Howdy, I've written a white-paper, "Hackproofing Oracle Application Server." It covers vulnerable areas and what must done to secure the box. Anyone interested may get a copy from http://www.nextgenss.com/papers/hpoas.pdf . Cheers, David Litchfield http://www.nextgenss.com/