SAP R/3 password encryption ?

From: Petr.Kazil@eap.nl
Date: Thu Feb 02 2006 - 11:15:49 EST


One of our customers with access to a SAP system found a query that lists
password changes.
It shows both the old and new passwords in encrypted format. He was
wondering if these password hashes might be crackable. I'm no SAP
specialist and if you don't have a SAP account it's hard to get any
documentation.

But to me it looks like a password hash that might be vulnerable to a
dictionary attack. But I don't know whether SAP uses something common
(like SHA) or a proprietary algorithm. The password dumps look like this:

Old value: New value:
|D624B6DF0C787DBC||21621AFB43G9726F| (I changed some values.)
|0000000000000000||75ADC566FA921A4A|

Does anyone have more information about the encrytion algorithm? I tried
to get the information from SAP specialists who gave a course to my
colleagues, but they didn't know either.

Greetings, Petr Kazil

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:26 EDT