Radoslav Rusinov's Blog and mod_plsql passwords in clear text
This post talks about how easy it is to get at DAD passwords in clear text in pre-10g versions. I was aware of this previously as I mention this in my book and also the SANS course but Radoslav has given a very good discussion of the issue with examples and also tips on how to secure. He also includes a Java program for decrypting the base64 encoded passwords and also a link to an online decoder. This is a great blog so far and well worth watching in the future.