[ERPSCAN-16-033] SAP NetWeaver AS JAVA icman – DoS vulnerability

Posted by ERPScan inc on Nov 22

Application: SAP NetWeaver AS JAVA

Versions Affected: SAP NetWeaver AS JAVA 7.4

Vendor URL: http://SAP.com

Bug: Denial of Service

Sent: 22.04.2016

Reported: 23.04.2016

Vendor response: 23.04.2016

Date of Public Advisory: 09.08.2016

Reference: SAP Security Note 2313835

Author: Vahagn Vardanyan (ERPScan)

Description

1. ADVISORY INFORMATION

Title: [ERPSCAN-16-033] SAP NetWeaver AS JAVA icman – DoS vulnerability

Advisory…

Reflected XSS in WonderCMS <= v0.9.8

Posted by Manuel Garcia Cardenas on Nov 22

=============================================
MGC ALERT 2016-006
– Original release date: Nov 16, 2016
– Last revised: Nov 21, 2016
– Discovered by: Manuel Garcia Cardenas
– Severity: 4,8/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
————————-
Reflected XSS in WonderCMS <= v0.9.8

II. BACKGROUND
————————-
WonderCMS is a simple, small & secure flat file CMS.

III….

Hackers Steal Millions From European ATMs Using Malware That Spit Out Cash

ATM hackers who long relied on tactics of stealing payment card numbers and online banking credentials to steal millions are now targeting the bank itself to steal cash directly from the machines.

Earlier this year, a gang of cyber criminals infected several ATMs with malware in Taiwan and Thailand that caused the machines to spit out millions in cash, and the gang members then stood in front

Oracle acquires DNS provider Dyn for more than $600 Million

Yes, Oracle just bought the DNS provider company that brought down the Internet last month.

Business software vendor Oracle announced on Monday that it is buying cloud-based Internet performance and Domain Name System (DNS) provider Dyn.

Dyn is the same company that was hit by a massive distributed denial of service (DDoS) attack by the Mirai botnet last month which knocked the entire

data services

Dear Sir/Madam, 


We wish to introduce our company to you; Data Service, in London Uk.

We are a consulting Firm to HSBC,in Spain. We are conducting a standard
process verification involving a client who shares the same name with you
in an investments made at HSBC, Spain. The HSBC,Private Banking client 
died intestate and did not nominate a heir to her investments.

Sequel to the above, We are requesting that you confirm the following below
and your full names;

(i). Are you aware of any relative/relation having the same surname,Whose
last known contact address was Madrid,Spain? 

(ii). Are you aware of any investment of considerable value made by such a 
person at the HSBC,?

(iii). If the above is correct, Can you assume the status of the heir to the
deceased At this point.? 

You must appreciate that we are constrained from providing you with more 
detailed information.

All correspondence should please be directed to this email address ([email protected])


Thanks for the anticipated response to this inquiry.



Yours sincerely,
Mrs.Marie Benes,
[email protected]
Data Service Ltd



This is a confidential message from Data services Ltd