<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Musings on Database Security &#187; Passwords</title>
	<atom:link href="http://www.slaviks-blog.com/category/passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.slaviks-blog.com</link>
	<description>Slavik&#039;s Blog</description>
	<lastBuildDate>Wed, 07 Dec 2011 17:07:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PlentyOfFish hacked &#8211; blames messenger</title>
		<link>http://www.slaviks-blog.com/2011/01/31/plentyoffish-hacked-blames-messenger/</link>
		<comments>http://www.slaviks-blog.com/2011/01/31/plentyoffish-hacked-blames-messenger/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 02:50:02 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[sentrigo]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=301</guid>
		<description><![CDATA[This is just too funny &#8211; the site owner is accusing the guys that reported the vulnerability of extortion. More details can be found here and here. And it all started with a simple SQL Injection that can be exploited through the site error messages. I talked about this multiple times in the past. Of course, the [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/01/31/plentyoffish-hacked-blames-messenger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>YAOPC &#8211; Yet Another Oracle Password Cracker</title>
		<link>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/</link>
		<comments>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/#comments</comments>
		<pubDate>Fri, 28 Jan 2011 03:07:51 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[DBA]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Python]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=292</guid>
		<description><![CDATA[I was preparing a presentation for RMOUG and wanted to show how easy it is to crack Oracle passwords once you get the hashes. There are a lot of Oracle password crackers out there but I find that using low level C code in a presentation makes the audience leave before you get to the half [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/01/27/yaopc-yet-another-oracle-password-cracker/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Mixed case passwords for Oracle</title>
		<link>http://www.slaviks-blog.com/2010/09/01/mixed-case-passwords-for-oracle/</link>
		<comments>http://www.slaviks-blog.com/2010/09/01/mixed-case-passwords-for-oracle/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 00:03:08 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=272</guid>
		<description><![CDATA[So, we all know that Oracle used to be non-case sensitive when it came to user names and passwords. We also know that since 11g this is not the case and Oracle, by default, is case sensitive. The one thing I wanted to point out is that even if you are using sec_case_sensitive_logon=false and ignore [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/09/01/mixed-case-passwords-for-oracle/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New FPGA-based Oracle passwords cracker</title>
		<link>http://www.slaviks-blog.com/2009/10/05/new-fpga-based-oracle-passwords-cracker/</link>
		<comments>http://www.slaviks-blog.com/2009/10/05/new-fpga-based-oracle-passwords-cracker/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 16:53:31 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Passwords]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=174</guid>
		<description><![CDATA[Dennis Yurichev just dropped me a note about his new web front end for his FPGA-based password cracker. Looks very interesting as now you can write some interesting PL/SQL code to crack passwords directly from the database using this available web interface. Right now, it appears that most users are the usual suspects testing it [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2009/10/05/new-fpga-based-oracle-passwords-cracker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.427 seconds -->

