Feeds

Enterprise giant SAP's systems take a probe to the wobbly bits - report

Penetration-testing securo-boffins show how hackers target corporate software

SANS - Survey on application security programs

At least 3,000 SAP systems are directly exposed to the internet, providing direct access to core corporate systems for potential attackers, according to a penetration-testing firm.

Rapid7, the firm behind the Metasploit penetration-testing tool, carried out the scanning exercise in the wake of the discovery of a banking Trojan that had been modified to look for SAP GUI installations, a worrying sign that SAP system hacking is moving towards into mainstream cybercrime.

Once the domain of a few isolated APT attacks, SAP appears to be in the crosshairs of hackers that know just how much sensitive data enterprise resource planning (ERP) systems house, including financial, customer, employee and production records. SAP's tens of thousands of customers may see an increase of attacks and their customers face the threat of data theft, fraud and sabotage.

"This trend is not really surprising, given that financial, customer, employee and production data reside in a company’s enterprise resource planning (ERP) systems — and they are juicy targets for all sorts of malicious hackers," writes Christian Kirsch, product marketing manager for Metasploit at Rapid7, in a blog post.

Too big to fail

He adds: "What’s worse, these systems have often organically grown over decades and are so complex that few people understand their organisation’s entire ecosystem, let alone some of SAP’s protocols and components that are not publicly documented."

Kirsch goes on to list a range of criminal scams that might be possible after hacking into vulnerable SAP installs. "Organised cyber-crime often looks for credit card numbers contained in business transaction data, which they use to conduct fraudulent transactions. They can extract social security numbers in an employee database to conduct identity theft. By changing the payee account details in the system, they can redirect funds into their own accounts and go home with a hefty paycheck," Kirsch warns.

"State-sponsored hacking groups regularly break into enterprises for purposes of industrial espionage," he adds. ERP systems provide them with a wealth of data to pass on to their domestic industry – as well as a chance to sabotage production flows and financial data. As a result, mergers and acquisitions may fall through or foreign competitors may get a head start on copying the latest technology."

5,000 SAP routers publicly exposed on the internet

SAP security specialists ERPScan, the firm that discovered the SAP-probing variant of the Shiz Trojan, reckons 3,400 SAP systems are exposed online (the difference in figures is because Rapid7 is only looking at web-based systems, according to ERPScan). However this isn't even the worst of the problem with insecure ERP systems.

"What is more critical is that almost 5,000 SAP routers are published on the internet and 85 per cent of them are vulnerable to remote code execution," Alexander Polyakov, CTO and co-founder of ERPScan, told El Reg.

"Thousands of other services are also exposed - at least 10,000 were found during some scans but it's very hard to calculate the full number," he added.

The latest annual survey (PDF) into the state of SAP security by ERPScan found that the most popular release SAP release is still NetWeaver 7.0, which was released in 2005 but still commands 35 per cent of the market. The general state of SAP security is getting worse, ERPScan concludes.

"Old issues are being patched, but a lot of new systems have vulnerabilities. SAP acquires new companies and invents new technologies faster than researchers analyse them," according to the ERP security specialists.

Separately, Rapid7 has released a research paper on conducting penetration tests on SAP systems. The research report gives an overview of key SAP components, explores how consultants can map out the system before an attack, and gives step-by-step examples on how to exploit vulnerabilities and brute-force logins.

These methods have been implemented and published in the form of more than 50 modules for Metasploit, Rapid7's open-source penetration-testing software. The modules enable organisations to test whether their own systems could be penetrated by an attacker.

The research paper, SAP Penetration Testing Using Metasploit - How to Protect Sensitive ERP Data, can be found here (free but registration required).

We invited SAP to comment on Rapid7 and ERPScan's assessments of the general state of corporate security tied to running and maintaining its software. The software giant has been in touch to say it is reviewing the reports. We'll update as and when we hear more. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.