Yaping's Weblog

January 9, 2009

Oracle password algorithm

Filed under: Oracle,Security — Yaping @ 5:11 am

Recently I read several Oracle security articles, they’re related to Oralce password algorithm.
In the article, it details how Oracle use DES algorithm in CBC mode to generate password hash value
and how Oracle process TNS native authentication.

You can find them with the following links.
The next level of Oracle attacks (http://freeworld.thc.org/papers/thc-orakelsniffert.pdf)
TNS native authentication (http://www.oxid.it/topics.html)
Oracle 9i TNS 3DES authentication details
Oracle 10g TNS AES-128 authentication details
Oracle 11g TNS AES-192 authentication details

Blog at WordPress.com.