Call: +44 (0)1904 557620 Call

Pete Finnigan's Oracle Security Weblog

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

[Previous entry: "DBMS_ASSERT can be used to protect against SQL Injection"] [Next entry: "Problems with the October CPU discovered"]

Disclosure or advertising?

I saw an intersting news item this evening by Brian Martin titled "Disclosure or advertising?". This article explores whether full-disclosure of bugs is advertising or not for the researcher that finds the bug. This is quite controversial and actually is written about Oracle security bug researchers and is current if you read Oracles stance on this issue in their document "Security Vulnerability Fixing Policy and Process" in the section "credit for reporting vulnerabilities".