Oracle network encrypted data exposed.

For this exercise I will use Oracle Advanced Security Option ( ASO) with following parameters: SQLNET.ORA file: /* ASO Encryption */ SQLNET.CRYPTO_SEED = “fsdfsdfsdfsdfsdfsdfsdfsdfwrewrwerwerwesdfsdfsdfsd” SQLNET.ENCRYPTION_SERVER = REQUIRED SQLNET.ENCRYPTION_CLIENT = REQUIRED SQLNET.ENCRYPTION_TYPES_SERVER = (RC4_256) SQLNET.ENCRYPTION_TYPES_CLIENT = (RC4_256) /* ASO Checksumm */ SQLNET.CRYPTO_CHECKSUM_SERVER = REQUIRED SQLNET.CRYPTO_CHECKSUM_CLIENT = REQUIRED SQLNET.CRYPTO_CHECKSUM_TYPES_SERVER = (MD5) SQLNET.CRYPTO_CHECKSUM_TYPES_CLIENT = (MD5) * Tracing */ … Read more

Tracing Database Replay

SQL> alter session set events ‘trace[rat_wcr.*] disk=high’; Session altered. SQL> BEGIN dbms_workload_capture.start_capture(UNISTR(‘CAPTURE-demo-20100601134908′),UNISTR(‘DATA_PUMP_DIR’), 60, ‘INCLUDE’, FALSE); END; / PL/SQL procedure successfully completed. SQL> alter session set events ‘trace[rat_wcr.*] off’; Session altered. and trace file ( just a snippet ) looks like: