Researchers: Oracle Database Passwords Can Be Cracked - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
News
News
10/28/2005
01:56 PM
50%
50%

Researchers: Oracle Database Passwords Can Be Cracked

The security experts said that the password algorithm Oracle uses is weak and provides attackers several ways to break into databases.

Passwords that limit access to Oracle databases can be cracked with off-the-shelf hardware, a pair of security researchers claimed in a recently published paper.

The researchers, Joshua Wright of the SANS Institute and Carlos Cid, of the University of London, said that the password algorithm Oracle uses is weak -- Oracle doesn't preserve the case of the password, for example -- and provides attackers several ways to break into databases.

"An adversary with limited resources can mount an attack that would reveal the plaintext password from the password hash for a known user," wrote Wright and Cid.

Although an attacker would have to have one of more usernames and the associated password hashes to proceed, that's not an impossible chore, even if the assault is only a brute force attack.

The pair used an off-the-shelf workstation powered by a Pentium 4 2.8GHz processor to test Oracle password hash cracking, then concluded that all the possible passwords of an account could be cranked out in under 40 days, giving 20 days as the average time it would take to break into an account.

"This is especially problematic for organizations with a password expiration duration that is shorter than 20 days, since it is likely an attacker will be able to produce the plaintext password before the account password is changed," wrote the researchers.

Among their recommendations, Wright and Cid advised Oracle-equipped enterprises to enforce longer passwords (12 characters minimum) and require that passwords be changed frequently.

"The SANS Institute contacted the Oracle product security team about these findings on 7/12/2005," said Johannes Ullrich, the chief research officer at the SANS Internet Storm Center, in an alert posted Thursday. "Subsequent requests for clarification on what Oracle plans to do to address these vulnerabilities have gone unanswered."

Oracle did not immediately respond to TechWeb's call for comment.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
2021 State of ITOps and SecOps Report
2021 State of ITOps and SecOps Report
This new report from InformationWeek explores what we've learned over the past year, critical trends around ITOps and SecOps, and where leaders are focusing their time and efforts to support a growing digital economy. Download it today!
InformationWeek Is Getting an Upgrade!

Find out more about our plans to improve the look, functionality, and performance of the InformationWeek site in the coming months.

News
Pandemic Responses Make Room for More Data Opportunities
Jessica Davis, Senior Editor, Enterprise Apps,  5/4/2021
Slideshows
10 Things Your Artificial Intelligence Initiative Needs to Succeed
Lisa Morgan, Freelance Writer,  4/20/2021
News
Transformation, Disruption, and Gender Diversity in Tech
Joao-Pierre S. Ruth, Senior Writer,  5/6/2021
Register for InformationWeek Newsletters
Video
Current Issue
Planning Your Digital Transformation Roadmap
Download this report to learn about the latest technologies and best practices or ensuring a successful transition from outdated business transformation tactics.
White Papers
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll