«
Expand/Collapse
436 items tagged "business"
Related tags:
sap [+],
java runtime environment [+],
docsis [+],
comcast [+],
studio business [+],
studio [+],
session management [+],
service vulnerability [+],
pre [+],
forgery [+],
docsis 3 [+],
denial of service [+],
security vulnerability [+],
remote security [+],
vulnerability [+],
srp [+],
small business [+],
small [+],
security [+],
objects [+],
hp business [+],
cisco small [+],
cisco security advisory [+],
cisco security [+],
chaos communication congress [+],
business objects [+],
business cards [+],
business availability [+],
advisory [+],
yahoo [+],
sql injection [+],
source [+],
security bulletin [+],
sap systems [+],
online [+],
level [+],
java web start [+],
directory traversal vulnerability [+],
directory traversal [+],
day [+],
d vulnerability [+],
critical business functions [+],
cisco [+],
business source [+],
business directory [+],
business card designer [+],
bulletin [+],
world [+],
sophos [+],
safer use [+],
forgotten [+],
enterprise business applications [+],
corporate business [+],
business application systems [+],
information disclosure vulnerability [+],
windows [+],
webapps [+],
vulnerabilities [+],
vuln [+],
voice security [+],
use [+],
usa [+],
uk partner [+],
ubiquity [+],
top business [+],
todd feinman [+],
thieves [+],
sponges [+],
smart phones [+],
service [+],
security policies [+],
security 2001 [+],
safeguarding [+],
ruler [+],
rsa [+],
practice [+],
pov [+],
potential security vulnerability [+],
personal laptops [+],
oxcars [+],
north street [+],
new java [+],
netweaver [+],
name [+],
multiple [+],
mariano nunez [+],
malicious intruders [+],
machine [+],
logic products [+],
led [+],
java plug [+],
java db [+],
internet security threats [+],
internet civil society [+],
infoproject [+],
inclusion [+],
hitachi [+],
hero multiple [+],
hero [+],
hacks [+],
government business [+],
government [+],
gala [+],
fortune 100 companies [+],
enterprise resource planning [+],
di croce [+],
david goldman [+],
culture [+],
compton [+],
cnc machine [+],
cnc [+],
chartac [+],
card [+],
business solution [+],
business software alliance [+],
business services [+],
business partners [+],
business logic [+],
business gateway [+],
business edition [+],
business client [+],
business assets [+],
bugtraq [+],
barcelona [+],
backdoors [+],
availability [+],
arbitrary code [+],
anti virus [+],
alliance [+],
acclaim [+],
Software [+],
Hackerspaces [+],
oracle java [+],
java [+],
oracle [+],
cve [+],
code execution [+],
integer overflow vulnerability [+],
ntlm [+],
web business directory,
web,
vp engineering,
voice,
video surveillance cameras,
video,
vice president marketing,
usb,
unit,
uiga,
txt,
traditional infrastructure,
term,
stack buffer,
social networking,
silk screen,
session,
server vulnerability,
scripts,
script sql,
script,
savvy,
sans giac,
rom,
rhce,
portal,
picochip,
php,
networking platform,
network equipment providers,
net,
naming service,
miniweb,
midi stream,
microcontrollers,
listing,
license,
jre,
joomla,
jim machi,
java runtime,
java 2d,
jan linden,
jack of all trades,
infrastructure market,
frank zhao,
feed business,
feed,
doug makishima,
directory,
d2 technologies,
cybercriminals,
custom business card,
custom,
cross site scripting,
communication protocols,
clayton christensen,
classified,
cellular,
card script,
business portal,
business march,
business component,
business card,
buffer overflow vulnerability,
budget,
bpdirectory,
authentication,
General,
Discussion
-
-
21:35
»
SecDocs
Authors:
Ertunga Arsal Tags:
rootkit SAP Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: SAP systems are the heart of many enterprises. Most critical business functions run on SAP Applications and the complexity of these systems makes it very difficult to protect against attackers. Default setups, forgotten/unimplemented security configurations, weak password management and change processes that apply to one ‘unimportant’ system can result in complete compromise of the SAP landscape. The legal consequences, lost/damaged business and reputation can be disastrous depending on the type of the attack. While companies invest a lot to secure SAP systems at business process level for example by designing authorization concepts, implementing separation of duties or by using GRC (Governance Risk and Compliance) tools, the security at technical level mostly lacks attention. In this paper, I present several attack paths exploiting configuration weaknesses at technical level, leading to attack potential to single systems, to whole SAP landscapes, and finally the whole enterprise network. By demonstrating creative exploit variants of configuration weaknesses, I motivate the necessity to safeguard a SAP system at technical level.
-
-
21:27
»
SecDocs
Authors:
Ertunga Arsal Tags:
rootkit SAP Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: SAP systems are the heart of many enterprises. Most critical business functions run on SAP Applications and the complexity of these systems makes it very difficult to protect against attackers. Default setups, forgotten/unimplemented security configurations, weak password management and change processes that apply to one ‘unimportant’ system can result in complete compromise of the SAP landscape. The legal consequences, lost/damaged business and reputation can be disastrous depending on the type of the attack. While companies invest a lot to secure SAP systems at business process level for example by designing authorization concepts, implementing separation of duties or by using GRC (Governance Risk and Compliance) tools, the security at technical level mostly lacks attention. In this paper, I present several attack paths exploiting configuration weaknesses at technical level, leading to attack potential to single systems, to whole SAP landscapes, and finally the whole enterprise network. By demonstrating creative exploit variants of configuration weaknesses, I motivate the necessity to safeguard a SAP system at technical level.
-
21:27
»
SecDocs
Authors:
Ertunga Arsal Tags:
rootkit SAP Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: SAP systems are the heart of many enterprises. Most critical business functions run on SAP Applications and the complexity of these systems makes it very difficult to protect against attackers. Default setups, forgotten/unimplemented security configurations, weak password management and change processes that apply to one ‘unimportant’ system can result in complete compromise of the SAP landscape. The legal consequences, lost/damaged business and reputation can be disastrous depending on the type of the attack. While companies invest a lot to secure SAP systems at business process level for example by designing authorization concepts, implementing separation of duties or by using GRC (Governance Risk and Compliance) tools, the security at technical level mostly lacks attention. In this paper, I present several attack paths exploiting configuration weaknesses at technical level, leading to attack potential to single systems, to whole SAP landscapes, and finally the whole enterprise network. By demonstrating creative exploit variants of configuration weaknesses, I motivate the necessity to safeguard a SAP system at technical level.
-
-
7:29
»
Hack a Day
The guys over at North Street Labs were bored, so they figured why not go ahead and built a CNC machine just for kicks. While they haven’t put up build details on the CNC just yet, they do have some newly milled business cards to show off just how well the machine works. Part ruler, [...]
-
-
21:32
»
SecDocs
Tags:
social Event:
Chaos Communication Congress 28th (28C3) 2011 Abstract: OXcars is fun. oXcars is empowering the people. Presentation and screening of the best of the oXcars 2011, 2010, 2009, 2008. Because their business is not our business. Every year, in Barcelona 1500 people gather for the biggest free/libre culture Show of all times ;-). Artists and performers from all areas of Spanish and international culture take part in a "Gala";-) in which artists say "Not in my name" to the commercialisation of culture, "Not in my name" to limiting the potential of digital media and to criminalization of the Internet. Civil society demands the 'lost profits' of all the knowledge that is being withheld and stolen from public use in the name of private profits.
-
-
21:42
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Small Business (SRP 500) Series Services Ready Platforms contains command injection, unauthenticated configuration upload, and directory traversal vulnerabilities.
-
21:42
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Small Business (SRP 500) Series Services Ready Platforms contains command injection, unauthenticated configuration upload, and directory traversal vulnerabilities.
-
21:42
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco Small Business (SRP 500) Series Services Ready Platforms contains command injection, unauthenticated configuration upload, and directory traversal vulnerabilities.
-
-
0:00
»
SecurityFocus Vulnerabilities
Oracle Java SE and Java for Business 'MixerSequencer' Remote Code Execution Vulnerability
-
-
10:00
»
SecurityFocus Vulnerabilities
[security bulletin] HPSBMU02736 SSRT100699 rev.2 - HP Business Availability Center (BAC) and Business Service Management (BSM), Remote Unauthorized Access to Sensitive Information
-
-
7:00
»
SecurityFocus Vulnerabilities
[security bulletin] HPSBMU02736 SSRT100699 rev.1 - HP Business Availability Center (BAC) and Business Service Management (BSM), Remote Unauthorized Access to Sensitive Information
-
-
1:44
»
Sophos product advisories
If you are using Sophos Small Business Edition with Control Center v 4, you will receive an automatic update to Sophos Anti-Virus v 9.7 in April 2012.
-
5:52
»
SecDocs
Authors:
Mariano Nunez Di Croce Tags:
SAP Event:
Black Hat USA 2010 Abstract: In any company, the ERP (Enterprise Resource Planning) is the heart of the business technological platform. These systems handle the key business processes of the organization, such as procurement, invoicing, human resources management, billing, stock management and financial planning. Among all the ERPs, SAP is by far the most widely deployed one, having more than 90.000 customers in more than 120 countries and running in Fortune 100 companies, governmental and defense organizations. The information stored in these systems is of absolute importance to the company, which unauthorized manipulation would result in big economic losses and loss of reputation. This talk will present an old concept applied to a new paradigm: SAP Backdoors. We will discuss different novel techniques that can be deployed by malicious intruders in order to create and install backdoors in SAP systems, allowing them to retain access or install malicious components that would result in imperceptible-and-ongoing financial frauds. After the description of these techniques, we will present the countermeasures that should be applied in order to avoid these attacks and protect the business information, effectively reducing financial fraud risks and enforcing compliance. Furthermore, we will release a new Onapsis free tool that will help security managers to automatically detect unauthorized modifications to SAP systems. Is your SAP backdoored? If your answer is "I don’t know," you may consider attending to this talk.
-
-
12:39
»
SecuriTeam
Multiple administrative Vulnerabilities were identified in Comcast DOCSIS Business Gateway.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
0:00
»
Sophos security news
Sophos survey highlights worrying lack of security policies regarding use of personal laptops and mobiles for business purposes.
-
-
12:00
»
Hack a Day
Some say that handing out business cards is an antiquated practice due to the ubiquity of smart phones which can be used to trade or record contact information in mere moments. Instructables user [sponges] however, doesn’t agree and is pushing a “business card renaissance” of sorts with his POV business card. Hand-built in his basement, [...]
-
-
17:20
»
SecuriTeam
A potential security vulnerability has been identified with HP Business Availability Center (BAC) and Business Service Management (BSM).
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
9:37
»
Packet Storm Security Recent Files
Whitepaper called Forgotten World - Corporate Business Application Systems. This paper will describe some basic and advanced threats and attacks on Enterprise Business Applications – the core of many companies. Both the paper and Blackhat DC presentation are included in this archive.
-
9:37
»
Packet Storm Security Misc. Files
Whitepaper called Forgotten World - Corporate Business Application Systems. This paper will describe some basic and advanced threats and attacks on Enterprise Business Applications – the core of many companies. Both the paper and Blackhat DC presentation are included in this archive.
-
-
20:15
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of SAP NetWeaver Business Client.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
10:13
»
Packet Storm Security Exploits
Comcast DOCSIS 3.0 Business Gateways suffer from static credential, multiple cross site request forgery, and weak session management vulnerabilities. Versions prior to 1.4.0.49.2 are affected.
-
10:13
»
Packet Storm Security Exploits
Comcast DOCSIS 3.0 Business Gateways suffer from static credential, multiple cross site request forgery, and weak session management vulnerabilities. Versions prior to 1.4.0.49.2 are affected.
-
10:13
»
Packet Storm Security Recent Files
Comcast DOCSIS 3.0 Business Gateways suffer from static credential, multiple cross site request forgery, and weak session management vulnerabilities. Versions prior to 1.4.0.49.2 are affected.
-
10:13
»
Packet Storm Security Recent Files
Comcast DOCSIS 3.0 Business Gateways suffer from static credential, multiple cross site request forgery, and weak session management vulnerabilities. Versions prior to 1.4.0.49.2 are affected.
-
10:13
»
Packet Storm Security Misc. Files
Comcast DOCSIS 3.0 Business Gateways suffer from static credential, multiple cross site request forgery, and weak session management vulnerabilities. Versions prior to 1.4.0.49.2 are affected.
-
10:13
»
Packet Storm Security Misc. Files
Comcast DOCSIS 3.0 Business Gateways suffer from static credential, multiple cross site request forgery, and weak session management vulnerabilities. Versions prior to 1.4.0.49.2 are affected.