Recent post to the [SC-L] List:

FYI, Stephen Kost of Integrigy Corporation has published a paper called, "An Introduction To SQL Injection Attacks For Oracle Developers".  The full 24 page paper (in PDF format) is freely available at:

 http://www.net-security.org/dl/articles/IntegrigyIntrotoSQLInjectionAttacks.pdf

On first glance, it appears to me to be a pretty worthwhile read, FWIW. Although it is aimed at Oracle developers and much of the paper is indeed Oracle-specific, pretty much anyone writing multi-tier SQL database software could find useful information in it.

[Now Playing: Pyar Aaya - Plan]