Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 25 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » February 2008 » Speaking events, SQL Hashes and clever password crackers

[Previous entry: "Oracle Defending Against SQL Injection Tutorial"] [Next entry: "Oracle Security Back to basics slides available"]

02/25/2008: "Speaking events, SQL Hashes and clever password crackers"

Post to del.icio.us   Post to Furl   Digg!

I have managed, last week to update my speaking events list on my sites home page to include all the presentations I will be giving over the next couple of months. I am speaking this Thursday at the UKOUG back to basics event in London and I am looking forwards to that. Come and say hello if you are coming along to any of the events.

I was doing some research for a project last week and made a note of a new package DBMS_SQLHASH that some sites are marking as new for 11G but it's also there in 10gR2. This is an interesting package that allows the use of cryptographic hashes such as HASH_MD4, HASH_MD5, or HASH_SH1 (From DBMS_CRYPTO) to hash the result set of a SQL statement to allow the checking of data integrity. This allows data to be checked to see if it has been changed. The package with the function GETHASH can also be used to test the integrity of dictionary objects in a similar fashion to some of the commercial database scanners that are available. The package can of course be used to select the source of packages, triggers, views and more and hashes can be calculated and stored for later comparison.

Finally Lazslo sent me an interesting link to the methods Elcomsoft are using to make password crackers run at 20 times the normal speed by passing off the repetitive calculations to the parallel hardware available in graphics cards such as NVIDIA GeForce8 graphics boards. The page is titled "Elcomsoft Distributed Password Recovery"


February 2008
SMTWTFS
     12
3456789
10111213141516
17181920212223
242526272829 

About

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Search weblog

Home and Archives

Weblog Home
Weblog Archives

Recommended reading

Oracle Security Step-by-Step (Version 2.0)

Useful links

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Other useful blogs

Web Development
SQL Server Security

Syndication - Feeds

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0

Other Links


Valid XHTML 1.0!