Solved

Using Hydra to Scan Oracle Databases

Posted on 2013-02-04
5
610 Views
Last Modified: 2013-02-27
Hello Experts,

      For the past few weeks I have been using Hydra to scan our network for exposed SQL databases (MySQL and MSSQL) with a great deal of success. Now I need to scan for Oracle databases with weak or no password protection.  I have been doing some research and found that you need to use a module ( based on the Readme file that comes with Hydra) to run with hydra to successfully  do pen test  these type of databases… does anybody know where I can get the Oracle-listener Module to complete this task.
0
Comment
Question by:amstoots
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 500 total points
ID: 38854714
Hydra has had that module out-of-the-box since release 6.3 - however, it won't build unless you have both an Oracle client and libaio on the machine - so I would suggest installing those (you can get the oracle client from http://www.oracle.com/technetwork/topics/linuxsoft-082809.html ) and trying again?
0
 

Author Comment

by:amstoots
ID: 38933148
I've requested that this question be deleted for the following reason:

no longer needed
0
 
LVL 33

Expert Comment

by:Dave Howe
ID: 38933149
Gave answer, not sure why this is to be deleted?
0
 

Author Closing Comment

by:amstoots
ID: 38933982
Thank you ....
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Manage ASA using outside IP 14 77
android samsung attempts 10 61
Configuring DNS Round Robin in Windows DNS server ? 8 67
Barracuda WAF Training? 2 28
Many old projects have bad code, but the budget doesn't exist to rewrite the codebase. You can update this code to be safer by introducing contemporary input validation, sanitation, and safer database queries.
Do you know what to look for when considering cloud computing? Should you hire someone or try to do it yourself? I'll be covering these questions and looking at the best options for you and your business.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question