Nmap Development mailing list archives
Re: Script suggestion - oracle
From: Dhiru Kholia <dhiru.kholia () gmail com>
Date: Sun, 30 Sep 2012 09:16:04 +0530
On Sat, Sep 29, 2012 at 10:40 PM, David Fifield <david () bamsoftware com> wrote:
On Fri, Sep 28, 2012 at 10:59:14AM +0200, Martin Holst Swende wrote:I took a look at this http://marcel.vandewaters.nl/oracle/security/cryptographic-flaws-in-oracle-database-authentication-protocol Then checked tns.lua. Patrik has implemented TNS far enough it seems, there is implementation support for enumerating users and getting the salt (auth["AUTH_VFR_DATA"] ) and session key. As I interpret the info given above and in the comments on http://threatpost.com/en_us/blogs/flaw-oracle-logon-protocol-leads-easy-password-cracking-092012?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+Popular ), it seems like the session key is encrypted with SHA1(salt+pw), and it is possible to determine whether the decryption is correct or not, and thereby determine what the password is. More info about this will probably be released soon, would be solid script to add to NSE. Since enumeration is already implemented, a script could just get all users and their passwords in one go. That's pretty awesome.
I have authored JtR and Ettercap plug-ins to exploit the cryptographic flaw in Oracle Database authentication protocol. See http://www.openwall.com/lists/john-users/2012/09/29/2 ✗ ../run/john -fo:o5logon -t Benchmarking: Oracle O5LOGON protocol [32/64]... DONE Raw: 748982 c/s real, 754370 c/s virtual This is ~2.5X faster than Marcel's tool (http://marcel.vandewaters.nl/oracle/security/cryptographic-flaws-in-oracle-database-authentication-protocol). oracle-brute.nse script is failing for me. I have sent an email to Patrik (along with .pcap files) to debug the issue. Once this is sorted out, I will try to figure out how do to stealth attack against Oracle databases. -- Cheers, Dhiru _______________________________________________ Sent through the nmap-dev mailing list http://cgi.insecure.org/mailman/listinfo/nmap-dev Archived at http://seclists.org/nmap-dev/
Current thread:
- Script suggestion - oracle Martin Holst Swende (Sep 28)
- Re: Script suggestion - oracle David Fifield (Sep 29)
- Re: Script suggestion - oracle Dhiru Kholia (Sep 29)
- Re: Script suggestion - oracle David Fifield (Sep 29)