Bugtraq mailing list archives

Re: Oracle toplink mapping workbench password algorithm


From: Pete Finnigan <plsql () petefinnigan com>
Date: Thu, 29 Jan 2004 20:59:38 +0000

Hi Everyone,

Martin (broadcast () mail ptraced net) has written a perl script to decrypt
the passwords and has kindly allowed me to host his script on my Oracle
security tools page so if anyone would like to bookmark it for future
reference its on http://www.petefinnigan.com/tools.htm or directly a
link to the file is http://www.petefinnigan.com/oracletest.perl

Kind regards

Pete


In article <LREiMlBezvFARxra () peterfinnigan demon co uk>, Pete Finnigan
<plsql () petefinnigan com> writes
Hi

I thought readers here might be interested in this item. Today I found
that a website has posted the algorithm and sample code for the
encryption algorithm used in Oracles toplink mapping workbench. This
code can be used to decrypt the passwords held in the xml file easily. A
link to the details can be found on my website at
http://www.petefinnigan.com/orasec.htm

If you use this tool beware of this fact and protect the files used.

kind regards

Pete

-- 
Pete Finnigan
email:pete () petefinnigan com
Web site: http://www.petefinnigan.com - Oracle security audit specialists
Book:Oracle security step-by-step Guide - see http://store.sans.org for details.


Current thread: