• Home
  • GRC Lists
  • GRC Vendors
  • Archives
  • About
  • Sitemap

amuDee.com

Grilling into Compliance Regulations, Risk Management, Internal Controls, Information Security, News and Media

  • GRC & Security
    • Access Controls
    • Compliance regulations
    • Enterprise Risk Management
    • Network System Security
      • Twitter Security
      • Vulnerabilities
    • SAP Security
      • SAP Basis
    • Troubleshooting GRC
  • Guest Lounge
    • Gadgets & Technology
      • Technology Sneak Peaks
      • Tips & Tricks
  • My Epitomization
    • Twitter Digest
  • News & Media
    • Avarice News Makers
  • Subscribe
Password Input field, the biggest Security failure

Password Input field, the biggest Security failure

By Amol Bharti on June 4, 2010

Umbrellas have been around for thousands of years, So why is it so hard to find a decent one that doesn’t flip inside-out, if a big wind comes along. Well, WSJ is full of such stories lately and the new Umbrella designs are making some big news.

Full Story »

Posted in Network System Security | Tagged biggest failure, century's failure, copy, ctrl+c, ctrl+v, disable copy and paste, disable password copying, failure, flipped umbrella, forensics, hacked, hacking, input field validation, password, password validation, paste, SAP Security, security design failure, social networks, technology failure | 6 Responses

Previous Pause Next
Flawed McAfee Signature caused False Positive

Flawed McAfee Signature caused False Positive

By Amol Bharti on April 23, 2010

The Anti Virus programs are supposed to protect you, but that’s not what happened to countless Windows users on Wednesday. McAfee added detection for variants of the W32/Wecorl.a family of Malware to DAT file 5958 on 21st April 2010. This detection caused a false positive that flagged the svchost.exe Windows system file as malicious.

Posted in Avarice News Makers, Network System Security | Tagged 21st april failures, antivirus failure, caused False Positive, dat file 5958, family of malware, Flawed, McAfee, Signature, w32/Wecorl.a

Phishing attacks on INDIA’s Income Tax Department

Phishing attacks on INDIA’s Income Tax Department

By Amol Bharti on March 17, 2010

India has a tax paying population of 31.5 million and the number is supposed to increase significantly in the coming years. Looking at the number, there is no doubt about the similar phishing attacks happening in future and that’s obvious. All we need is Security awareness about the online scams and attention to our online identities.

Posted in Avarice News Makers, News & Media | Tagged attack, cyber crime, identity protection law india, income tax department, india, online phishing scam, phishing, scam revealed | Leave a response

Jim Hagemann Snabe

Response to Bill and Jim’s Open letter

By Amol Bharti on March 14, 2010

Amol Bharti’s response to a blog post “Open letter to SAP Customers from SAP’s Co-CEOS Jim Hagemann Snabe and Bill McDermott”

Posted in My Epitomization | Tagged Bill McDermott, comments, feedback, Jim Hagemann Snabe, response, response to bill and jim, sap open letter, social media | Leave a response

Ubuntu 9.10 gnome-Screensaver vulnerability

Ubuntu 9.10 gnome-Screensaver vulnerability

By Amol Bharti on February 10, 2010

Can a screensaver be exploited to gain access on your linux gnome? Strangely Yes. This vulnerability applies to Ubuntu 9.10 and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

Posted in Vulnerabilities | Tagged access control measures, crashing, gain access, screensaver exploit, ubuntu 9.10, unauthorized access, upgrade linux gnome, upgrade ubuntu, vulnerabilities | Leave a response

How SAP R/3 security is different from SAP BW and EP

How SAP R/3 security is different from SAP BW and EP

By Amol Bharti on January 25, 2010

This short blog gives an overview on how Security in SAP BW, Enterprise Portal and SAP HR is different from SAP R/3 Security.

Posted in SAP Security | Tagged difference, Enterprise Portal Security, EP, how R/3 differs from SAP BW, HR, R/3 security is different, SAP BW Security | 3 Responses

Bug in Spool request affecting all SAP releases

Bug in Spool request affecting all SAP releases

By Amol Bharti on January 21, 2010

All spool requests created after 2009/12/23 with deletion date exceeding 2010/01/01 are wrongly Y2K’ed as 2099/12/31 or 2100/01/01 regardless of their retention period specified during creation. These spool requests will not be deleted if the spool reorg job RSPO0041 or RSPO1041 is executed with a variant that selects requests according to their deletion data, and [...]

Posted in SAP Security | Tagged 2100/01/01, Deletion date, expiry date, SP01, spool full, spool overflow

PortQry.exe a better alternative to Ping, Telnet, tracert

PortQry.exe a better alternative to Ping, Telnet, tracert

By Amol Bharti on January 4, 2010

PortQry is a TCP/IP connectivity testing and troubleshooting utility that is included with the Microsoft Windows Server 2003 Support Tools. This utility reports the port status of target TCP and User Datagram Protocol (UDP) ports on a local computer or on a remote computer.

Posted in Network System Security | Tagged Acceleration Server troubleshooting, alternative to Ping, DNS, Domain Name System, Internet Security, ISA, ldap, Lightweight Directory Access Protocol, NetBIOS Name Service, portqry, PortQry troubleshooting, PortQry.exe, protocols, Remote Procedure Calls, RPC, SNMP, Telnet, tracert, Troubleshooting GRC | Leave a response

SAP Security Notes – the deadly list

SAP Security Notes – the deadly list

By Amol Bharti on December 31, 2009

This blog lists some of the most important and highly recommended SAP Security Notes. Please consult with a security expert or a basis specialist before implementing these security notes.

Posted in SAP Security | Tagged abap, blind sql, Cross Site Scripting, forensic security, missing authorizations, Netweaver, obsolete code, portal security, r/3, SAP Security, SQLi, xss | 2 Responses

SAP Basis – monitoring os environment

SAP Basis – monitoring os environment

By Amol Bharti on December 19, 2009

A new user interface for monitoring operating system environment has been introduced by SAP, in my opinion it’s way better than ST06 or OS07

Posted in SAP Basis | Tagged best practices, new applications, SAP Basis, sap basis tutorial, short blog, tips, tricks | Leave a response

Swish Max3 – Favorite Blogs and Forum posts

Swish Max3 – Favorite Blogs and Forum posts

By Amol Bharti on December 11, 2009

Wow, another fantastic year is about to over and it’s the festive season again. I’d like to take this opportunity to wish everyone a very happy holiday and a good 2010. This blog post is dedicated to my favorite flash authoring application Swish Max3 and miniMax3. If you are looking for some great templates and [...]

Posted in My Epitomization | Tagged 2010, favorite blogs, forum posts, Happy New Year, Swish Max3, Swish MiniMax3, swishzone, tutorials, X-mas 2009

Vulnerabilities & Recommendations – Firefox 3.0 and Xulrunner 1.9

Vulnerabilities & Recommendations – Firefox 3.0 and Xulrunner 1.9

By Amol Bharti on December 10, 2009

If you have firefox and xulrunner installed on Linux ubuntu, now is the time to update the packages. Checkout the insights on the vulnerability and recommendations to patch your system.

Posted in Vulnerabilities | Tagged advisories, browser engine bug, firefox, firefox flaws and security breach, linux flaws, recommendations, security advisory, security vulnerability, ubuntu, vulnerabilities | Leave a response

SAP Portal Security Guidelines

SAP Portal Security Guidelines

By Amol Bharti on November 27, 2009

Given are a few guidelines for an effective SAP Portal implementation. Stay tuned for the amudee.com security series, a lot more to come..

Posted in SAP Security | Tagged 0 day exploit, codergeek82, Collaboration Security, exploiting SAP Portal with Google hacking., GRC Security, Hacking SAP Portal, Knoweledge Management, Portal vulnerability, SAP Enterprise Portal Security, SAP Portal Security Guidelines, Secure your SAP Portal, zero day | 1 Response

‘HTTPOnly’ Flag In Cookie Not Set – SAP Portal

‘HTTPOnly’ Flag In Cookie Not Set – SAP Portal

By Amol Bharti on November 27, 2009

During an SAP Portal Security review, I came across a scenario where HTTPOnly flag in session cookie was not set. Please checkout the recommendation given in this short blog.

Posted in SAP Security | Tagged ethical hacker india, httponly flag in cookie not set, recommendations, sap hacker, sap portal security, SAP Security | Leave a response

SAP Enterprise Portal Security

SAP Enterprise Portal Security

By Amol Bharti on November 26, 2009

In my earlier blog, I had promised to cover some of the most critical security issues that you may face sooner or later. So here are some pointers for you to re-evaluate your SAP Portal implementation and fix the significant issues before someone else breaks-in. Here is a POC with some snapshots.

Posted in SAP Security | Tagged 0 day exploit, codergeek82, Collaboration Security, exploiting SAP Portal with Google hacking., GRC Security, Hacking SAP Portal, Knoweledge Management, Portal vulnerability, SAP Enterprise Portal Security, Secure your SAP Portal, zero day | Leave a response

Forensic SAP Security

Forensic SAP Security

By Amol Bharti on November 26, 2009

In this series of blogs, I will be focusing more on the core SAP security, Portal, Netweaver and some other topics like XSS, So keep watching the space.

Posted in SAP Security | Tagged 0day exploits, back door access, CA, ethical hacker india, forensic, hacking sap, NASA vulnerabilities reported, sap, sap portal vulnerabilities, SAP Security, white hat hackers, zero day | 1 Response

Security Alert: Fake twitter website

Security Alert: Fake twitter website

By Amol Bharti on November 11, 2009

I recently came across a forged twitter website which is currently active and may cause severe damage to your online identity and privacy. This kind of attack is conducted for the purposes of information or identity theft.

Posted in Network System Security, SAP Security, Twitter Security | Tagged alert, amol bharti indian ethical hacker, amudee, Fake twitter website, hacker, hacking, http://videos.blogs.dsfasdc.com, sap hacker, spoofy twitter, twitter phishing, twitter security | 3 Responses

Access Controls

  • Cross-Platform Access Controls
  • Handling emergency with SAP BusinessObjects Superuser Privilege Management

Compliance regulations

  • Handling SOX compliance requirements in non-US (esp. Canadian) companies
  • Impact of SOX on non American companies

Network System Security

  • Sender Policy Framework – SPF Record
  • Are you Zombie ? If you use cracked softwares, You may be on target !

News & Media

  • Syntel Joins SAP PartnerEdge Program as an SAP Services Partner in India
  • Obama’s cyber security policy – Review by Melissa Hathaway
  • Twitter
  • Top Blogs
  • Comments
  • SAP SDN
  • Featured Blog

Twitter Updates

  • Comment on Password Input field, the biggest Security failure by Anshul: Awesome article ...and a nice piece of im... http://bit.ly/b6cD71 2 hrs ago
  • Comment on Password Input field, the biggest Security failure by andy waroma: seriously i never thought about it t... http://bit.ly/bYPUuo 4 hrs ago
  • More updates...

Posting tweet...

Hottest Blogs

  • Vista's Security Rendered Completely Useless by New Exploit
  • (9999)
  • You can post your precious e-blessings here!!
  • (2231)
  • Dollar-Rupee relationship amidst current financial slowdown
  • (2079)
  • GetyTV YouTube Downloader for Windows Mobile Pocket PC - Freeware
  • (1659)
  • SAP Security Notes - the deadly list
  • (1447)

Recent Comments

  • Anshul on Password Input field, the biggest Security failure
  • Jagdip on Password Input field, the biggest Security failure
  • andy waroma on Password Input field, the biggest Security failure
  • Amol Bharti on GRC Vendors
  • Amol Bharti on GRC Vendors

RSS SAP SDN Contributions

  • Re: Hr Object analysis in RAR 5.3 - by Amol Bharti
  • Re: Activating BC Sets while upgrading the system to latest version - by Amol Bharti
  • Re: Role of a Security Consultant in an SAP implementation Project - by Amol Bharti
  • Re: SAP GRC Access Control 5.3 intergration with orcale - by Amol Bharti
  • Re: risk terminator configuration and problem with functionality - by Amol Bharti

Featured Blog

Sponsors

Categories

  • Access Controls
  • Avarice News Makers
  • Compliance regulations
  • Enterprise Risk Management
  • Gadgets & Technology
  • GRC & Security
  • Guest Lounge
  • My Epitomization
  • Network System Security
  • News & Media
  • SAP Basis
  • SAP Security
  • Technology Sneak Peaks
  • Tips & Tricks
  • Troubleshooting GRC
  • Twitter Digest
  • Twitter Security
  • Vulnerabilities

Exclusive Blogs

  • Handling emergency with SAP BusinessObjects Superuser Privilege Management

  • Vista’s Security Rendered Completely Useless by New Exploit

  • PortQry.exe a better alternative to Ping, Telnet, tracert

  • SAP Portal Security Guidelines

  • SAP Enterprise Portal Security

  • ‘HTTPOnly’ Flag In Cookie Not Set – SAP Portal

  • Security Alert: Fake twitter website

  • Sender Policy Framework - SPF Record

  • Want to become a SAP Security consultant?

  • Basel II’s Three Approaches to Operational Risk Management

  • Handling SOX compliance requirements in non-US (esp. Canadian) companies

  • Section 302 – Disclosure and Section 404 – Internal Controls

  • Sarbanes Oxley Act of 2002

  • Operational Risk Management Awareness

  • Ten Key Technologies For Lean Process Improvement

  • The Weakest Link In Your Information Security Chain

  • Key Triggers for future Indian IT industry and Outsourcing

  • Network Utilities – Freeware

  • How to analyze passwords of all important users across SAP clients

  • What to do before your website gets Hacked

  • Understand Vandalism and Hacking – Open source CMS

  • The Dark side of IT

  • Role of a Security Consultant in an SAP implementation Project

  • 10 things you need to know to become an SAP Security Forensic Consultant

  • Important SAP Security Parameters

  • SAP default users and passwords

  • If you have lost SAP* password how would you recover
Kaspersky Internet Security 2011
DreamTemplate - Web Templates

amudee.com is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 2.5 India License | Privacy Policy | Disclaimer SAP®, Oracle®, Syntel®, Microsoft® are registered trademarks of the respective companies and affiliates in the U.S, Germany and other countries. All other trademarks mentioned on this blog or any document on the website are the property of their respective owners. Powered by WordPress