<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SAP on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/sap/</link>
    <description>Recent content in SAP on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 23 Mar 2018 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/sap/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>#TR18 SAP Security Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-sap-security-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-sap-security-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; SAP Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;sap-igs--the-vulnerable-forgotten-component-by-yvan-genuer&#34;&gt;SAP IGS : The ‘vulnerable’ forgotten component by Yvan Genuer&lt;/h1&gt;&#xA;&lt;p&gt;The Internet Graphics Server (IGS) is used to generate Web Based graphics from the SAP Web AS. Yvan Genuer looked at the security of an ancient component with very few public vulnerabilities available so far. In his talk he gave us insights on the structure of the IGS, its services, and problems he had when looking for documentation of the IGS and its components.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information About SAP Security Note 2336795</title>
      <link>https://insinuator.net/2017/03/information-about-sap-security-note-2336795/</link>
      <pubDate>Tue, 14 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/information-about-sap-security-note-2336795/</guid>
      <description>&lt;p&gt;Last year I encountered a slight variation of an internal port scan vulnerability for the CrystalReports component of SAP Business Objects. The original vulnerability was presented and disclosed by rapid7 in the talk “Hacking SAP Business Objects”. The corresponding slides can be found &lt;a href=&#34;http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Basically, the original vulnerability allowed port scanning of (internal) systems via the URL http://hostname/CrystalReports/viewrpt.cwr?id=$ID&amp;amp;wid=$WID&amp;amp;apstoken=ip:port@$TOKEN. By accessing this URL, different responses were received depending on if the port (parameter port in the URL) of the system (parameter ip in the URL) was in the state “open” or “closed”. The original vulnerability has been fixed a long time ago (SAP security note 1432881), but the fix did allow for a slight variation to make the attack work again.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2nd Rounds of TROOPERS17 Talks!</title>
      <link>https://insinuator.net/2016/12/2nd-rounds-of-troopers17-talks/</link>
      <pubDate>Wed, 14 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/2nd-rounds-of-troopers17-talks/</guid>
      <description>&lt;p&gt;It is the end of the year and we are hoping it is not too hectic of a time for you all! But if it is, hopefully the announcement of our next round of &lt;a href=&#34;http://troopers.de&#34;&gt;TROOPERS17&lt;/a&gt; talks is enough to get you in the TROOPERS (if not the holiday) spirit 🙂&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;Francis Alexander &amp;amp; Bharadwaj Machiraju: &lt;em&gt;How we hacked Distributed Configuration Management Systems&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;With increase in necessity of distributed applications, coordination and configuration management tools for these classes of applications have popped up. These systems might pop-up occasionally during penetration tests. The major focus of this research was to find ways to abuse these systems as well as use them for getting deeper access to other systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some infos about SAP Security Note 2258786</title>
      <link>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</link>
      <pubDate>Thu, 30 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</guid>
      <description>&lt;p&gt;On the 8th of March SAP released the security note for a vulnerability we reported during an assessment of a SAP landscape. The issue affects the SAP NetWeaver Web Administration Interface.  By knowing a special URL a malicious user can acquire version information about the services enabled in the SAP system as well as the operating system used.  We wanted to share some details on the issue.&lt;/p&gt;&#xA;&lt;p&gt;The vulnerability is a bypass of the HTTP Basic Authorization for the &lt;a href=&#34;https://help.sap.com/saphelp_nw73/helpdata/en/4b/c1cd5cfb0050e9e10000000a15822b/content.htm?frameset=/en/48/3e191a252f72d0e10000000a42189c/frameset.htm&amp;amp;current_toc=/en/62/d678c5330a4992bc6fe927e6137c9d/plain.htm&amp;amp;node_id=155&amp;amp;show_children=false&#34;&gt;SAP Web Administration Interface&lt;/a&gt;. It discloses version information about the system respectively operating system, a brief SAP patch level overview and running services including their corresponding ports.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SAP Security @ Troopers16</title>
      <link>https://insinuator.net/2016/04/sap-security-@-troopers16/</link>
      <pubDate>Mon, 25 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/sap-security-@-troopers16/</guid>
      <description>&lt;p&gt;When it comes to SAP, Troopers has two events that are about Security in SAP Systems in particular. On the first day of the Troopers16 Trainings the BIZEC workshop takes place. The second event is a dedicated SAP track during the conference. Apart from these events there were of course a lot of nice folks to talk to (about SAP) 🙂 This post is a short overview about SAP security &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;@ TROOPERS16.&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Patch Me If You Can</title>
      <link>https://insinuator.net/2016/04/patch-me-if-you-can/</link>
      <pubDate>Sat, 02 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/patch-me-if-you-can/</guid>
      <description>&lt;p&gt;Right after the Opening Keynote of TROOPERS16, an informative and interesting talk took place at the SAP Security track. This talk was given by three speakers; Damian Poddebniak who is currently a master student at the University of Applied Sciences of Münster, Sebastian Schinzel who works as an IT security Professor at the University of Applied Sciences of Münster and he is also the founder of CycleSEC GmbH and finally the sixth-time speaker at Troopers “Andreas Wiegenstein” who is the CTO of Virtual Forge GmbH and a professional SAP security consultant since 2003.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Check your SAP landscape for default Solution Manager users</title>
      <link>https://insinuator.net/2016/03/check-your-sap-landscape-for-default-solution-manager-users/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/check-your-sap-landscape-for-default-solution-manager-users/</guid>
      <description>&lt;p&gt;This is a guest post from Joris van de Vis &lt;a href=&#34;https://twitter.com/jvis&#34;&gt;@jvis&lt;/a&gt;,  on his upcoming Troopers &lt;a href=&#34;https://www.troopers.de/events/troopers16/603_an_easy_way_into_your_multi-million_dollar_sap_systems_an_unknown_default_sap_account/&#34;&gt;talk&lt;/a&gt;. Additional credits go to: Robin Vleeschhouwer, and Fred van de Langenberg.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/03/Picture1.png&#34; alt=&#34;Picture1&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;As &lt;a href=&#34;https://www.troopers.de/events/troopers16/603_an_easy_way_into_your_multi-million_dollar_sap_systems_an_unknown_default_sap_account/&#34;&gt;presented at Troopers&lt;/a&gt; this year, ERP-SEC research has uncovered a set of potential default accounts related to the use of SAP Solution Manager. These default accounts might pose a big risk to your SAP supported business as some of them have wide authorisations. It is therefore important to check if they exist in your landscape and change the default passwords.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS in SAP Netweaver</title>
      <link>https://insinuator.net/2014/01/xss-in-sap-netweaver/</link>
      <pubDate>Fri, 24 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/xss-in-sap-netweaver/</guid>
      <description>&lt;p&gt;We just got &lt;a href=&#34;http://scn.sap.com/docs/DOC-8218&#34; title=&#34;Acknowledgments to Security Researchers&#34;&gt;credits&lt;/a&gt; for a flaw we found in SAP Netweaver. The issue is a reflected &lt;a href=&#34;https://www.owasp.org/index.php/Top_10_2013-A3-Cross-Site_Scripting_%28XSS%29&#34; title=&#34;OWASP Top 10 - XSS&#34;&gt;Cross-Site Scripting&lt;/a&gt; (XSS). It can be triggered in the administrative interface for the Internet Communication Manager (ICM) and Web Dispatcher. This means that the targets for this XSS will definitely be users with administrative privileges. This makes it especially juicy for an attacker.&lt;/p&gt;&#xA;&lt;p&gt;SAP rated the vulnerability with CVSS and a Base Score of 4.3 having a Base Vector of &lt;code&gt;AV:N/AC:M/AU:N/C:N/I:P/A:N&lt;/code&gt;. Which again opens the discussion on how to rate the impact of XSS by using CVSS. CVSS &lt;a href=&#34;http://www.first.org/cvss/cvss-guide#i3.1.1&#34; title=&#34;CVSS rating XSS&#34;&gt;states&lt;/a&gt; that XSS “&lt;em&gt;should be scored with no impact to confidentiality or availability, and partial impact to integrity&lt;/em&gt;“, which is clearly arguable. Especially when thinking of the impact on confidentiality. As you might know by now, we tried to tackle the problem of rating vulnerabilities ourselves with the &lt;a href=&#34;http://www.insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/&#34; title=&#34;ERRS&#34;&gt;ERNW Rapid Rating System&lt;/a&gt; (ERRS) and it was not an easy task. 😉 However, SAP states that this is a correction with high priority, so you should apply the patches as soon as possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Latest SAP threats, SAP Forensics &amp;amp; BIZEC @Troopers!</title>
      <link>https://insinuator.net/2013/02/latest-sap-threats-sap-forensics-amp-bizec-@troopers/</link>
      <pubDate>Wed, 27 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/latest-sap-threats-sap-forensics-amp-bizec-@troopers/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-mariano-nunez-and-juan-perez-etchegoyen&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-1-day-workshop-sap-security-protecting-your-sap-systems-against-hackers-and-industrial-espionage/index.html&#34;&gt;Mariano Nunez and Juan Perez-Etchegoyen&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Juan Perez-Etchegoyen (&lt;a href=&#34;https://twitter.com/intent/user?screen_name=jp_pereze&#34;&gt;@jp_pereze&lt;/a&gt;) and Mariano Nunez (&lt;a href=&#34;https://twitter.com/intent/user?screen_name=marianonunezdc&#34;&gt;@marianonunezdc&lt;/a&gt;) from &lt;a href=&#34;http://www.onapsis.com/&#34;&gt;Onapsis&lt;/a&gt; here, thrilled to be &lt;a href=&#34;https://www.troopers.de&#34;&gt;troopers&lt;/a&gt; for the third time! In this post we want to share with you a glimpse of what you will see regarding SAP security at this amazing conference.&lt;/p&gt;&#xA;&lt;p&gt;Last week we released advisories regarding several vulnerabilities affecting SAP platforms. Some of these vulnerabilities are in fact very critical, and their exploitation could lead to a &lt;strong&gt;full-compromise&lt;/strong&gt; of the entire SAP implementation – even &lt;strong&gt;by completely anonymous attackers&lt;/strong&gt;. Following our responsible disclosure policy, SAP released the relevant SAP Security Notes (patches) for all these vulnerabilities a long time ago, so if you are an SAP customer make sure you have properly implemented them!&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERP Platforms Are Vulnerable</title>
      <link>https://insinuator.net/2012/03/erp-platforms-are-vulnerable/</link>
      <pubDate>Thu, 08 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/erp-platforms-are-vulnerable/</guid>
      <description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;This is a guest post by the SAP security expert Juan Pablo Perez-Etchegoyen, CTO of  Onapsis. Enjoy reading:&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;At &lt;a href=&#34;http://www.onapsis.com/&#34;&gt;Onapsis&lt;/a&gt; we are continuously researching in the ERP security field to identify the risks that ERP systems and business-critical applications are exposed to. This way we help customers and vendors to increase their security posture and mitigate threats that may be affecting their most important platform: the one that stores and manages their business’ crown jewels.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Diving Into Real-World Security Threats to SAP Systems</title>
      <link>https://insinuator.net/2012/02/diving-into-real-world-security-threats-to-sap-systems/</link>
      <pubDate>Wed, 01 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/diving-into-real-world-security-threats-to-sap-systems/</guid>
      <description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;This is a guest post by the SAP security experts of BIZEC. Enjoy reading:&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;On March 20^(th), the first &lt;a href=&#34;http://www.bizec.org/&#34;&gt;BIZEC&lt;/a&gt; workshop will be held at the amazing Troopers conference in Heidelberg, Germany. For those still unfamiliar with BIZEC: the &lt;em&gt;business application security initiative&lt;/em&gt; is a non-profit organization focused on security threats affecting ERP systems and business-critical infrastructures.&lt;/p&gt;&#xA;&lt;p&gt;The main goals of BIZEC are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Raise awareness, demonstrating that ERP security must be analyzed holistically.&lt;/li&gt;&#xA;&lt;li&gt;Analyze current and future threats affecting these systems.&lt;/li&gt;&#xA;&lt;li&gt;Serve as a unique central point of knowledge and reference in this subject.&lt;/li&gt;&#xA;&lt;li&gt;Provide experienced feedback to global organizations, helping them to increase the security of their business-critical information.&lt;/li&gt;&#xA;&lt;li&gt;Organize events with the community to share and exchange information.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The “&lt;a href=&#34;http://http://www.troopers.de/troopers12/agenda/bizec-workshop-sap-security-vulnerabilities-exploits-remediation/&#34;&gt;BIZEC workshop at Troopers 2012&lt;/a&gt;” will dive into the security of SAP platforms. Still to this day, a big part of the Auditing and Information Security industries believe that Segregation of Duties (SoD) controls are enough to protect these business-critical systems.&lt;br&gt;&#xA;By attending this session, InfoSec professionals and SAP security managers will be able to stop “flying blind” with regards to the security of their SAP systems. They will learn why SoD controls are not enough, which current threats exist that could be exploited by evil hackers, and how to protect their business-critical information from cyber-attacks.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
