20081209 decrypting ebs passwords - plembo/onemoretech GitHub Wiki

title: Decrypting EBS Passwords link: https://onemoretech.wordpress.com/2008/12/09/decrypting-ebs-passwords/ author: lembobro description: post_id: 421 created: 2008/12/09 15:10:27 created_gmt: 2008/12/09 15:10:27 comment_status: open post_name: decrypting-ebs-passwords status: publish post_type: post

Decrypting EBS Passwords

Just a list of URLs for now, will come back to this later when I’ve learned some more.

Oracle Applications Passwords Decryption Vulnerability

cited in

Oracle Applications 11i Password Decryption

Oracle E-Business Suite Vulnerability: Users Passwords Decrypted

Why is this relevant? Not simply to beat up on Oracle (which everyone knows is one of my hobbies), but also that I’ve been looking for a way to force EBS passwords remotely (the standard FNDCPASS tool needs to be executed on the EBS server, or so I’ve been led to believe). This vulnerability appears to hold the promise of a solution. We shall see.

Copyright 2004-2019 Phil Lembo