This blogpost contains summaries of talks from this year’s
TROOPERS18 SAP Security Track.
SAP IGS : The ‘vulnerable’ forgotten component by Yvan Genuer
The Internet Graphics Server (IGS) is used to generate Web Based graphics from
the SAP Web AS. Yvan Genuer looked at the security of an ancient component with
very few public vulnerabilities available so far. In his talk he gave us
insights on the structure of the IGS, its services, and problems he had when
looking for documentation of the IGS and its components.
Last year I encountered a slight variation of an internal port scan
vulnerability for the CrystalReports component of SAP Business Objects. The
original vulnerability was presented and disclosed by rapid7 in the talk
“Hacking SAP Business Objects”. The corresponding slides can be found
here.
Basically, the original vulnerability allowed port scanning of (internal)
systems via the URL
http://hostname/CrystalReports/viewrpt.cwr?id=$ID&wid=$WID&apstoken=ip:port@$TOKEN.
By accessing this URL, different responses were received depending on if the
port (parameter port in the URL) of the system (parameter ip in the URL) was in
the state “open” or “closed”. The original vulnerability has been fixed a long
time ago (SAP security note 1432881), but the fix did allow for a slight
variation to make the attack work again.
It is the end of the year and we are hoping it is not too hectic of a time for
you all! But if it is, hopefully the announcement of our next round
of TROOPERS17 talks is enough to get you in the TROOPERS
(if not the holiday) spirit 🙂
Francis Alexander & Bharadwaj Machiraju: How we hacked Distributed
Configuration Management Systems
With increase in necessity of distributed applications, coordination and
configuration management tools for these classes of applications have popped up.
These systems might pop-up occasionally during penetration tests. The major
focus of this research was to find ways to abuse these systems as well as use
them for getting deeper access to other systems.
On the 8th of March SAP released the security note for a vulnerability we
reported during an assessment of a SAP landscape. The issue affects the SAP
NetWeaver Web Administration Interface. By knowing a special URL a malicious
user can acquire version information about the services enabled in the SAP
system as well as the operating system used. We wanted to share some details on
the issue.
The vulnerability is a bypass of the HTTP Basic Authorization for the
SAP Web Administration Interface.
It discloses version information about the system respectively operating system,
a brief SAP patch level overview and running services including their
corresponding ports.
When it comes to SAP, Troopers has two events that are about Security in SAP
Systems in particular. On the first day of the Troopers16 Trainings the BIZEC
workshop takes place. The second event is a dedicated SAP track during the
conference. Apart from these events there were of course a lot of nice folks to
talk to (about SAP) 🙂 This post is a short overview about SAP security
@ TROOPERS16.
Right after the Opening Keynote of TROOPERS16, an informative and interesting
talk took place at the SAP Security track. This talk was given by three
speakers; Damian Poddebniak who is currently a master student at the University
of Applied Sciences of Münster, Sebastian Schinzel who works as an IT security
Professor at the University of Applied Sciences of Münster and he is also the
founder of CycleSEC GmbH and finally the sixth-time speaker at Troopers “Andreas
Wiegenstein” who is the CTO of Virtual Forge GmbH and a professional SAP
security consultant since 2003.
This is a guest post from Joris van de Vis @jvis,
on his upcoming Troopers
talk.
Additional credits go to: Robin Vleeschhouwer, and Fred van de Langenberg.
As
presented at Troopers
this year, ERP-SEC research has uncovered a set of potential default accounts
related to the use of SAP Solution Manager. These default accounts might pose a
big risk to your SAP supported business as some of them have wide
authorisations. It is therefore important to check if they exist in your
landscape and change the default passwords.
We just got
credits
for a flaw we found in SAP Netweaver. The issue is a reflected
Cross-Site Scripting
(XSS). It can be triggered in the administrative interface for the Internet
Communication Manager (ICM) and Web Dispatcher. This means that the targets for
this XSS will definitely be users with administrative privileges. This makes it
especially juicy for an attacker.
SAP rated the vulnerability with CVSS and a Base Score of 4.3 having a Base
Vector of AV:N/AC:M/AU:N/C:N/I:P/A:N. Which again opens the discussion on how
to rate the impact of XSS by using CVSS. CVSS
states that XSS
“should be scored with no impact to confidentiality or availability, and
partial impact to integrity“, which is clearly arguable. Especially when
thinking of the impact on confidentiality. As you might know by now, we tried to
tackle the problem of rating vulnerabilities ourselves with the
ERNW Rapid Rating System
(ERRS) and it was not an easy task. 😉 However, SAP states that this is a
correction with high priority, so you should apply the patches as soon as
possible.
Juan Perez-Etchegoyen
(@jp_pereze) and
Mariano Nunez
(@marianonunezdc)
from Onapsis here, thrilled to be
troopers for the third time! In this post we want to
share with you a glimpse of what you will see regarding SAP security at this
amazing conference.
Last week we released advisories regarding several vulnerabilities affecting SAP
platforms. Some of these vulnerabilities are in fact very critical, and their
exploitation could lead to a full-compromise of the entire SAP
implementation – even by completely anonymous attackers. Following our
responsible disclosure policy, SAP released the relevant SAP Security Notes
(patches) for all these vulnerabilities a long time ago, so if you are an SAP
customer make sure you have properly implemented them!
This is a guest post by the SAP security expert Juan Pablo Perez-Etchegoyen,
CTO of Onapsis. Enjoy reading:
At Onapsis we are continuously researching in the ERP
security field to identify the risks that ERP systems and business-critical
applications are exposed to. This way we help customers and vendors to increase
their security posture and mitigate threats that may be affecting their most
important platform: the one that stores and manages their business’ crown
jewels.