Pete Finnigan's Avatar

Pete Finnigan

@petefinnigan.bsky.social

Living, breathing Oracle Security; Oracle ACE on security; OAK table member. Database security audits, consulting and training on all aspects of Oracle security - http://www.petefinnigan.com/training/oracle_security_training_in_york_2025.htm

422 Followers  |  317 Following  |  47 Posts  |  Joined: 17.11.2024  |  1.6173

Latest posts by petefinnigan.bsky.social on Bluesky

Post image

Are you worried that someone could steal the data from your Oracle database? Do you feel overwhelmed and need guidance to secure your database.

I will be teaching 3 days in depth training in York, UK on the 3rd, 4th and 5th December 2025. lnkd.in/eniNGiQP

Book your place now -

03.11.2025 16:48 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

I will be teaching a 3 day Oracle Security class in York, UK from 3rd to 5th December 2025. Full details of the class are here - www.petefinnigan.com/training/ora... - Rare opportunity to be taught in person. To book early as places limited #oracle #security #training #oracleace

21.10.2025 12:51 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

I have just posted a new blog discussing AI and AI for Oracle Security - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #ukoug #ai #UKOUGDiscover25 #OracleCommunity #JoelKallmanDay #oracle #database #AI

15.10.2025 13:31 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Post image

Brand new blog post discussing how we may block DISABLE TRIGGER to help with designing security solutions within the database - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #database #security #grants #ddl #trigger #protect #hacking #databreach #UKOUGDiscover2025

24.09.2025 09:31 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I have been accepted to speak twice at the UKOUG conference in December - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #UKOUGDiscover25 #UKOUG #conference #community #oracle #database #security #fuzzing #design #plsql

22.09.2025 16:56 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

My Oracle Security blog is 21 next week. I have created a summary post detailing some of the blog journey - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #database #security #tools #software #training #products #blogging #birthday

10.09.2025 12:21 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Is it possible in Oracle to stop your own procedure/package from being executed by someone with EXECUTE ANY PROCEDURE? - petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #security #audit #trail #audittrail #databreach #hacking #grants #protect #readonly #table

09.09.2025 12:30 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Testing our secured schema and table to allow READONLY and delete and insert only via an API - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #security #audit #trail #audittrail #databreach #hacking #grants #protect #readonly #table

03.09.2025 12:08 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Lets implement an account you cannot log into and a table that you can read but not delete/insert except by an API and no updates! - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #security #audit #trail #audittrail #grants #protect #readonly #table

26.08.2025 09:37 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

New blog discussing how we may replicate the security of the AUDSYS.AUD$UNIFIED table without access to Oracle secret sauce - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #security #audit #unified #protect #audittrail #databreach #readonly #grants #protection

19.08.2025 12:58 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

What is a schema in Oracle and what does the CREATE SCHEMA command do? - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #database #security #create #schema

14.08.2025 09:05 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Exploring how Oracle may or may not secure AUDSYS and AUD$UNIFIED - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #security #audit #unified #protect #audittrail #databreach

12.08.2025 13:24 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Twisted foot sideways and heard loud snap so knew it was broken. Rang 111, A&E and Urgent Care, x-ray &had the boot fitted quickly. 4-6 weeks for it to heal BUT all Oracle Security work, training and products are available #oracleace #sym_42 #oracle #security #training #software

11.08.2025 15:08 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

A new PL/SQL unwrapper for 9i and lower - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #plsql #unwrap #reverse #engineering #security

07.08.2025 11:31 β€” πŸ‘ 7    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

New blog about attacking and protecting the Oracle database from file system issues - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #database #security #dos #hacking #file #directory #java

05.08.2025 12:29 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Thanks for this great insight Christoph

05.08.2025 12:28 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Oracle protects the user AUDSYS and makes the table AUD$UNIFIED read only; not 100% true because Oracle writes to it and allows delete via DBMS_AUDIT_MGMT. How does this work - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #security #audit #trail #unifiedaudit #readonly

31.07.2025 10:04 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Would you be surprised to know that if you issue one DDL command in Oracle that it actually does two DDL commands? - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #database #security #ddl #grants #privileges #hacking

28.07.2025 11:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Don't be caught out using Mixed Mode Unified audit and find that your unified audit trail stops working - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #unified #audit #oracle #database #security #audittrail #audit

22.07.2025 08:57 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Blog post about auditing Oracle databases - www.petefinnigan.com/weblog/archi... - creating a security score, alerts score as well as adaptive audit trails and security and finally a black-box flight recorder for Oracle databases - #oracleace #sym_42 #oracle #database #security #audit

10.07.2025 14:42 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I have just created a blog post discussing privilege escalation in Oracle - www.petefinnigan.com/weblog/archi... - #oracleace @oracleace #sym_42 #oracle #security #privilege #escalation #roles #grants #databreach #hacking #training

03.07.2025 10:03 β€” πŸ‘ 8    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

More details in - www.petefinnigan.com/weblog/archi... - discussing June 29th. 30 years since I got a first class honours degree in Electronics and 49 years since myself and Paul stopped an express train from crashing - #oracleace #oracle #security #traincrash #degree #electronics #june29th

26.06.2025 11:24 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Thanks #oracleace @oracleace for accepting me as an Oracle ACE Pro for another year!!

25.06.2025 09:21 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Great news yesterday and extremely honoured to get an email from @oracleace to let me know I am an Oracle ACE Pro for 2025 to 2026. Thanks!

06.06.2025 07:57 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

PFCLScan can be used to look for vulnerabilities in an Oracle database. I have written a brief history of the development of this tool as someone asked me about it recently - www.petefinnigan.com/weblog/archi... - #oracle #security #pfclscan #vulnerability #scanner #breach #databreach #datasecurity

15.05.2025 10:36 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Finally changed PeteFinnigan.com to HTTPS. I know some people have commented over the years about this BUT the site was / is static and we do not collect any data so strictly HTTPS was not necessary but we have implemented it - www.petefinnigan.com/weblog/archi... - #oracle #security #website #https

14.05.2025 08:31 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Is it possible to extend a PL/SQL application including Apex at runtime by embedding a script engine into it? - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #plsql #apex #scripting #compiler #interpreter #oracle #security

14.04.2025 11:41 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Are there any hidden, undocumented or public interfaces to wallets that can be used to manage encryption keys for DBMS_CRYPTO? - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #key #vault #wallet #encryption #tde #key

07.04.2025 13:13 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Are you concerned about key management when using DBMS_CRYPTO in your Oracle database to encrypt your data? - www.petefinnigan.com/weblog/archi... - #oracleace #sym_42 #oracle #data #encryption #security #datasecurity #keys #vault #audit #audittrails

02.04.2025 14:18 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

on my way to Oracle Cloud World London 2025 #ocw #oracleace #sym_42

20.03.2025 08:34 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@petefinnigan is following 20 prominent accounts