OWASP Leeds meeting slides available
Firstly, I find this interesting as if the main ideas of exploiting via SQL injection were 5 - 7 years ago then the big problem (i.e. why people are still getting injected) must be lack of training, lack of acceptance of the problem, lack of work on the systems to protect agains SQl Injection or perhaps the wrong protections? It was a really interesting idea though.
After Justin finished I launched into the "Right way to secure Oracle"; this is a talk I have done before for the UKOUG but i modified it a bit and extended it to one hour. The talk basically looks at the reasons why you must start with the data if you want to have a hope of securing your database. This talk seemed to go down well and I have had quite a few emails today from people who were there complementing me on it. The slides are on my Oracle security white papers page.