April 2008

Hello world!

Just getting started here at WordPress.com.  Soon this blog will be filled with my insights into the Oracle database.

Injection Nation

I’m somewhat surprised to see a lack of Oracle blogging reaction to the recent post on The Daily WTF which goes into great detail on a case of SQL injection.  Maybe we’ve either become tired of it or we assume that “my systems don’t do that!”.

So, how do you audit or track if your system is being hit by injection?  How would you detect it?  Assume you’re “just a DBA” — and no one tells you about applications being deployed that talk to the database.  Is there a way you could tell just by looking from within the database?  What kind of assumptions would you make?

Sql tuning advisor in 10g

Oracle now offers SQL tuning recommendations. November 2004