<feed version="0.3"
      xmlns="http://purl.org/atom/ns#"
      xmlns:dc="http://purl.org/dc/elements/1.1/">
  <author>
    <name>Pete Finnigan</name>
    <email>pete\@petefinnigan.com</email>
  </author>
  <copyright mode="escaped"
             type="text/html">Copyright PeteFinnigan.com Ltd 2005, All rights reserved. All trademarks are the property of their respective owners and are hereby acknowledged</copyright>
  <entry>
    <id>tag:www.petefinnigan.com,2011-12-24:%2Fweblog%2Farchives%2F00001353.htm</id>
    <author>
      <name>Pete Finnigan</name>
      <email>pete\@petefinnigan.com</email>
    </author>
    <content mode="escaped"
             type="text/html">  &amp;lt;p&amp;gt; Alex commented on my post about &amp;quot; oradebug &amp;quot; about the select statement on x$ksmfsv which holds a list of all fixed variables amongst other things and joined it to x$ksmmem to get the absolute address in the SGA to....&amp;lt;a href=&amp;quot;http://www.petefinnigan.com/weblog/archives/00001353.htm&amp;quot;&amp;gt;[Read More]&amp;lt;/a&amp;gt; &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;Posted by Pete On 21/09/11 At 07:26 PM&amp;lt;/p&amp;gt;</content>
    <issued>2011-12-24T09:27:11Z</issued>
    <link href="http://www.petefinnigan.com/weblog/archives/00001353.htm"
          rel="alternate"
          type="text/html" />
    <modified>2011-12-24T09:27:11Z</modified>
    <title mode="escaped"
           type="text/html">More oradebug</title>
  </entry>
  <entry>
    <id>tag:www.petefinnigan.com,2011-12-24:%2Fweblog%2Farchives%2F00001352.htm</id>
    <author>
      <name>Pete Finnigan</name>
      <email>pete\@petefinnigan.com</email>
    </author>
    <content mode="escaped"
             type="text/html">  &amp;lt;p&amp;gt; Laszlo has published his slides from Hacktivity in Budapest last weekend where he shows how the Oracle undocumented oradebug command can be used to exploit the database; covering turning off authentication, turning off audit and more. His slides are here....&amp;lt;a href=&amp;quot;http://www.petefinnigan.com/weblog/archives/00001352.htm&amp;quot;&amp;gt;[Read More]&amp;lt;/a&amp;gt; &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;Posted by Pete On 21/09/11 At 12:54 PM&amp;lt;/p&amp;gt;</content>
    <issued>2011-12-24T09:27:11Z</issued>
    <link href="http://www.petefinnigan.com/weblog/archives/00001352.htm"
          rel="alternate"
          type="text/html" />
    <modified>2011-12-24T09:27:11Z</modified>
    <title mode="escaped"
           type="text/html">oradebug</title>
  </entry>
  <entry>
    <id>tag:www.petefinnigan.com,2011-12-24:%2Fweblog%2Farchives%2F00001351.htm</id>
    <author>
      <name>Pete Finnigan</name>
      <email>pete\@petefinnigan.com</email>
    </author>
    <content mode="escaped"
             type="text/html">  &amp;lt;p&amp;gt; I spoke at the UKOUG special security day event last week at Bletchley Park just outside of Milton Keynes. We had a great agenda for the day which was focused on Data Security. We had Ian Glover of CREST and....&amp;lt;a href=&amp;quot;http://www.petefinnigan.com/weblog/archives/00001351.htm&amp;quot;&amp;gt;[Read More]&amp;lt;/a&amp;gt; &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;Posted by Pete On 19/09/11 At 04:07 PM&amp;lt;/p&amp;gt;</content>
    <issued>2011-12-24T09:27:11Z</issued>
    <link href="http://www.petefinnigan.com/weblog/archives/00001351.htm"
          rel="alternate"
          type="text/html" />
    <modified>2011-12-24T09:27:11Z</modified>
    <title mode="escaped"
           type="text/html">UKOUG Oracle Data Security Day presentation slides available</title>
  </entry>
  <entry>
    <id>tag:www.petefinnigan.com,2011-12-24:%2Fweblog%2Farchives%2F00001350.htm</id>
    <author>
      <name>Pete Finnigan</name>
      <email>pete\@petefinnigan.com</email>
    </author>
    <content mode="escaped"
             type="text/html">  &amp;lt;p&amp;gt; Ron Reidy will be teaching my 2 day class &amp;quot; how to perform a security audit of an Oracle database &amp;quot; in Denver, CO, USA on November 10th and November 11th 2011. The class is a public course so if....&amp;lt;a href=&amp;quot;http://www.petefinnigan.com/weblog/archives/00001350.htm&amp;quot;&amp;gt;[Read More]&amp;lt;/a&amp;gt; &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;Posted by Pete On 06/09/11 At 09:49 AM&amp;lt;/p&amp;gt;</content>
    <issued>2011-12-24T09:27:11Z</issued>
    <link href="http://www.petefinnigan.com/weblog/archives/00001350.htm"
          rel="alternate"
          type="text/html" />
    <modified>2011-12-24T09:27:11Z</modified>
    <title mode="escaped"
           type="text/html">Oracle Security Training in Denver, USA</title>
  </entry>
  <entry>
    <id>tag:www.petefinnigan.com,2011-12-24:%2Fweblog%2Farchives%2F00001349.htm</id>
    <author>
      <name>Pete Finnigan</name>
      <email>pete\@petefinnigan.com</email>
    </author>
    <content mode="escaped"
             type="text/html">  &amp;lt;p&amp;gt; I noticed a few days ago that David Litchfield had posted two new short papers on Oracle security; one is related to global cursors declared in PL/SQL packages, the other about cursor variable type SYS_REFCURSOR being passed out of functions/procedures....&amp;lt;a href=&amp;quot;http://www.petefinnigan.com/weblog/archives/00001349.htm&amp;quot;&amp;gt;[Read More]&amp;lt;/a&amp;gt; &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;Posted by Pete On 06/07/11 At 01:20 PM&amp;lt;/p&amp;gt;</content>
    <issued>2011-12-24T09:27:11Z</issued>
    <link href="http://www.petefinnigan.com/weblog/archives/00001349.htm"
          rel="alternate"
          type="text/html" />
    <modified>2011-12-24T09:27:11Z</modified>
    <title mode="escaped"
           type="text/html">Cursor variable and global cursors security issues</title>
  </entry>
  <entry>
    <id>tag:www.petefinnigan.com,2011-12-24:%2Fweblog%2Farchives%2F00001348.htm</id>
    <author>
      <name>Pete Finnigan</name>
      <email>pete\@petefinnigan.com</email>
    </author>
    <content mode="escaped"
             type="text/html">  &amp;lt;p&amp;gt; Time flies by so fast..:-), its been two months since my last blog post but it only seems like yesterday...:-(, Times are very busy for me so blogging has become harder to fit in. Just writing a blog post seems....&amp;lt;a href=&amp;quot;http://www.petefinnigan.com/weblog/archives/00001348.htm&amp;quot;&amp;gt;[Read More]&amp;lt;/a&amp;gt; &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;Posted by Pete On 24/06/11 At 11:29 AM&amp;lt;/p&amp;gt;</content>
    <issued>2011-12-24T09:27:11Z</issued>
    <link href="http://www.petefinnigan.com/weblog/archives/00001348.htm"
          rel="alternate"
          type="text/html" />
    <modified>2011-12-24T09:27:11Z</modified>
    <title mode="escaped"
           type="text/html">Training, twitter, Oracle security products</title>
  </entry>
  <entry>
    <id>tag:www.petefinnigan.com,2011-12-24:%2Fweblog%2Farchives%2F00001347.htm</id>
    <author>
      <name>Pete Finnigan</name>
      <email>pete\@petefinnigan.com</email>
    </author>
    <content mode="escaped"
             type="text/html">  &amp;lt;p&amp;gt; David has released four new papers on Oracle security topics a few days ago. Two of the papers seem to be from his ill fated book on Oracle Forensics as they are labelled &amp;quot; chapter 3 - How attackers break....&amp;lt;a href=&amp;quot;http://www.petefinnigan.com/weblog/archives/00001347.htm&amp;quot;&amp;gt;[Read More]&amp;lt;/a&amp;gt; &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;Posted by Pete On 20/04/11 At 09:50 AM&amp;lt;/p&amp;gt;</content>
    <issued>2011-12-24T09:27:11Z</issued>
    <link href="http://www.petefinnigan.com/weblog/archives/00001347.htm"
          rel="alternate"
          type="text/html" />
    <modified>2011-12-24T09:27:11Z</modified>
    <title mode="escaped"
           type="text/html">New Oracle security papers and Oracle forensics tool</title>
  </entry>
  <entry>
    <id>tag:www.petefinnigan.com,2011-12-24:%2Fweblog%2Farchives%2F00001346.htm</id>
    <author>
      <name>Pete Finnigan</name>
      <email>pete\@petefinnigan.com</email>
    </author>
    <content mode="escaped"
             type="text/html">  &amp;lt;p&amp;gt; Marcel-Jan emailed me an article on arstechnica a few days ago and has now written a forum post titled &amp;quot; How Anonymous hacked HBGary &amp;quot;. This is intersting reading and shows that simple techniques can be used to abuse systems....&amp;lt;a href=&amp;quot;http://www.petefinnigan.com/weblog/archives/00001346.htm&amp;quot;&amp;gt;[Read More]&amp;lt;/a&amp;gt; &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;Posted by Pete On 03/03/11 At 02:14 PM&amp;lt;/p&amp;gt;</content>
    <issued>2011-12-24T09:27:11Z</issued>
    <link href="http://www.petefinnigan.com/weblog/archives/00001346.htm"
          rel="alternate"
          type="text/html" />
    <modified>2011-12-24T09:27:11Z</modified>
    <title mode="escaped"
           type="text/html">SQL Injection Attack</title>
  </entry>
  <generator url="http://search.cpan.org/dist/XML-Atom-SimpleFeed"
             version="0.7">XML::Atom::SimpleFeed</generator>
  <link href="http://www.petefinnigan.com/weblog/entries"
        rel="alternate"
        type="text/html" />
  <modified>2011-12-24T09:27:11Z</modified>
  <tagline mode="escaped"
           type="text/html">PeteFinnigan.com's weblog is the only weblog dedicated to Oracle security.</tagline>
  <title mode="escaped"
         type="text/html">Pete Finnigan's Oracle security weblog</title>
</feed>

