RE: Pete Finnigan's Oracle database password checker
- From: "Mercadante, Thomas F (LABOR)" <Thomas.Mercadante@xxxxxxxxxxxxxxxxx>
- To: <John.Hallas@xxxxxxxxxxxxxxxxxx>, <guillermo.bort@xxxxxxx>
- Date: Wed, 8 Oct 2008 08:14:31 -0400
I ran it in two of my development environments. My question is how do I extend
the dictionary that Pete included in the routine. His Web page states that it
can be extended. Anybody have any ideas about how to get a dictionary loaded
into an Oracle database?
-----Original Message-----
From: oracle-l-bounce@xxxxxxxxxxxxx [mailto:oracle-l-bounce@xxxxxxxxxxxxx] On
Behalf Of John.Hallas@xxxxxxxxxxxxxxxxxx
Sent: Wednesday, October 08, 2008 3:06 AM
To: guillermo.bort@xxxxxxx
Cc: oracle-l@xxxxxxxxxxxxx
Subject: RE: Pete Finnigan's Oracle database password checker
This is a neat PL/SQL routine which is very easy to customise to your
requirements
http://www.pentest.co.uk/cgi-bin/viewcat.cgi?cat=downloads
I downloaded the tool yesterday but I am stil looking for a suitable
sandpit environment to test it on
=========================================
John Hallas
Oracle DBA
Wm Morrison Supermarkets PLC
Mobile: 07876 790540
E-mail: john.hallas@xxxxxxxxxxxxxxxxxx
-----oracle-l-bounce@xxxxxxxxxxxxx wrote: -----
To: "Oracle-L Freelists" <oracle-l@xxxxxxxxxxxxx>
From: "Bort, Guillermo" <guillermo.bort@xxxxxxx>
Sent by: oracle-l-bounce@xxxxxxxxxxxxx
Date: 08/10/2008 02:53AM
Subject: RE: Pete Finnigan's Oracle database password checker
It means the role has a password and that it most likely has a weak
password.
I run it in a testing environment and got about 15 results, then run it in
a production database and got about 90 passwords. I am implementing a
password verification function now... any suggestions?
People REALLY need to start being careful about their passwords...
I will work on extending the dictionary to include spanish words... ¬¬
==========================================================================================================================
Wm Morrison Supermarkets PLC is registered in England with number 358949. The
registered office of the company is situated
at Gain Lane, Bradford, West Yorkshire BD3 7DL.
This email and any attachments are intended for the addressee(s) only and may
be confidential. If you are not the
intended recipient, please inform the sender by replying to the email that you
have received in error and then destroy
the email. If you are not the intended recipient, you must not use, disclose,
copy or rely on the email or its attachments
in any way.
Wm Morrison Supermarkets PLC accepts no liability or responsibility for
anything said in the email or its
attachments and gives no warranty as to accuracy. It is the policy of Wm
Morrison Supermarkets PLC not to enter
into any contractual or other obligations by email.
Although we have taken steps to ensure the email and its attachments are
virus-free, we cannot guarantee this or
accept any responsibility, and it is the responsibility of recipients to carry
out their own virus checks.
==========================================================================================================================
--
http://www.freelists.org/webpage/oracle-l
--
http://www.freelists.org/webpage/oracle-l
- Follow-Ups:
- RE: Pete Finnigan's Oracle database password checker
- From: Bort, Guillermo
- RE: Pete Finnigan's Oracle database password checker
- From: Rich Jesse
- Re: Pete Finnigan's Oracle database password checker
- From: Pete Finnigan
- References:
- Pete Finnigan's Oracle database password checker
- From: Andre van Winssen
- Re: Pete Finnigan's Oracle database password checker
- From: Ray Stell
- RE: Pete Finnigan's Oracle database password checker
- From: Bort, Guillermo
- RE: Pete Finnigan's Oracle database password checker
- From: John . Hallas
Other related posts:
- » Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » RE: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- » Re: Pete Finnigan's Oracle database password checker
- RE: Pete Finnigan's Oracle database password checker
- From: Bort, Guillermo
- RE: Pete Finnigan's Oracle database password checker
- From: Rich Jesse
- Re: Pete Finnigan's Oracle database password checker
- From: Pete Finnigan
- Pete Finnigan's Oracle database password checker
- From: Andre van Winssen
- Re: Pete Finnigan's Oracle database password checker
- From: Ray Stell
- RE: Pete Finnigan's Oracle database password checker
- From: Bort, Guillermo
- RE: Pete Finnigan's Oracle database password checker
- From: John . Hallas