<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Pete Finnigan's Oracle security weblog</title>
<link>http://www.petefinnigan.com/weblog/entries</link>
<description>PeteFinnigan.com's weblog is the only weblog dedicated to Oracle security.</description>
<copyright>Copyright PeteFinnigan.com Ltd 2005, All rights reserved. All trademarks are the property of their respective owners and are hereby acknowledged</copyright>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
<lastBuildDate>Fri, 16 May 2008 20:52:04 +0100</lastBuildDate>

<image>
<title>Pete Finnigan's Oracle security weblog</title>
<url>http://www.petefinnigan.com/images/company_logo_1.gif</url>
<link>http://www.petefinnigan.com/weblog/entries</link>
<width>144</width>
</image>

<item>
<title>Howard&apos;s DORIS script is available again - some security comments from me</title>
<link>http://www.petefinnigan.com/weblog/archives/00001172.htm</link>
<description>  &lt;p&gt; I noticed today that Howard&apos;s Dizwell-Oracle Reliable Installation Script (DORIS) version 1.0a shell script is available again for download. This is a useful script and great for installing Oracle on Linux without resorting to reading loads of &quot;how-to&quot; sites. Howard....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001172.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 16/05/08 At 07:50 PM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001172.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

<item>
<title>License Plate scanners and SQL Injection</title>
<link>http://www.petefinnigan.com/weblog/archives/00001171.htm</link>
<description>  &lt;p&gt; I posted a couple of days ago a link to an almost certain hoax of a license plate of a red mini that had been altered to include SQL Injection. This was in a post titled License Plate SQL Injection....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001171.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 15/05/08 At 09:02 PM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001171.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

<item>
<title>Oracle Application Server 10g ORA_DAV basic authentication bypass</title>
<link>http://www.petefinnigan.com/weblog/archives/00001170.htm</link>
<description>  &lt;p&gt; I would recommend anyone that is interested in securing their Oracle database to subscribe to some of the major security lists such as the bugtraq list at securityfocus.com or the full disclosure list. There are plent more besides these, but....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001170.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 14/05/08 At 07:42 PM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001170.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

<item>
<title>License plate SQL Injection</title>
<link>http://www.petefinnigan.com/weblog/archives/00001169.htm</link>
<description>  &lt;p&gt; Wow, its been a while since I posted, I have been travelling all over the world over the last month or so, teaching my Oracle security class and also speaking at conferences and performing Oracle security audits. It&apos;s been a....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001169.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 13/05/08 At 07:38 PM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001169.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

<item>
<title>Slides from OUG Scotland DBA SIG on Oracle Forensics available</title>
<link>http://www.petefinnigan.com/weblog/archives/00001168.htm</link>
<description>  &lt;p&gt; I have posted the slides to my talk from yesterday at the OUG Scotland SIG to my Oracle Security white papers page . They are the first entries in the page. The talk was 45 minutes about Oracle Forensics. This....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001168.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 01/05/08 At 02:23 PM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001168.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

<item>
<title>Conditionally firing triggers</title>
<link>http://www.petefinnigan.com/weblog/archives/00001167.htm</link>
<description>  &lt;p&gt; I saw a post on the BAR Solutions blog today titled &quot; Triggers… &quot; that was very interesting as I have had the same issue in the past for different reasons. The blog post was around an issue where triggers....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001167.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 01/05/08 At 01:22 PM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001167.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

<item>
<title>Lateral SQL Injection and Conferences and security training</title>
<link>http://www.petefinnigan.com/weblog/archives/00001166.htm</link>
<description>  &lt;p&gt; I am writing this whilst sat on a train travelling at around 120mph between York and Darlington, this is probably my first blog entry written at speed! I saw that David had released his paper &quot; Lateral SQL Injection: A....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001166.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 30/04/08 At 08:26 AM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001166.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

<item>
<title>Slides from OUGN Norway and RISK 2008 Norway available</title>
<link>http://www.petefinnigan.com/weblog/archives/00001165.htm</link>
<description>  &lt;p&gt; I was over in Norway this week and the Oracle User Group Norway (OUGN) asked me to speak at an evening user group meeting of theirs. This was a eally friendly group and it was a pleasure to speak there....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001165.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 25/04/08 At 05:58 PM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001165.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

<item>
<title>Two remotely exploitable without authentication bugs to be fixed</title>
<link>http://www.petefinnigan.com/weblog/archives/00001164.htm</link>
<description>  &lt;p&gt; Oracle&apos;s pre-patch advisory note for the next Critical Patch Update (CPU) due this Tuesday (15th) states that there are 17 new security fixes for the database, two for Apex and two of which are remotely exploitable without authentication. The advisory....&lt;a href=&quot;http://www.petefinnigan.com/weblog/archives/00001164.htm&quot;&gt;[Read More]&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Posted by Pete On 14/04/08 At 10:17 AM&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.petefinnigan.com/weblog/archives/00001164.htm</guid>
<pubDate>Fri, 16 May 2008 20:52:04 +0100</pubDate>
</item>

</channel>
</rss>