Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 18 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » July 2007 » More SQL Injection

[Previous entry: "Please dont SQL Inject a bank"] [Next entry: "database security bloopers"]

More SQL Injection

July 10th, 2007 by Pete

Post to del.icio.us   Post to Furl   Digg!

Alex has posted an entry in his blog yesterday titled "he that is without sin among you, let him cast a stone at her" on the same subject that Tom and then I spoke about, the error message from a bank around SQL Injection. Alex makes some points about where the developers of these types of applications learn to code applications vulnerable to SQL Injection. He points at Tom's book, David Knox, Kevin Loney and others. I think he makes a good point as where do developers learn to code against Oracle? - training, Oracle documentation, Oracle sample programs and of course popular books.

Alex then commented on Toms blog and an interesting conversation started. Tom does know what SQL Injection is, he has made a recent acreer talking about bind variables and SQL Injection and I am hoping he will cover security and of course SQL Injection and more with gusto when we get to see the second volume of his book. I remember he even canvassed for subjects and security was in there amongst them. Alex has amde a very good point, that people do learn from peers, mentors, BOOKS and training; I think the unfortunate apsect of all of this is that writers of these media have not taken security into account until very recently even though issues like SQL Injection have been known for many years now. Lets hope that everyone writes with security in mind and that old and new generations of coders understand the risks and dont provide these loopholes.


July 2007
SMTWTFS
1234567
891011121314
15161718192021
22232425262728
293031    

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!