SAP Security
SAP Security Tips and Tricks, Trouble shooting problems, applying sap notes, support packages, upgradation, tweaks, audit, day to day jobs, security consultants’ activities etc.
By Amol Bharti on August 12, 2010
Unpacking SAP Support packages (SAR/CAR) during SAP upgrades takes a lot of time and manual effort. Find out how a simple batch script can automate and unpack hundreds of SAP Support Packages in seconds.
Posted in SAP Basis | Tagged accelerate sap support package upgrade, accelerator, batch file, car, quickly unpack, sap support packages, sapcar utility, sapcar.exe, sar, sarcar files, tips, tricks, un-archive, uncar |
By Amol Bharti on January 25, 2010
This short blog gives an overview on how Security in SAP BW, Enterprise Portal and SAP HR is different from SAP R/3 Security.
Posted in SAP Security | Tagged difference, Enterprise Portal Security, EP, how R/3 differs from SAP BW, HR, R/3 security is different, SAP BW Security |
By Amol Bharti on January 21, 2010
All spool requests created after 2009/12/23 with deletion date exceeding 2010/01/01 are wrongly Y2K’ed as 2099/12/31 or 2100/01/01 regardless of their retention period specified during creation. These spool requests will not be deleted if the spool reorg job RSPO0041 or RSPO1041 is executed with a variant that selects requests according to their deletion data, and [...]
Posted in SAP Security | Tagged 2100/01/01, Deletion date, expiry date, SP01, spool full, spool overflow
By Amol Bharti on December 31, 2009
This blog lists some of the most important and highly recommended SAP Security Notes. Please consult with a security expert or a basis specialist before implementing these security notes.
Posted in SAP Security | Tagged abap, blind sql, Cross Site Scripting, forensic security, missing authorizations, Netweaver, obsolete code, portal security, r/3, SAP Security, SQLi, xss |
By Amol Bharti on December 19, 2009
A new user interface for monitoring operating system environment has been introduced by SAP, in my opinion it’s way better than ST06 or OS07
Posted in SAP Basis | Tagged best practices, new applications, SAP Basis, sap basis tutorial, short blog, tips, tricks |
By Amol Bharti on November 27, 2009
Given are a few guidelines for an effective SAP Portal implementation. Stay tuned for the amudee.com security series, a lot more to come..
Posted in SAP Security | Tagged 0 day exploit, codergeek82, Collaboration Security, exploiting SAP Portal with Google hacking., GRC Security, Hacking SAP Portal, Knoweledge Management, Portal vulnerability, SAP Enterprise Portal Security, SAP Portal Security Guidelines, Secure your SAP Portal, zero day |
By Amol Bharti on November 27, 2009
During an SAP Portal Security review, I came across a scenario where HTTPOnly flag in session cookie was not set. Please checkout the recommendation given in this short blog.
Posted in SAP Security | Tagged ethical hacker india, httponly flag in cookie not set, recommendations, sap hacker, sap portal security, SAP Security |
By Amol Bharti on November 26, 2009
In my earlier blog, I had promised to cover some of the most critical security issues that you may face sooner or later. So here are some pointers for you to re-evaluate your SAP Portal implementation and fix the significant issues before someone else breaks-in. Here is a POC with some snapshots.
Posted in SAP Security | Tagged 0 day exploit, codergeek82, Collaboration Security, exploiting SAP Portal with Google hacking., GRC Security, Hacking SAP Portal, Knoweledge Management, Portal vulnerability, SAP Enterprise Portal Security, Secure your SAP Portal, zero day |
By Amol Bharti on November 26, 2009
In this series of blogs, I will be focusing more on the core SAP security, Portal, Netweaver and some other topics like XSS, So keep watching the space.
Posted in SAP Security | Tagged 0day exploits, back door access, CA, ethical hacker india, forensic, hacking sap, NASA vulnerabilities reported, sap, sap portal vulnerabilities, SAP Security, white hat hackers, zero day |
Recent Comments