Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: SAP Pen Testing |
|---|---|
| Date: | Sat, 26 Feb 2005 15:48:22 +0100 |
Hi, looks like SAP requires the HTTP PUT method on it's J2EE app server. I just stumbled about it in a pen-test. So maybe you can upload scripts, if you find a directory with write permissions and run commands using the uploaded scripts. Hope that helps ;-) YB> I know there was a previous thread on this topic, however some of the YB> information provided was not relevent. YB> In this case I am pentesting the Enterprise Portal; the actual R/3 database YB> is out of scope for this engagement. The portal is a J2EE application YB> server. We will also be testing a TREX system that is part of the YB> environment. YB> I am going to be running through the typical stuff for most web YB> applications, as well as some platform specific issues. Anyone know of any YB> issues or gotchas with SAP? YB> Regards, YB> Yvan Boily -- Mit freundlichen Grüßen Mailinglisten mailto:mozilla@ids-guide.de
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Coldfusion Path Disclosure Vulnerability-Help Required, Maverick The Techie |
|---|---|
| Next by Date: | Google Getting (even) smarter, Josh Zlatin-Amishav |
| Previous by Thread: | SAP Pen Testing, Yvan Boily |
| Next by Thread: | Traceroute, Chris |
| Indexes: | [Date] [Thread] [Top] [All Lists] |