Pete Finnigan
@petefinnigan
Followers
4K
Following
6K
Media
988
Statuses
5K
Living, breathing Oracle Security; Oracle ACE on security; OAK table member. Database security audits, consulting and training on all aspects of Oracle security
York, England
Joined November 2009
I will be teaching a 3 day Oracle Security class in York, UK from 3rd to 5th December 2025. Full details of the class are here - https://t.co/3p4ha7x20u - Rare opportunity to be taught in person. To book early as places limited #oracle #security #training #oracleace
0
0
3
"because of how the shell script was constructed, converted into shell input and the stars were converted in his case to file listings from the CWD (Current Working Directory)." - https://t.co/QEyqOCwAZr
#oracleace #oracle #sql #notice
0
0
0
"Unwrapping PL/SQL" We are here to help you secure your data in your Oracle database. Contact us - https://t.co/ynS25DdGB6
#oracleace #oracle #security #plsql #securecode #securityaudit #databreach #forensics #datasecurity Please like, follow and share our pages and posts.
0
0
0
If you’re responsible for managing, designing or auditing Oracle databases, then the upcoming three-day course by Pete Finnigan is one you won’t want to miss - https://t.co/3U9pNqnGSP - #oracleace #OracleSecurity #DatabaseSecurity #OracleDBA #CyberSecurityTraining #OracleTraining
0
0
1
"So in simple terms you may want to gather SQL statements that have been executed to see if any of them are dodgy BUT gathering the SQL statements means running SQL ..." - https://t.co/09KRK9XS2l
#oracleace #oracle #database #forensics
0
0
1
"The talk is about what to do if there is a breach of an Oracle database. This covers the response process which is in essence a checklist of actions to take when there is a breach" - https://t.co/09KRK9XS2l
#oracleace #oracle #database #forensics
0
0
0
0
0
3
"But some shell scripts (bash, sh, ksh etc) that then called sqlplus to connect to the database read in the output which included the banner..." - https://t.co/QEyqOCwAZr
#oracleace #oracle #sql #notice
0
0
3
"A good list of Oracle security check items" We are here to help you secure your data in your Oracle database. Contact us - https://t.co/ynS25DdGB6
#oracleace #oracle #data #plsql #securecode #securityaudit #datasecurity Please like, follow and share our pages and posts.
0
0
5
"He said he had implemented something similar using a logon trigger many many years ago where this logon trigger was able to output a banner of the form..." - https://t.co/QEyqOCwAZr
#oracleace #oracle #sql #notice
0
0
0
0
0
0
"Perform Live Response : Collect the live data that is held in memory; users logged in, contents of current SQL and more..." - https://t.co/9ZDo7MWYC1
#oracleace #security #forensics #liveresponse
0
0
2
"All of this is measured and controlled at the ERP level BUT the controls and settings are mostly stored in an Oracle database and usually that database does not have deep levels of security..." - https://t.co/wMEdjCtEON
#oracleace #database #security #gdpr
0
0
0
"In that post Add A SQL*Net Security Banner And Audit Notice I talked about using the sqlnet.ora parameters SEC_USER_AUDIT_ACTION_BANNER..." - https://t.co/QEyqOCwAZr
#oracleace #oracle #sql #notice
0
0
2
"Getting started with Oracle security" We are here to help you secure your data in your Oracle database. Contact us - https://t.co/ynS25DdGB6
#oracleace #oracle #data #security #plsql #securecode #securityaudit #datasecurity Please like, follow and share our pages and posts.
0
0
2
"Provide Training: Ensure that all of the response team in advance of a breach are trained on how to respond to a data breach in an Oracle database and trained on how to use the relevant tools" - https://t.co/9ZDo7MWYC1
#oracleace #security #forensics #liveresponse
0
0
0
"Appoint an incident response co-ordinator : Identify someone who will manage the response when it happens. This ideally should not be someone deeply involved in a breach. I.e. the DBA..." - https://t.co/9ZDo7MWYC1
#oracleace #security #forensics #liveresponse
0
0
2
Be Careful of What You Include In SQL*Net Security Banners. - https://t.co/QEyqOCwAZr
#oracleace #oracle #sql #notice
0
0
3
"At a high level an ERP can be looked at in a security way for Conflicts of interest. Separation of Duties, Fraud, limits, menus, access controls, business level controls, compliance and more." - https://t.co/wMEdjCtEON
#oracleace #database #security #gdpr
0
0
0
"because of how the shell script was constructed, converted into shell input and the stars were converted in his case to file listings from the CWD (Current Working Directory)." - https://t.co/QEyqOCwAZr
#oracleace #oracle #security #banner
0
0
2
"This is a huge subject that cannot be done detailed justice here as a blog BUT lets dive in and discuss the high level points of investigating a breach of an Oracle database." - https://t.co/9ZDo7MWYC1
#oracleace #security #forensics #liveresponse
0
1
4