19.06.2015 Views

Attacking the Giants: Exploiting SAP Internals - Cybsec

Attacking the Giants: Exploiting SAP Internals - Cybsec

Attacking the Giants: Exploiting SAP Internals - Cybsec

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Attacking</strong> <strong>the</strong> <strong>Giants</strong>: <strong>Exploiting</strong> <strong>SAP</strong> <strong>Internals</strong><br />

<strong>SAP</strong> RFC Interface<br />

© 2007<br />

RFC Between <strong>SAP</strong> and External Systems<br />

• External RFC Client<br />

• External RFC Server<br />

External System<br />

<strong>SAP</strong> R/3 System<br />

<strong>SAP</strong> R/3 System<br />

External System<br />

Client<br />

Program<br />

Values<br />

G<br />

A<br />

T<br />

ABAP<br />

Function<br />

Module<br />

ABAP<br />

Program<br />

G<br />

A<br />

T<br />

Values<br />

Result<br />

Server Function 1<br />

E<br />

E<br />

Result<br />

W<br />

A<br />

Y<br />

result<br />

W<br />

A<br />

Y<br />

Server Function 2<br />

11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!