<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=James+Vaughan</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=James+Vaughan"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/James_Vaughan"/>
		<updated>2026-05-28T13:05:33Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ApEx:SQL_injection&amp;diff=158274</id>
		<title>ApEx:SQL injection</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ApEx:SQL_injection&amp;diff=158274"/>
				<updated>2013-09-11T16:39:16Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Don't use substitution variables &amp;amp; but bind variables :&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
At KScope 2013, a presentation was given about SQL Injection in Oracle APEX applications. The two demonstrations given during this presentation are available as videos:&lt;br /&gt;
&lt;br /&gt;
* [1] [http://bit.ly/14Ybo21 APEX SQL Injection demonstration 1 (dynamic SQL and SQLMAP)]&lt;br /&gt;
* [2] [http://bit.ly/137HDgm APEX SQL Injection demonstration 2 (substitution variables and manual exploitation)]&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Application_Express_(ApEx)&amp;diff=158273</id>
		<title>Application Express (ApEx)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Application_Express_(ApEx)&amp;diff=158273"/>
				<updated>2013-09-11T16:38:47Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Oracle Application Express (Oracle APEX), formerly called HTML DB, is a rapid web application development tool for the Oracle database. Using only a web browser and limited programming experience, you can develop and deploy professional applications that are both fast and secure. Oracle application express combines the qualities of a personal database, productivity, ease of use, and flexibility with the qualities of an enterprise database, security, integrity, scalability, availability and built for the web. Application Express is a tool to build web-based applications and the application development environment is also conveniently web-based.&lt;br /&gt;
&lt;br /&gt;
''A more generic description is needed, this is a copy from the Oracle ApEx Site''&lt;br /&gt;
&lt;br /&gt;
* [[ApEx:XSS]]&lt;br /&gt;
* [[ApEx:SQL injection]]&lt;br /&gt;
* [[ApEx:URL Tampering]]&lt;br /&gt;
* [[ApEx:Authentication]]&lt;br /&gt;
* [[ApEx:Authorization Schemes]]&lt;br /&gt;
* [[ApEx:Defence in depth]]&lt;br /&gt;
* [[ApEx:Configuration]]&lt;br /&gt;
* [[ApEx:Google dorks]]&lt;br /&gt;
* [[ApEx:Architecture]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
* [1] [http://www.oracle.com/technology/products/database/application_express/html/what_is_apex.html Official Oracle APEX website]&lt;br /&gt;
&lt;br /&gt;
=== External Resources ===&lt;br /&gt;
&lt;br /&gt;
There have been two books written specifically about Oracle APEX and security, both released in 2013.&lt;br /&gt;
&lt;br /&gt;
* [1] [http://www.amazon.com/Application-Express-Security-Experts-ebook/dp/B00ACC6AO6/ Expert Oracle Application Express Security]&lt;br /&gt;
* [2] [http://apexsec.recx.co.uk/apex-security-ebook/ Hands-On Oracle Application Express Security: Building Secure Apex Applications]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Oracle Project]]&lt;br /&gt;
[[Category:Development]]&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Application_Express_(ApEx)&amp;diff=158272</id>
		<title>Application Express (ApEx)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Application_Express_(ApEx)&amp;diff=158272"/>
				<updated>2013-09-11T16:37:33Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: Change ApEx to APEX in references&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Oracle Application Express (Oracle APEX), formerly called HTML DB, is a rapid web application development tool for the Oracle database. Using only a web browser and limited programming experience, you can develop and deploy professional applications that are both fast and secure. Oracle application express combines the qualities of a personal database, productivity, ease of use, and flexibility with the qualities of an enterprise database, security, integrity, scalability, availability and built for the web. Application Express is a tool to build web-based applications and the application development environment is also conveniently web-based.&lt;br /&gt;
&lt;br /&gt;
''A more generic description is needed, this is a copy from the Oracle ApEx Site''&lt;br /&gt;
&lt;br /&gt;
* [[ApEx:XSS]]&lt;br /&gt;
* [[ApEx:SQL injection]]&lt;br /&gt;
* [[ApEx:URL Tampering]]&lt;br /&gt;
* [[ApEx:Authentication]]&lt;br /&gt;
* [[ApEx:Authorization Schemes]]&lt;br /&gt;
* [[ApEx:Defence in depth]]&lt;br /&gt;
* [[ApEx:Configuration]]&lt;br /&gt;
* [[ApEx:Google dorks]]&lt;br /&gt;
* [[ApEx:Architecture]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
* [1] [http://www.oracle.com/technology/products/database/application_express/html/what_is_apex.html Official Oracle APEX website]&lt;br /&gt;
&lt;br /&gt;
=== External Resources ===&lt;br /&gt;
&lt;br /&gt;
There have been two books written specifically about Oracle APEX and security, both released in 2013.&lt;br /&gt;
&lt;br /&gt;
[1] [http://www.amazon.com/Application-Express-Security-Experts-ebook/dp/B00ACC6AO6/ Expert Oracle Application Express Security]&amp;lt;br&amp;gt;&lt;br /&gt;
[2] [http://apexsec.recx.co.uk/apex-security-ebook/ Hands-On Oracle Application Express Security: Building Secure Apex Applications]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Oracle Project]]&lt;br /&gt;
[[Category:Development]]&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Application_Express_(ApEx)&amp;diff=158271</id>
		<title>Application Express (ApEx)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Application_Express_(ApEx)&amp;diff=158271"/>
				<updated>2013-09-11T16:37:08Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Oracle Application Express (Oracle APEX), formerly called HTML DB, is a rapid web application development tool for the Oracle database. Using only a web browser and limited programming experience, you can develop and deploy professional applications that are both fast and secure. Oracle application express combines the qualities of a personal database, productivity, ease of use, and flexibility with the qualities of an enterprise database, security, integrity, scalability, availability and built for the web. Application Express is a tool to build web-based applications and the application development environment is also conveniently web-based.&lt;br /&gt;
&lt;br /&gt;
''A more generic description is needed, this is a copy from the Oracle ApEx Site''&lt;br /&gt;
&lt;br /&gt;
* [[ApEx:XSS]]&lt;br /&gt;
* [[ApEx:SQL injection]]&lt;br /&gt;
* [[ApEx:URL Tampering]]&lt;br /&gt;
* [[ApEx:Authentication]]&lt;br /&gt;
* [[ApEx:Authorization Schemes]]&lt;br /&gt;
* [[ApEx:Defence in depth]]&lt;br /&gt;
* [[ApEx:Configuration]]&lt;br /&gt;
* [[ApEx:Google dorks]]&lt;br /&gt;
* [[ApEx:Architecture]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
* [1] [http://www.oracle.com/technology/products/database/application_express/html/what_is_apex.html Official Oracle ApEx website]&lt;br /&gt;
&lt;br /&gt;
=== External Resources ===&lt;br /&gt;
&lt;br /&gt;
There have been two books written specifically about Oracle APEX and security, both released in 2013.&lt;br /&gt;
&lt;br /&gt;
[1] [http://www.amazon.com/Application-Express-Security-Experts-ebook/dp/B00ACC6AO6/ Expert Oracle Application Express Security]&amp;lt;br&amp;gt;&lt;br /&gt;
[2] [http://apexsec.recx.co.uk/apex-security-ebook/ Hands-On Oracle Application Express Security: Building Secure Apex Applications]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Oracle Project]]&lt;br /&gt;
[[Category:Development]]&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ApEx:SQL_injection&amp;diff=158270</id>
		<title>ApEx:SQL injection</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ApEx:SQL_injection&amp;diff=158270"/>
				<updated>2013-09-11T15:24:34Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: Added a references section, which includes two external links to videos demonstrating SQL injection into Oracle APEX applications given at KScope 2013.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Don't use substitution variables &amp;amp; but bind variables :&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
At KScope 2013, a presentation was given about SQL Injection in Oracle APEX applications. The two demonstrations given during this presentation are available as videos:&lt;br /&gt;
&lt;br /&gt;
* [1] [http://bit.ly/14Ybo21 APEX SQL Injection demonstration 1 (dynamic SQL and SQLMAP)]&amp;lt;br&amp;gt;&lt;br /&gt;
* [2] [http://bit.ly/137HDgm APEX SQL Injection demonstration 2 (substitution variables and manual exploitation)]&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Application_Express_(ApEx)&amp;diff=158269</id>
		<title>Application Express (ApEx)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Application_Express_(ApEx)&amp;diff=158269"/>
				<updated>2013-09-11T15:21:44Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: Added two external references to books that have been authored on the subject of Oracle Application Express security.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Oracle Application Express (Oracle APEX), formerly called HTML DB, is a rapid web application development tool for the Oracle database. Using only a web browser and limited programming experience, you can develop and deploy professional applications that are both fast and secure. Oracle application express combines the qualities of a personal database, productivity, ease of use, and flexibility with the qualities of an enterprise database, security, integrity, scalability, availability and built for the web. Application Express is a tool to build web-based applications and the application development environment is also conveniently web-based.&lt;br /&gt;
&lt;br /&gt;
''A more generic description is needed, this is a copy from the Oracle ApEx Site''&lt;br /&gt;
&lt;br /&gt;
* [[ApEx:XSS]]&lt;br /&gt;
* [[ApEx:SQL injection]]&lt;br /&gt;
* [[ApEx:URL Tampering]]&lt;br /&gt;
* [[ApEx:Authentication]]&lt;br /&gt;
* [[ApEx:Authorization Schemes]]&lt;br /&gt;
* [[ApEx:Defence in depth]]&lt;br /&gt;
* [[ApEx:Configuration]]&lt;br /&gt;
* [[ApEx:Google dorks]]&lt;br /&gt;
* [[ApEx:Architecture]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
* [1] [http://www.oracle.com/technology/products/database/application_express/html/what_is_apex.html Official Oracle ApEx website]&lt;br /&gt;
&lt;br /&gt;
=== External Resources ===&lt;br /&gt;
&lt;br /&gt;
There have been two books written specifically about Oracle APEX and security, both released in 2013.&lt;br /&gt;
&lt;br /&gt;
[1] [http://www.amazon.com/Application-Express-Security-Experts-ebook/dp/B00ACC6AO6/ Expert Oracle Application Express Security]&amp;lt;br&amp;gt;&lt;br /&gt;
[2] [http://www.amazon.com/Hands-On-Application-Express-Security-ebook/dp/B00CIBNS4E/ Hands-On Oracle Application Express Security: Building Secure Apex Applications]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Oracle Project]]&lt;br /&gt;
[[Category:Development]]&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:James_Vaughan&amp;diff=158268</id>
		<title>User:James Vaughan</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:James_Vaughan&amp;diff=158268"/>
				<updated>2013-09-11T15:19:30Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Company Declaration =&lt;br /&gt;
&lt;br /&gt;
I work at [http://www.recx.co.uk/ Recx] where we do security consulting and some security products. We sell an application security product, ApexSec which is designed to inspect Oracle [[Application_Express_(ApEx)]] applications.&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:James_Vaughan&amp;diff=158267</id>
		<title>User:James Vaughan</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:James_Vaughan&amp;diff=158267"/>
				<updated>2013-09-11T15:18:43Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Company Declaration =&lt;br /&gt;
&lt;br /&gt;
I work at [http://www.recx.co.uk/ Recx] where we do security consulting and some security products. We sell an application security product, ApexSec which is designed to inspect [[Application_Express_(ApEx) Oracle Application Express]] applications.&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:James_Vaughan&amp;diff=158266</id>
		<title>User:James Vaughan</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:James_Vaughan&amp;diff=158266"/>
				<updated>2013-09-11T15:17:29Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Company Declaration =&lt;br /&gt;
&lt;br /&gt;
I work at [http://www.recx.co.uk/ Recx] where we do security consulting and some security products. We sell an application security product, ApexSec which is designed to inspect Oracle Application Express applications.&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:James_Vaughan&amp;diff=158265</id>
		<title>User:James Vaughan</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:James_Vaughan&amp;diff=158265"/>
				<updated>2013-09-11T15:16:00Z</updated>
		
		<summary type="html">&lt;p&gt;James Vaughan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Company Declaration =&lt;/div&gt;</summary>
		<author><name>James Vaughan</name></author>	</entry>

	</feed>