Having had great success with the first part of our research “A crushing blow at the heart of SAP’s J2EE Engine” this is a continuation in this series of presentations and will look deeper at new web-based attacks and post exploitations on SAP’s J2EE applications. We will explain the architecture of SAP’s J2EE engine and give a complete tour into its internals. Thereafter, we will show a number of previously unknown architecture and program vulnerabilities from auth bypasses, smbrelays, internal scans, XML/SOAP attacks to insecure encryption algorithms and cross-system vulnerabilities in the J2EE platform. Finally a chained attack which use multiple logic vulnerabilities that gives full control over SAP’s J2EE Engine will be demoed. A free tool will also be presented to automatically scan custom applications against this attack. Will this attack concept lead to a new worm? Who knows, but be prepared for SAPocalypsis NOW!