OracSec is a simple utility that can be used to enumerate SID's and carry out a simple username and password check against all default known usernames and passwords.  For databases Oracle 9i and below, SID's will be self enumerated for databases above this, the SID has to be supplied.


It is available from here.  (The link is not reliable I have found).




Double-click of the .exe will install the application.




Insert the IP address and port number, SID is only required for Oracle 10g+.

Highlight the instance and click on the padlock.

All default accounts will be displayed.



There is also an update feature.


I would liken this to OAT with a graphical front-end.


