The 2013 Pwnie Nominee For Best Server-Side Bug

Cryptographic flaws in the Oracle Database authentication protocol (CVE-2012-3137)

Credit: Esteban Fayo

Esteban has found the only thing better than brute forcing database passwords online, brute forcing them offline with super fast GPUs without leaving a trail of failed attempts in the server logs.

(CVE-2012-3137)