发新话题
打印

[转载]An Assessment of the Oracle Password Hashing Algorithm

[转载]An Assessment of the Oracle Password Hashing Algorithm

原始连接:http://www.sans.org/rr/special/index.php?id=oracle_pass

In this paper the authors examine the mechanism used in Oracle databases for protecting users' passwords. We review the algorithm used for generating password hashes, and show that the current mechanism presents a number of weaknesses, making it straightforward for an attacker with limited resources to recover a user's plaintext password from the hashed value. We also describe how to implement a password recovery tool using off-the-shelf software. We conclude by discussing some possible attack vectors and recommendations to mitigate this risk.

附件

An Assessment of the Oracle Password Hashing Algorithm.rar (82 KB)

2005-10-30 23:00, 下载次数: 46

曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题