RE: SAP Pen-Test

From: Todd Towles (toddtowles@brookshires.com)
Date: Tue Nov 02 2004 - 12:05:33 EST


Hydra (parallized login hacker) from THC uses some SAP R/3 stuff. Anyone ever use test it?
Currently this tool supports:
          TELNET, FTP, HTTP, HTTPS, HTTP-PROXY, LDAP, SMB, SMBNT, MS-SQL, MYSQL, REXEC,
          CVS, SNMP, SMTP-AUTH, SOCKS5, VNC, POP3, IMAP, NNTP, PCNFS, ICQ, SAP/R3,
          Cisco auth, Cisco enable, Cisco AAA (incorporated in telnet module).
http://www.thc.org/releases.php

> -----Original Message-----
> From: Sven Tambler [mailto:tambler.20.tam@spamgourmet.com]
> Sent: Friday, October 29, 2004 3:42 AM
> To: pen-test@securityfocus.com
> Subject: SAP Pen-Test
>
> Hello everyone,
>
> I want to test a SAP Enterprise Portal. Do you know a tool
> for pen-testing a SAP portal? Of course, there are a lot of
> tools and techniques for apache or IIS and you can use them
> in a similar way.
> Otherwise there are a lot of SAP originalities and
> specialities you have to keep in mind. I donīt search for a
> tool like "nessus for SAP" - such a thing doesnīt exist - but
> some advices or plug-ins could be very useful. Could you by
> any chance be able to help?
>
> Thanks - Sven
>
>



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:08 EDT