16.08.2013 Views

Breaking SAP Portal - Proidea

Breaking SAP Portal - Proidea

Breaking SAP Portal - Proidea

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Breaking</strong> <strong>SAP</strong> <strong>Portal</strong><br />

• Found a file in the OS of <strong>SAP</strong> <strong>Portal</strong> with the<br />

encrypted passwords for administration and DB<br />

• Found a file in the OS of <strong>SAP</strong> <strong>Portal</strong> with keys to<br />

decrypt passwords<br />

• Found a vulnerability (another one ;)) which<br />

allows reading the files with passwords and<br />

keys<br />

• Decrypt passwords and log into <strong>Portal</strong><br />

• PROFIT!

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!