My take on this case would be make the listener encrypted through SSL option. Then also you could make your listen to only those connections that arise from certain IPs. as a result you can put in some security on it. Also there owa_util to capture the IP of the connection on your pl/sql procedure and then you can perform a check, and deny access any further. As far as I know in OAS, you have all these features that could be enabled and made use of. Foe webdb, since it again was an incranation of oracle webserver as that of OAS, these features should be there.
Sam
Thanx
Sam
Life is a journey, not a destination!