<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GeeKs Blogging @ dotCOM &#187; Security</title>
	<atom:link href="http://geeksbloggingat.com/topics/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://geeksbloggingat.com</link>
	<description>Let&#039;s share...</description>
	<lastBuildDate>Tue, 30 Aug 2011 21:29:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Siebel : Security Vulnerability !</title>
		<link>http://geeksbloggingat.com/2010/03/08/siebel-security-vulnerability-found/</link>
		<comments>http://geeksbloggingat.com/2010/03/08/siebel-security-vulnerability-found/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 20:17:46 +0000</pubDate>
		<dc:creator>Nitin Jain</dc:creator>
				<category><![CDATA[Siebel CRM]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Siebel]]></category>

		<guid isPermaLink="false">http://geeksbloggingat.com/?p=928</guid>
		<description><![CDATA[This post could have far-reaching implications. I am still at crossroads whether I should be covering this or not.. The baseline is that there has been a Security Vulnerability detected, and announced. It is said to have been detected nearly a year ago, and informed to the Parent Organization. However, despite a year passing by, [...]


<b>Related posts:<b><ol><li><a href='http://geeksbloggingat.com/2010/03/20/siebelsis-om-pmt-service/' rel='bookmark' title='Permanent Link: Siebel &#8211; SIS OM PMT Service'>Siebel &#8211; SIS OM PMT Service</a> <small>There are lots of vanilla business services available in Siebel...</small></li>
<li><a href='http://geeksbloggingat.com/2009/06/15/siebel-forcing-user-logoff/' rel='bookmark' title='Permanent Link: Siebel &#8211; Forcing User Logoff'>Siebel &#8211; Forcing User Logoff</a> <small>Hi all, Somebody recently asked me if there is a...</small></li>
<li><a href='http://geeksbloggingat.com/2009/04/17/siebel-lookupname-and-lookupvalue/' rel='bookmark' title='Permanent Link: Siebel &#8211; LookUpName() and LookUpValue()'>Siebel &#8211; LookUpName() and LookUpValue()</a> <small>Hi all, I was working for a multi lingual implementation...</small></li>
<li><a href='http://geeksbloggingat.com/2009/04/24/html-code-in-error-message/' rel='bookmark' title='Permanent Link: Siebel &#8211; HTML Code displayed in Error Message'>Siebel &#8211; HTML Code displayed in Error Message</a> <small>There was a requirement in our project to make Account...</small></li>
<li><a href='http://geeksbloggingat.com/2010/04/04/siebel-upgrade-process-part-i/' rel='bookmark' title='Permanent Link: Siebel &#8211; Upgrade Process &#8211; Part I'>Siebel &#8211; Upgrade Process &#8211; Part I</a> <small>If you have reached here, I assume you have already...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>This post could have far-reaching implications. I am still at crossroads whether I should be covering this or not..</p>
<p>The baseline is that there has been a Security Vulnerability detected, and announced. It is said to have been detected nearly a year ago, and informed to the Parent Organization. However, despite a year passing by, we are not aware of any remedial action having been taken by the Corporation. Since the vulnerability has already been publicly announced over the internet, we feel it&#8217;s safe to cover it here as well. We feel morally responsible to apprise <a rel="nofollow" href="http://oracle.com" target="_blank">Oracle Corp</a> of the issue by building sufficient public opinion to patch it..</p>
<p><span id="more-928"></span>This Security Vulnerability has been detected in some of the older versions of Oracle&#8217;s very popular Siebel CRM Softwa=re, aka versions 7.7 and 7.8. It has not been tested on the older versions, but, expectedly it would appear there as well.</p>
<p>This Security Loophole has been detected by &#8220;Yaniv Miron&#8221;, a Security Researcher from Israel. <a rel="nofollow" href="http://il.linkedin.com/in/yanivmiron" target="_blank">Click here</a> to reach his LinkedIn profile directly.</p>
<p>The vulnerability comes by the name of, <strong>&#8220;Oracle Siebel CRM &#8216;start.swe&#8217; Cross Site Scripting Vulnerability&#8221;</strong>.</p>
<p>It is rated &#8220;Low Risk&#8221;, and is Remotely Exploitable.</p>
<p>The following is directly from <a rel="nofollow" href="http://www.vupen.com" target="_blank">VUPEN</a> :<br />
<i>&#8221; ..This vulnerability could be exploited by attackers to execute arbitrary scripting code. This issue is caused by an input validation error in the &#8220;htim_enu/start.swe&#8221; script when processing user-supplied data, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user&#8217;s browser in the security context of an affected site.. &#8220;</i></p>
<p><a href="http://secunia.com/advisories/38806" target="_blank" rel="nofollow">SECUNIA</a> says..<br />
<i>&#8221; ..Input passed via the URL to htim_enu/start.swe is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user&#8217;s browser session in context of an affected site.. &#8220;</i></p>
<p>A simple example could be:</p>
<pre style="word-wrap: break-word; white-space: pre-wrap;">http://example.com/htim_enu/start.swe/?&gt;'"&gt;&lt;script&gt;alert('XSS by Lament')&lt;/script&gt;</pre>
<p>Jan 2009 &#8211; Vulnerability found<br />
Jan 2009 &#8211; Vendor Notification<br />
Feb 2010 &#8211; Public Disclosure</p>
<p>Complete details about the vulnerability can be found at the following URLs where it was first reported:</p>
<p>http://www.vupen.com/english/advisories/2010/0516</p>
<p>http://seclists.org/bugtraq/2010/Mar/6</p>
<p>The original Advisories may be downloaded from the links below:<br />
<a href="http://www.packetstormsecurity.com/1002-exploits/oraclesiebel-xss.txt" target="_blank" rel="nofollow">Siebel Loyalty Advisory</a><br />
<a href="http://www.packetstormsecurity.com/1003-exploits/oraclesiebelcrm-xss.txt target="_blank" rel="nofollow">Siebel CRM Advisory</a></p>
<p>The vulnerability is already popular over Twitter.. try the link below..<br />
<a href="http://tweetmeme.com/story/652872374/bugtraq-oracle-siebel-7x-crm-cross-site-scripting-vulnerability" target="_blank" rel="nofollow">Twitter Links for Siebel Advisory</a></p>
<p>Could there be better reasons to Upgrade to the latest Siebel versions, 8.x ?<br />
Considering Siebel CRM is an expensive product targetted only at the companies with $250K+ revenues, this is all the more important.</p>
<p>Note: This post is for informational purposes only.<br />
The author of this document is not and will not hold any responsibility for any illegal or unauthorized use of the information contained within this document, or that is implied from it.<br />
The author of this document does not encourage in any way whatsoever, attacking any Siebel based System.</p>


<p><b>Related posts:<b><ol><li><a href='http://geeksbloggingat.com/2010/03/20/siebelsis-om-pmt-service/' rel='bookmark' title='Permanent Link: Siebel &#8211; SIS OM PMT Service'>Siebel &#8211; SIS OM PMT Service</a> <small>There are lots of vanilla business services available in Siebel...</small></li>
<li><a href='http://geeksbloggingat.com/2009/06/15/siebel-forcing-user-logoff/' rel='bookmark' title='Permanent Link: Siebel &#8211; Forcing User Logoff'>Siebel &#8211; Forcing User Logoff</a> <small>Hi all, Somebody recently asked me if there is a...</small></li>
<li><a href='http://geeksbloggingat.com/2009/04/17/siebel-lookupname-and-lookupvalue/' rel='bookmark' title='Permanent Link: Siebel &#8211; LookUpName() and LookUpValue()'>Siebel &#8211; LookUpName() and LookUpValue()</a> <small>Hi all, I was working for a multi lingual implementation...</small></li>
<li><a href='http://geeksbloggingat.com/2009/04/24/html-code-in-error-message/' rel='bookmark' title='Permanent Link: Siebel &#8211; HTML Code displayed in Error Message'>Siebel &#8211; HTML Code displayed in Error Message</a> <small>There was a requirement in our project to make Account...</small></li>
<li><a href='http://geeksbloggingat.com/2010/04/04/siebel-upgrade-process-part-i/' rel='bookmark' title='Permanent Link: Siebel &#8211; Upgrade Process &#8211; Part I'>Siebel &#8211; Upgrade Process &#8211; Part I</a> <small>If you have reached here, I assume you have already...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://geeksbloggingat.com/2010/03/08/siebel-security-vulnerability-found/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Siebel &#8211; Remove About SRF Window</title>
		<link>http://geeksbloggingat.com/2009/05/20/siebel-remove-about-srf-window/</link>
		<comments>http://geeksbloggingat.com/2009/05/20/siebel-remove-about-srf-window/#comments</comments>
		<pubDate>Wed, 20 May 2009 05:35:49 +0000</pubDate>
		<dc:creator>Nitin Jain</dc:creator>
				<category><![CDATA[Siebel CRM]]></category>
		<category><![CDATA[Admin]]></category>
		<category><![CDATA[Applet]]></category>
		<category><![CDATA[Client]]></category>
		<category><![CDATA[Configuration]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Siebel]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Tricks]]></category>

		<guid isPermaLink="false">http://geeksbloggingat.com/?p=315</guid>
		<description><![CDATA[In my previous post, I had discussed as to how we can control how we can control the data being displayed in the Siebel Client, About SRF window. You can read the article here. One impromptu question came up from the audience, &#8220;What if I want to limit opening of the About SRF window itself [...]


<b>Related posts:<b><ol><li><a href='http://geeksbloggingat.com/2009/05/19/siebel-about-srf-window-remove-data/' rel='bookmark' title='Permanent Link: Siebel &#8211; About SRF Window &#8211; Remove data'>Siebel &#8211; About SRF Window &#8211; Remove data</a> <small>Okay. This is something those who like to toy with...</small></li>
<li><a href='http://geeksbloggingat.com/2009/05/22/siebel-close-browser-window-when-logging-off/' rel='bookmark' title='Permanent Link: Siebel- Close Browser window when logging off'>Siebel- Close Browser window when logging off</a> <small>In case of standard interactivity applications like eSales , eService,...</small></li>
<li><a href='http://geeksbloggingat.com/2009/06/25/siebel-popup-update-only/' rel='bookmark' title='Permanent Link: Siebel &#8211; Popup Update Only'>Siebel &#8211; Popup Update Only</a> <small>Hi all, I was working with Siebel Multi Valued Links...</small></li>
<li><a href='http://geeksbloggingat.com/2009/05/18/siebel-changing-textbox-height/' rel='bookmark' title='Permanent Link: Siebel &#8211; changing Textbox height'>Siebel &#8211; changing Textbox height</a> <small>There are a number of HTML controls available in Siebel....</small></li>
<li><a href='http://geeksbloggingat.com/2009/08/17/siebel-run-case-insensitive-queries/' rel='bookmark' title='Permanent Link: Siebel &#8211; Run Case Insensitive queries'>Siebel &#8211; Run Case Insensitive queries</a> <small>This is a nice tip I ran across. All the...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>In my previous post, I had discussed as to how we can control how we can control the data being displayed in the Siebel Client, About SRF window. You can read the article <a href="http://geeksbloggingat.com/siebel-about-srf-window-remove-data/" target="_blank">here</a>.</p>
<p>One impromptu question came up from the audience, &#8220;What if I want to limit opening of the About SRF window itself in the first place?&#8221;. I said, &#8220;Nice question!&#8221;.</p>
<p>Try out the following steps to disable the About SRF window itself from Siebel Web Client.</p>
<p><span id="more-315"></span>Log into Siebel Tools.<br />
Navigate to &#8216;Application&#8217; in the Object Explorer. In may case, &#8220;Siebel Automotive&#8221;.<br />
Notice that the Menu property corresponding to this Application reads, &#8220;Generic WEB&#8221;.<br />
Navigate to &#8216;Menu&#8217; in the Object Explorer in Siebel Tools.<br />
In the &#8216;Menu Item&#8217; below the &#8216;Menu&#8217; in OE, search for the record name as &#8220;Help &#8211; About SRF&#8221;, or the Caption as &#8220;About SRF&#8230;&#8221;.<br />
Set the corresponding property, &#8216;Inactive&#8217; to TRUE.<br />
Compile into Siebel SRF and Go!</p>
<p>You should no longer see the &#8216;About SRF&#8217; option in the &#8216;Help&#8217; menu.</p>
<p>Just as I said with my previous post on hiding data from the About SRF Applet, you can play around with similar other entities as well. Let me know if this helped you. Cheers!</p>


<p><b>Related posts:<b><ol><li><a href='http://geeksbloggingat.com/2009/05/19/siebel-about-srf-window-remove-data/' rel='bookmark' title='Permanent Link: Siebel &#8211; About SRF Window &#8211; Remove data'>Siebel &#8211; About SRF Window &#8211; Remove data</a> <small>Okay. This is something those who like to toy with...</small></li>
<li><a href='http://geeksbloggingat.com/2009/05/22/siebel-close-browser-window-when-logging-off/' rel='bookmark' title='Permanent Link: Siebel- Close Browser window when logging off'>Siebel- Close Browser window when logging off</a> <small>In case of standard interactivity applications like eSales , eService,...</small></li>
<li><a href='http://geeksbloggingat.com/2009/06/25/siebel-popup-update-only/' rel='bookmark' title='Permanent Link: Siebel &#8211; Popup Update Only'>Siebel &#8211; Popup Update Only</a> <small>Hi all, I was working with Siebel Multi Valued Links...</small></li>
<li><a href='http://geeksbloggingat.com/2009/05/18/siebel-changing-textbox-height/' rel='bookmark' title='Permanent Link: Siebel &#8211; changing Textbox height'>Siebel &#8211; changing Textbox height</a> <small>There are a number of HTML controls available in Siebel....</small></li>
<li><a href='http://geeksbloggingat.com/2009/08/17/siebel-run-case-insensitive-queries/' rel='bookmark' title='Permanent Link: Siebel &#8211; Run Case Insensitive queries'>Siebel &#8211; Run Case Insensitive queries</a> <small>This is a nice tip I ran across. All the...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://geeksbloggingat.com/2009/05/20/siebel-remove-about-srf-window/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Siebel &#8211; About SRF Window &#8211; Remove data</title>
		<link>http://geeksbloggingat.com/2009/05/19/siebel-about-srf-window-remove-data/</link>
		<comments>http://geeksbloggingat.com/2009/05/19/siebel-about-srf-window-remove-data/#comments</comments>
		<pubDate>Tue, 19 May 2009 06:07:58 +0000</pubDate>
		<dc:creator>Nitin Jain</dc:creator>
				<category><![CDATA[Siebel CRM]]></category>
		<category><![CDATA[Applet]]></category>
		<category><![CDATA[Client]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Siebel]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Tricks]]></category>

		<guid isPermaLink="false">http://geeksbloggingat.com/?p=306</guid>
		<description><![CDATA[Okay. This is something those who like to toy with Siebel may find interesting. I will discuss today, how we can play with the Siebel &#8216;About SRF&#8217; window when you go Help -> About SRF in Siebel Client Application. I guess almost all the Siebel users would have seen or used the Siebel &#8216;About SRF&#8217; [...]


<b>Related posts:<b><ol><li><a href='http://geeksbloggingat.com/2009/05/20/siebel-remove-about-srf-window/' rel='bookmark' title='Permanent Link: Siebel &#8211; Remove About SRF Window'>Siebel &#8211; Remove About SRF Window</a> <small>In my previous post, I had discussed as to how...</small></li>
<li><a href='http://geeksbloggingat.com/2009/05/22/siebel-close-browser-window-when-logging-off/' rel='bookmark' title='Permanent Link: Siebel- Close Browser window when logging off'>Siebel- Close Browser window when logging off</a> <small>In case of standard interactivity applications like eSales , eService,...</small></li>
<li><a href='http://geeksbloggingat.com/2009/07/27/siebel-autosave-opportunity-the-concept/' rel='bookmark' title='Permanent Link: Siebel &#8211; Autosave Opportunity data &#8211; The concept'>Siebel &#8211; Autosave Opportunity data &#8211; The concept</a> <small>Requirement: System should have capability to automatically save opportunity(RFPs) data...</small></li>
<li><a href='http://geeksbloggingat.com/2009/07/28/siebel-autosave-opportunity-data-sample-code/' rel='bookmark' title='Permanent Link: Siebel &#8211; Autosave Opportunity data &#8211; Sample Code'>Siebel &#8211; Autosave Opportunity data &#8211; Sample Code</a> <small>This is a follow up post on my previous post,...</small></li>
<li><a href='http://geeksbloggingat.com/2009/05/10/siebel-reading-data-directly-from-siebel-srf/' rel='bookmark' title='Permanent Link: Siebel &#8211; Reading data directly from Siebel SRF'>Siebel &#8211; Reading data directly from Siebel SRF</a> <small>SRF or the Siebel Repository File as it is more...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Okay. This is something those who like to toy with Siebel may find interesting. I will discuss today, how we can play with the Siebel &#8216;About SRF&#8217; window when you go Help -> About SRF in Siebel Client Application.</p>
<p>I guess almost all the Siebel users would have seen or used the Siebel &#8216;About SRF&#8217; window to know about the latest SRF that has been compiled, or other technical information for the application that they just logged into.</p>
<p><span id="more-306"></span>However, for a lot of reasons you may want to disable this Siebel feature:<br />
1) Security Reasons<br />
2) Making data available on a Need to Know basis<br />
3) Making available custom information than that in the About SRF window. Or,<br />
4) Just for plain fun! <img src='http://geeksbloggingat.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Either way, a nice to know feature in Siebel.</p>
<p><b>Remove some data from the About SRF Window<br />
</b></p>
<p>In Siebel Tools, navigate to &#8216;Applets&#8217; in the Siebel Object Explorer.<br />
Search for the &#8216;About SRF Applet&#8217; in the List of available applets.<br />
In the &#8216;Controls&#8217; section below the &#8216;Applets&#8217; in the Object Explorer tree, select the controls that you no longer want to show on the &#8216;About SRF Applet&#8217;. There would also be corresponding Labels visible as different controls.<br />
Set the property, &#8216;Inactive&#8217; to TRUE for all these controls and corresponding Label controls.<br />
Compile and go. Tell me what you see!</p>
<p>This concept can also be used to show some customized data onto the Siebel &#8216;About SRF Applet&#8217; as the requirement may be. Just remember to add the proper controls in the Edit Web Layout section of the Applet.</p>
<p>I am sure that the smartest of the lot will find many more similar applications, related to this implementation. Once you are done playing with this one, drop me a comment telling me how all did you play with this Applet. <img src='http://geeksbloggingat.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>


<p><b>Related posts:<b><ol><li><a href='http://geeksbloggingat.com/2009/05/20/siebel-remove-about-srf-window/' rel='bookmark' title='Permanent Link: Siebel &#8211; Remove About SRF Window'>Siebel &#8211; Remove About SRF Window</a> <small>In my previous post, I had discussed as to how...</small></li>
<li><a href='http://geeksbloggingat.com/2009/05/22/siebel-close-browser-window-when-logging-off/' rel='bookmark' title='Permanent Link: Siebel- Close Browser window when logging off'>Siebel- Close Browser window when logging off</a> <small>In case of standard interactivity applications like eSales , eService,...</small></li>
<li><a href='http://geeksbloggingat.com/2009/07/27/siebel-autosave-opportunity-the-concept/' rel='bookmark' title='Permanent Link: Siebel &#8211; Autosave Opportunity data &#8211; The concept'>Siebel &#8211; Autosave Opportunity data &#8211; The concept</a> <small>Requirement: System should have capability to automatically save opportunity(RFPs) data...</small></li>
<li><a href='http://geeksbloggingat.com/2009/07/28/siebel-autosave-opportunity-data-sample-code/' rel='bookmark' title='Permanent Link: Siebel &#8211; Autosave Opportunity data &#8211; Sample Code'>Siebel &#8211; Autosave Opportunity data &#8211; Sample Code</a> <small>This is a follow up post on my previous post,...</small></li>
<li><a href='http://geeksbloggingat.com/2009/05/10/siebel-reading-data-directly-from-siebel-srf/' rel='bookmark' title='Permanent Link: Siebel &#8211; Reading data directly from Siebel SRF'>Siebel &#8211; Reading data directly from Siebel SRF</a> <small>SRF or the Siebel Repository File as it is more...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://geeksbloggingat.com/2009/05/19/siebel-about-srf-window-remove-data/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

