Red-Database-Security GmbH is specialized in Oracle Security

Products
Repscan 2.5
Hedgehog Enterprise
Checkpwd (free)

Services
Oracle Audit / Hardening
Security Training
Consulting

Information
Oracle Security Blog
Published Alerts
Upcoming Alerts
Patch Information
Whitepaper
Presentations
Oracle Fact Sheets
Exploits
Tutorials
Videos
Scripts

News & Events
Events
News

Company
Contact
People
Partner
Impressum
Sitemap


Search



Search Red-Database-Security
Benchmark Oracle Password Cracker - V1.03


Benchmark Oracle Password Cracker

The following chart describes the performance of some common Oracle password cracking tools. Benchmarks for 11g based password crackers are available here. Most new systems nowadays are supporting multiple cores and/or processors (like Core2Duo or Xeon). But most password crackers are not supporting these multiple cores/processors.

Since checkpwd 1.21 is supporting multiple cores and is the fastest Oracle password cracker in dictionary mode.

All tests were done with a dictionary file containing 1.5 million passwords. 34 passwords hashes were tested in an Oracle 10.2 database. checkpwd 2.0, woraauthbf and orabf checks against 40 password hashes from a file (orabf via multiple function calls)..

Dictionary Attack (passwords per second)

Name

Author

Pentium 4 with HT *

Dual Xeon **

Core2Duo ***

 
checkpwd 2.00 a8 Red-Database-Security GmbH - 552.853 664.672  
woraauthbf 0.2 Laszlo Toth   1.315.134 1.188.679  
Repscan 1.70 Red-Database-Security GmbH 179.333 417.263 473.324  
orabf 0.76 0rm 331.743 426.119 431.701  
John the Ripper 1.7.1 Bartavelle 368.757 633.033 503.227  
Cain 3.3 Mao 71.100 61.813 95.012  
Matrixay 1.0 (Build 1121) DBAppSecurity Ltd. 104.000 132.354 156.354  
NGSSquirrel 1.6.1.4 NGS Software 102.000 81.299 154.468  

* Intel Pentium 4, 3 GHz, Hyperthreading, 3 GB RAM, Windows XP
** Intel Dual-Xeon, 3 GHz, Dell-1800, 4 GB RAM, Windows x64 2003 Server
*** Intel Core 2 Duo (iMac), 2.16 GHz, 2 GB. Windows XP



Bruteforce Attack (passwords per second)

Name

Author

Pentium 4 with HT *

Dual Xeon **

Core2Duo ***

 
orabf 0.76 (BF) 0rm 1.067.528 1.181.023 1.118.528  
John the Ripper 1.7.1 (BF) Bartavelle 588.096 972.592 784.862  
Cain 3.3 (BF) Mao 624.169 776.505 704.342  
Woraauthbf (BF) Laszlo Toth 1.485.172  
Elcomsoft Distributed Password Recovery (BF) 2.10.137 Elcomsoft 706.747  

* Intel Pentium 4, 3 GHz, Hyperthreading, 3 GB RAM, Windows XP
** Intel Dual-Xeon, 3 GHz, Dell-1800, 4 GB RAM, Windows x64 2003 Server
*** Intel Core 2 Duo, 2.16 GHz, 2 GB. Windows XP



References


History
  • 01-nov-2006: inital version
  • 18-jan-2007: new values for checkpwd 1.22 added
  • 4-oct-2007: link to 11g benchmark added
  • 20-dec-2007: Benchmark for Elcom Distributed Password Recovery added


© 2006-2007 by Red-Database-Security GmbH - last update 20-dec-2007