Oracle11g新增密碼錯誤延遲驗證

yangtingkun發表於2010-09-07

11g中,Oracle新增密碼錯誤後延遲驗證的功能,這使得透過程式來破解密碼變得更加的困難。

 

 

首先看看10.2環境中:

bash-2.03$ sqlplus /nolog

SQL*Plus: Release 10.2.0.4.0 - Production on 星期二 9 7 23:47:32 2010

Copyright (c) 1982, 2007, Oracle.  All Rights Reserved.

SQL> set time on
23:47:57 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


23:47:58 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


23:47:59 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


23:48:00 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


23:48:01 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


23:48:02 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


23:48:03 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


23:48:04 SQL>

為了避免輸入字元造成的延遲,所有的CONN TEST/A命令都是透過貼上輸入的。不難看出,在10g中並沒有任何延遲機制。

看看11.2的情況:

[oracle@bjtest ~]$ sqlplus /nolog

SQL*Plus: Release 11.2.0.1.0 Production on 星期三 9 8 08:28:05 2010

Copyright (c) 1982, 2009, Oracle.  All rights reserved.

SQL> set time on
08:28:11 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


08:28:12 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


08:28:13 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


08:28:14 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


08:28:16 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


08:28:18 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


08:28:22 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


08:28:27 SQL> conn test/a
ERROR:
ORA-01017: invalid username/password; logon denied


08:28:33 SQL> CONN TEST/TEST
已連線。
08:28:35 SQL>

3次密碼錯誤後,延遲時間看是遞增,從開始的兩秒遞增到六秒,不過這種延遲驗證的機制只在密碼錯誤時生效,最後一行密碼輸入正確,包括手頭錄入命令時間一共兩秒,說明延遲只對密碼錯誤的情況生效。

 

來自 “ ITPUB部落格 ” ,連結:http://blog.itpub.net/4227/viewspace-672925/,如需轉載,請註明出處,否則將追究法律責任。

相關文章