SAPocalypse Now: Crushing SAP’s J2EE Engine

No ratings

Presented at HITBMalaysia 2011 by

Having had great success with the first part of our research “A crushing blow at the heart of SAP’s J2EE Engine” this is a continuation in this series of presentations and will look deeper at new web-based attacks and post exploitations on SAP’s J2EE applications. We will explain the architecture of SAP’s J2EE engine and give a complete tour into its internals. Thereafter, we will show a number of previously unknown architecture and program vulnerabilities from auth bypasses, smbrelays, internal scans, XML/SOAP attacks to insecure encryption algorithms and cross-system vulnerabilities in the J2EE platform. Finally a chained attack which use multiple logic vulnerabilities that gives full control over SAP’s J2EE Engine will be demoed. A free tool will also be presented to automatically scan custom applications against this attack. Will this attack concept lead to a new worm? Who knows, but be prepared for SAPocalypsis NOW!