --
    - -Joshua Wright
    jwright@hasborg.com

    2005-2006 pgpkey: http://802.11ninja.net/pgpkey.htm
    fingerprint: F00E 7A42 8375 0C55 964F E5A4 4D2F 22F6 3658 A4BF

    Today I stumbled across the world's largest hotspot. The SSID is "linksys".
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.1 (MingW32)
    Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

    iD8DBQFCwvrvTS8i9jZYpL8RAnlhAJ48Opq1+n4hZhY9kEHtJa yZFrObegCeNw6+
    BTtH2+4tI/4n9m49stcFv5A=
    =sIEl
    -----END PGP SIGNATURE-----

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics