The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Oracle password system comes under fire
Time: 03:00 EST/08:00 GMT | News Source: News.com | Posted By: Jonathan Tigner

In the latest critique of Oracle's security practices, experts are calling on the software maker to improve the mechanism used to secure passwords for database users. Researchers say they have found a way to recover the plain text password from even very strong, well-written Oracle database passwords within minutes.

The technique Oracle uses to store and encrypt user passwords doesn't provide sufficient security, said Joshua Wright of the SANS Institute and Carlos Sid of Royal Holloway College, University of London. Wright gave a presentation on the matter Wednesday at the SANS Network Security conference in Los Angeles.

In the presentation, Wright discussed how passwords are encrypted before being stored in Oracle databases and presented a tool he wrote to uncover passwords, according to a SANS statement. A paper by Wright and Cid is available on the SANS Web site.

Wright and Cid identified several vulnerabilities, including a weak hashing mechanism and a lack of case preservation--all passwords are converted to uppercase characters before calculating the hash.

Write Comment
Return to News

  Displaying 576 through 576 of 576
Prev | First
  The time now is 8:26:34 PM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 8/1/2025 12:58:56 AM
https://justpaste.me/Z4R91
https://justpaste.me/as9j3
https://justpaste.me/cG9S1
https://justpaste.me/ZdYD2
https://justpaste.me/eVTd1
https://justpaste.me/fcJQ3
https://justpaste.me/aAW04
https://justpaste.me/daHX2
https://justpaste.me/dvaV4
https://justpaste.me/bPRA2

Write Comment
Return to News
  Displaying 576 through 576 of 576
Prev | First
  The time now is 8:26:34 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *