Pwn a SAP System... then what ?

No ratings

Presented at Grehack 2018 by

SAP is no longer an unknown black box for security community. But despite this, we realize that risks behind SAP aren't well know. After a quick overview of SAP Netweaver fundamental, from pentesters point of view, I'll demonstrate three well know different ways to compromises a SAP system. Then I do not stop here and continue by showing post-exploitation examples who cover espionage, sabotage as well as fraud threats. Abusing privileged file manipulation Clement Lavoillotte https://www.youtube.com/watch?v=OfPTkx36EWsN/AThis talk presents how some file operations by privileged processes can be abused to escalate privileges. It will walk through various techniques to exploit such vulnerabilities on Windows, and illustrate these techniques with actual bugs found in security products, with a focus on AV quarantine bugs.