2009
You are browsing the archive for 2009.
SAP Security Notes – the deadly list
This blog lists some of the most important and highly recommended SAP Security Notes. Please consult with a security expert or a basis specialist before implementing these security notes.
SAP Basis – monitoring os environment
A new user interface for monitoring operating system environment has been introduced by SAP, in my opinion it’s way better than ST06 or OS07
Swish Max3 – Favorite Blogs and Forum posts
Wow, another fantastic year is about to over and it’s the festive season again. I’d like to take this opportunity to wish everyone a very happy holiday and a good 2010. This blog post is dedicated to my favorite flash authoring application Swish Max3 and miniMax3. If you are looking for some great templates and [...]
Vulnerabilities & Recommendations – Firefox 3.0 and Xulrunner 1.9
If you have firefox and xulrunner installed on Linux ubuntu, now is the time to update the packages. Checkout the insights on the vulnerability and recommendations to patch your system.
SAP Portal Security Guidelines
Given are a few guidelines for an effective SAP Portal implementation. Stay tuned for the amudee.com security series, a lot more to come..
HTTPOnly Flag In Cookie Not Set
During an SAP Portal Security review, I came across a scenario where HTTPOnly flag in session cookie was not set. Please checkout the recommendation given in this short blog.
SAP Enterprise Portal Security
In my earlier blog, I had promised to cover some of the most critical security issues that you may face sooner or later. So here are some pointers for you to re-evaluate your SAP Portal implementation and fix the significant issues before someone else breaks-in. Here is a POC with some snapshots.
A simple hack to take a snapshot from windows media player
This blog illustrates a very simple hack to grab a snapshot from windows media player. No additional software is required, all you need is to follow the given instructions.
Forensic SAP Security
In this series of blogs, I will be focusing more on the core SAP security, Portal, Netweaver and some other topics like XSS, So keep watching the space.
Security Alert: Fake twitter website
I recently came across a forged twitter website which is currently active and may cause severe damage to your online identity and privacy. This kind of attack is conducted for the purposes of information or identity theft.



Recent Comments