Chained to Hit: Discovering New Vectors to Gain Remote and Root Access in SAP Enterprise Software

No ratings

Presented at BlackHat USA 2023 by

At the core of every business on the planet there will always be a mission critical application system. Commonly, organizations overlook their security which is dangerous and results in putting the business at high risk.During 2022, multiple month-lasting research projects were kicked off as part of the Onapsis Offensive Research labs. Even though each project had its own crucial results, no one expected that a combination of them would end up in critical chains of exploitation.This presentation will begin with the analysis of "P4", a proprietary protocol based on RMI, which is uncommonly exposed to public or untrusted networks and thus, making it unreachable from the Internet. Not only will critical vulnerabilities be shared, but most importantly the tactics and techniques used to unveil them.Then, it will continue with the exploration of JNDI reference injections where usual exploitation techniques did not work. After a deep dive into JNDI internals in SAP, a new and specific vector of exploitation that does not require a reverse connection will be shown.Finally, the study of a widely used component running as root or nt/system will be introduced together with an astonishing result: the discovery of a critical flaw that may allow a local attacker to completely compromise the whole system beyond the application's boundaries. This presentation will exhibit how simple and not-so-critical vulnerabilities could be chained in order to increase their impact or exposure. Specifically, it will be shown how flaws affecting a non-publicly exposed protocol, could be finally abused through the Internet thanks to the discovery of a new vector of exploitation against JNDI reference injection. Additionally, by chaining a series of aforementioned vulnerabilities, it will be demonstrated how it is possible to get reliable root access in a remote and anonymous way.