Oracle security guru Peter Finnigan on the problem with PL/SQL

Article

Oracle security guru Peter Finnigan on the problem with PL/SQL

Mark Brunelli, News Editor

 

 

The protective wrapping around the programming language used to write procedures and commands in the Oracle Corp. database -- PL/SQL -- isn't as ironclad as some might expect, says Pete Finnigan, a well known Oracle database security guru and blogger. In fact, says Finnigan, who also serves as principal consultant and head of database security with Siemens Insight, it can be unraveled to give hackers access to sensitive data. In this SearchOracle.com podcast interview, Finnigan explains the exact nature of this problem and tells DBAs what they can do to protect their systems.

 

 

  Oracle security guru Peter Finnigan on the problem with PL/SQL  

 

    Requires Free Membership to View

    By submitting your registration information to SearchOracle.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchOracle.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

  Program highlights:  
  • (00:38) Can you give us a brief overview of the nature of this PL/SQL security problem as you see it?

     

  • (03:42) It sounds like a design problem rather than something that can be easily patched. Is this true?

     

  • (04:57) What is the worst case scenario that could result from these problems?

     

  • (06:20) Have you seen examples of folks exploiting these problems?

     

  • (09:18) Oracle's quarterly critical patch updates have been the subject of much criticism of late. What exactly is the problem here and what do you think the company needs to do to fix it?

     

  • (12:00) Oracle has had a reputation for solid security in the past. Is this still true today?

     

  • (13:45) What are some of the biggest security problems facing Oracle DBAs today, and what problems do you see on the horizon?

     

     

      Program Links:  
  • Oracle expert warns of weakness in PL/SQL: A well-known Oracle bug hunter says the wrapping mechanism used for PL/SQL -- the flagship language used in Oracle databases -- can be unraveled, exposing sensitive data.

     

  • Spotlight on Oracle security: A new one stop shop for Oracle security information.

     

  • Mr. Know-IT-All's Oracle Security Challenge: Let's find out how much you really know about Oracle security.

     


Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.