Andrew Clarke has a post about Google hacking Oracle

I saw today a post on Andrew's blog titled "Oracle...Most Insecure Database!" which relates the story of an Oracle forums post that is now not working, most likely removed!. The post talked about a person who had been reading an excellent paper on Application Security Inc's site titled "Search Engines used to attack databases" and then apparently applying what he had learned to hacking Oracle databases. Andrew had confirmed with the OP that he had in fact attacked his own Oracle databases.

This post prompted me to re-read Aaron's paper which is excellent.