Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

Re: SAP Pen Testing

Subject: Re: SAP Pen Testing
Date: Sat, 26 Feb 2005 15:48:22 +0100
Hi,

looks like SAP requires the HTTP PUT method on it's J2EE app server. I
just stumbled about it in a pen-test. So maybe you can upload scripts,
if you find a directory with write permissions and run commands using
the uploaded scripts.

Hope that helps ;-)

YB> I know there was a previous thread on this topic, however some of the
YB> information provided was not relevent.

YB> In this case I am pentesting the Enterprise Portal; the actual R/3 database
YB> is out of scope for this engagement.  The portal is a J2EE application
YB> server. We will also be testing a TREX system that is part of the
YB> environment.  

YB> I am going to be running through the typical stuff for most web
YB> applications, as well as some platform specific issues.  Anyone know of any
YB> issues or gotchas with SAP?

YB> Regards,
YB> Yvan Boily




-- 
Mit freundlichen Grüßen
Mailinglisten
mailto:mozilla@ids-guide.de



<Prev in Thread] Current Thread [Next in Thread>