Thanks for the comments...

I know you can use parameterized sql in sql server 2000 to avoid sql injection...

but does oracle has parameterized sql?

the package procedure == stored procedures in sql server 2000?

Hmm... any more comments...

How about other security threats in oracle.. as sql server 2000 has sql slammer... etc!

Regards,
Chua Wen Ching