<?xml version="1.0" encoding="windows-1251"?>
<rss version="2.0"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<link>http://dsecrg.com/pages/news/</link>
<title>Digital Security Research Group: News</title>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=88</link>
<guid>http://dsecrg.com/pages/news/show.php?id=88</guid>
<title>ERPScan researchers guard Adobe</title>
<description>&lt;div align=&quot;justify&quot;&gt;&lt;p&gt;Adobe, the global leader in digital marketing and digital media solutions, &lt;a href=&quot;http://www.adobe.com/support/security/bulletins/securityacknowledgments.html&quot;&gt;thanks&lt;/a&gt; &lt;b&gt;Dmitry Chastukhin&lt;/b&gt;, &lt;b&gt;ERPScan&lt;/b&gt; lead assessor, for the dangerous vulnerabilities that he has found at &lt;a href=&quot;http://www.adobe.com&quot;&gt;Adobe.Com&lt;/a&gt; in the framework of research conducted by Digital Security Research Group, a subdivision of &lt;b&gt;ERPScan&lt;/b&gt;.&lt;/p&gt;&lt;p&gt;
The website contained several vulnerabilities which allow compromising user accounts and getting additional information about the system so that an attacker could devise specific attack vectors with the gathered data. A possibility of injecting malicious code into the web page was also revealed, which would do serious harm to the public image of the company if exploited. In the course of one of the possible attacks, a hacker could replace legitimate content with malware, so that downloading a regular Adobe Flash Player update would lead to infection of millions PCs worldwide. Thanks to &lt;b&gt;ERPScan&lt;/b&gt; researchers, no hacker can exploit the security breach anymore.&lt;/p&gt;&lt;p&gt;
&#8219;&lt;i&gt;I hope other world-famous corporations like Adobe will follow suit and pay more attention to the security of their web sites. A web representation of company as a basis for their reputation must be undervalued&lt;/i&gt;&#8220;, Dmitry comments on his findings.&lt;/p&gt;&lt;/div&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=87</link>
<guid>http://dsecrg.com/pages/news/show.php?id=87</guid>
<title>ERPScan has released a new version of Security Scanner for SAP: ERPScan v2.0</title>
<description>&lt;a href=&quot;http://erpscan.com/wp-content/uploads/2012/04/ERPScan-SAP-2.png&quot;&gt;&lt;img src=&quot;http://erpscan.com/wp-content/uploads/2012/04/ERPScan-SAP-2-300x83.png&quot; alt=&quot;&quot; title=&quot;ERPScan-SAP 2&quot; width=&quot;300&quot; height=&quot;83&quot; class=&quot;alignnone size-medium wp-image-2709&quot; /&gt;&lt;/a&gt;
&lt;br&gt;
&lt;div align=&quot;justify&quot;&gt;&lt;p&gt;ERPScan company, one of the key players in ERP security, has released&nbsp; ERPScan Security Scanner for SAP 2.0 &ndash; a complex solution to continuously monitor all areas of SAP security, from vulnerability assessment and misconfigurations to ABAP code review and analysis of business-critical privileges.&lt;/p&gt;&lt;p&gt;

One of the most significant changes is a new module which can make static analysis of ABAP code security. It makes ERPScan the only solution on the market which makes both security assessment of platform and code review. We have also significantly increased the number of anonymous checks which can be performed in Penetration testing mode to help companies identify issues without using credentials in the system. The new engine can help to perform audit and compliance checks not just through RFC &ndash; it allows making complete scan through the web-interface which is a great feature for external penetration tests and can make pen-testers&#8217; lives easier.&lt;/p&gt;


&lt;p&gt;
&#8219;&lt;em&gt;Today, almost all critical operations like procurements, stock resources management, human resources management, financial reports and much more, and all the data related to them, are stored in SAP system. This is why the main target for an insider or an external attacker would be to gain illicit access to SAP with the purpose of malicious manipulation of company resources. In spite of the increasing popularity of ERP systems security in the security community, companies are still vulnerable to cybercriminal and insider attacks. At this moment SAP has released more than 2000 Security notes closing various vulnerabilities, which is quite a lot, especially if you keep in mind that sometimes it is enough to get access to all business critical data through only one issue. An example was presented at BlackHat last summer. On the other side, almost every company develops custom ABAP code which can also have vulnerabilities and backdoors left by developers&lt;/em&gt;&#8220;, said &lt;strong&gt;Alexander Polyakov&lt;/strong&gt;, CTO of ERPScan.

&lt;/p&gt;

&lt;p&gt;
Using ERPScan, all kinds of customers can decrease their expenses and get different benefits.&lt;/p&gt;&lt;p&gt;

&lt;ul&gt;
	&lt;li&gt;Consulting companies can save time and resources. ERPScan allows them to significantly simplify the task of assessment by automating most of the ordinary checks, so auditors can pay more attention to the analysis of the customized part. Moreover, the unique database of checks gives consulting companies competitive advantages.&lt;/li&gt;

	&lt;li&gt;CISOs can effectively monitor security of SAP systems and prevent insider and hacker threats.&lt;/li&gt;

	&lt;li&gt;Penetration testers can easily perform black-box and white-box assessments of SAP with the largest knowledge base in the world and 0-day vulnerabilities.&lt;/li&gt;

	&lt;li&gt;SAP team can manage business-critical authorizations and control development by applying preventive measures.&lt;/li&gt;
&lt;/ul&gt;

&lt;/p&gt;&lt;p&gt;


&#8219;&lt;em&gt;SAP security assessment, according to our experience, usually takes quite a long time. Additionally, the complexity of the system and the large amount of different installation types require the participation of specialists from various fields of security. Even the application server may have either ABAP or Java platform, and they require completely different specialists, not to mention particular applications and modules. ERPScan allows you to significantly simplify the task of assessment by automating most of the ordinary checks, so you can pay more attention to the analysis of the customized part&lt;/em&gt;&#8220;, said &lt;strong&gt;Alexander Polyakov&lt;/strong&gt;.
&lt;/p&gt;&lt;p&gt;
More new functions:&lt;/p&gt;&lt;p&gt;

&lt;ul&gt;
	&lt;li&gt;Support of different web application types (bsp/iviews/jsp/webservices/webdynpro&#8217;s)&lt;/li&gt;


	&lt;li&gt;More than 5000 different checks covering misconfigurations, vulnerabilities, access to web-applications; search for 50 different types of&nbsp; vulnerabilities in ABAP code&lt;/li&gt;


	&lt;li&gt;Elaborated black-box vulnerability assessment&lt;/li&gt;

	&lt;li&gt;Cataloguing of SAP systems and services&lt;/li&gt;
&lt;/ul&gt;


&lt;/p&gt;&lt;p&gt;

&#8219;&lt;em&gt;Earlier, you needed to implement many different solutions to secure SAP from threats, now it is all in one place&lt;/em&gt;&#8220;, said &lt;strong&gt;Ilya Medvedovsky&lt;/strong&gt;, CEO of ERPScan.&lt;/p&gt;&lt;/div&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=86</link>
<guid>http://dsecrg.com/pages/news/show.php?id=86</guid>
<title>Installation of vendor's patch does not always guarantee security</title>
<description>&lt;p&gt;
Experts from &lt;a href=&quot;http://www.erpscan.com&quot;&gt;ERPScan Company&lt;/a&gt;, specialized in business applications security and SAP security, found out that even well-timed installation of vendor&#8217;s patch does not always guarantee security because the fixes are not always correct. In 2011, three critical patches from the key software vendors like SAP, IBM and VMware actually did not fix or not completely fixed vulnerabilities that ERPScan or other researchers had found in their products. This allows potential attackers to continue exploiting the vulnerabilities, whereas all most scanners and auditors would say that the problem is no more because patch is installed.&lt;/p&gt;
&lt;p&gt;On the BlackHat Europe conference held from March 14 to March 16, &lt;b&gt;Alexey Sintsov&lt;/b&gt;, head of information security audit department in &lt;a href=&quot;http://www.erpscan.com&quot;&gt;ERPScan Company&lt;/a&gt;, shared his experience in penetration testing and presented the results of a recently conducted &lt;a href=&quot;http://erpscan.com/wp-content/uploads/2012/03/bh-eu-12-Sintsov-Lotus_Domino-WP.pdf&quot;&gt;research&lt;/a&gt; of Lotus Domino security.&lt;/p&gt;&lt;p&gt;
His presentation told about lack of time and frequently desire for companies to dig into the details of existing vulnerabilities to exploit them, and how it often impairs the quality of their work.&lt;/p&gt;&lt;p&gt;
In the demonstration, a private vulnerability in Lotus Domino was quite quickly disassembled, the resulting exploit used, the existing patch bypassed and a critical 0-day vulnerability found. The result was an attack on the Domino Controller service (the Lotus Domino administration service) which allows full server compromise.&lt;/p&gt;&lt;p&gt;
Vulnerable services were also exposed which, one would suppose, should not be accessible from the Internet. Moreover, in the course of the research, services with the 0-day vulnerability and ever older vulnerabilities were found on the USA government servers (the .gov domain), on the servers of Russian universities and, curiously enough, even in the corporate network of IBM itself.&lt;/p&gt;&lt;p&gt;
Thus, it can be concluded that penetration threats are quite easily actualized for pretty much any network; even governments and corporate giants are vulnerable to attacks from the Internet, such as those made by LulzSec and Anonymous.&lt;/p&gt;
&lt;p&gt; Links to vulnerabilities:&lt;/p&gt;
  Vulnerability in IBM Lotus (&lt;a href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-11-110/&quot;&gt;ZDI&lt;/a&gt;)&lt;/br&gt;
  Vulnerability in VMware (&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=342&quot;&gt;Advisory&lt;/a&gt;,&lt;a href=&quot;http://www.vmware.com/security/advisories/VMSA-2011-0014.html&quot;&gt;Vendor&#8217;s patch&lt;/a&gt;)&lt;/br&gt;
  Vulnerabilities in SAP (&lt;a href=&quot;http://erpscan.com/advisories/dsecrg-11-039-sap-netweaver-th_grep-module-code-injection-vulnerability-new/&quot;&gt;Advisory&lt;/a&gt;,
&lt;a href=&quot;https://service.sap.com/sap/support/notes/1580017&quot;&gt;New patch&lt;/a&gt;,
&lt;a href=&quot;https://service.sap.com/sap/support/notes/1433101&quot;&gt;Old patch&lt;/a&gt;); another one is still being patched again.&lt;/p&gt;&lt;p&gt;
Alexey&#8217;s presentation can be found &lt;a href=&quot;http://erpscan.com/wp-content/uploads/2012/03/bh-eu-12-Sintsov-Lotus_Domino-Slides.pdf&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=85</link>
<guid>http://dsecrg.com/pages/news/show.php?id=85</guid>
<title>SAP critical patch update March 2012</title>
<description>&lt;p&gt;&lt;a href=&quot;http://www.sap.com/&quot;&gt;SAP&lt;/a&gt; has released monthly critical patch update for March 2012. This patch update closes many vulnerabilities in SAP products. This month, 2 vulnerabilities found by &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;ERPScan&lt;/a&gt;  researchers Dmitriy Chastukhin and Alexey Tyurin were closed.&lt;/p&gt;

&lt;p&gt;Detailed list of corrected vulnerabilities is below:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt; An XSS vulnerability was found in SAP Portal. An attacker can use the XSS vulnerability by sending a link to malicious script to an unaware user via an e-mail, messaging or social networks. Thus, an attacker can gain access to user session and gain control over business-critical information which can be accessed by victim. Update is available in SAP Note 1656549. Criticality, according to CVSS, is 4.3.&lt;/li&gt;


&lt;li&gt; Missing authorization checks in RFC function from BASIS module. Update is available in SAP Note 1657891. Criticality, according to CVSS, is 2.3. An attacker can execute vulnerable transaction, program or RFC function remotely without authentication because authorization check is missing. It can lead to different threats from information disclosure to full system compromise.&lt;/li&gt;&lt;/ul&gt;

&lt;p&gt;SAP has traditionally published acknowledgements for found vulnerabilities to security researchers from DSecRG on their &lt;a href=&quot;http://scn.sap.com/docs/DOC-8218&quot;&gt;  acknowledgement page&lt;/a&gt;.&lt;/p&gt;
 
&lt;p&gt;It is highly recommended to patch all those issues to prevent business risks.&lt;/p&gt;


&lt;p&gt;Advisories for those issues with technical details will be available within 3 months on &lt;a href=&quot;http://www.erpscan.com/&quot;&gt;ERPScan.com&lt;/a&gt; and also on &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG.com&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Exploits will be available soon in &lt;a href=&quot;http://www.erpscan.com/&quot;&gt;ERPScan Security Scanner&lt;/a&gt; and ERPScan SaaS.&lt;/p&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=84</link>
<guid>http://dsecrg.com/pages/news/show.php?id=84</guid>
<title>DSecRG supports Project BaseCamp by releasing WAGO PLC 0-day vulnerabilities</title>
<description>&lt;p&gt; One of the key events in SCADA and PLC security &ndash; &lt;a href=&quot;http://www.digitalbond.com/s4&quot;&gt; the S4ICS symposium &lt;/a&gt; &ndash; took place in Miami on January, 18 to 19.&lt;/p&gt;&lt;p&gt;
Aside from several reports and SCADA security trainings, the results of a colossal &lt;a href=&quot;http://www.digitalbond.com/2012/01/19/project-basecamp-at-s4&quot;&gt; project&lt;/a&gt;, dedicated to research of vulnerabilities in industrial controllers, were presented to the symposium.&lt;/p&gt;&lt;p&gt;
The project was named Project Basecamp.
&lt;/p&gt;&lt;p&gt;
The following industrial controllers were examined:
&lt;/p&gt;&lt;p&gt;
&lt;ul&gt;
&lt;li&gt; General Electric D20ME &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Koyo/Direct LOGIC H4-ES &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Rockwell Automation/Allen-Bradley ControlLogix &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Rockwell Automation/Allen-Bradley MicroLogix &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Schneider Electric Modicon Quantum &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Schweitzer SEL-2032 (a communication module for relays) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt; The DSecRG researchers decided to support the project by their independent research and added the 750 series WAGO controller to the list. They have also published a variety of 0-day vulnerabilities for this controller and for the SCADA systems of wellintech KingSCADA and OPC Systems.NET, to draw the public attention to this problem once more.
&lt;/p&gt;&lt;p&gt;
The following links lead to the details about found vulnerabilities:&lt;/p&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=401&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=401&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=402&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=402&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=403&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=403&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=404&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=404&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=405&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=405&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=406&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=406&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=407&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=407&lt;/a&gt;
&lt;p&gt; The results of the Project BaseCamp research are available here:&lt;/p&gt;
&lt;a href=&quot;http://www.digitalbond.com/2012/01/19/project-basecamp-at-s4/&quot;&gt;http://www.digitalbond.com/2012/01/19/project-basecamp-at-s4/&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://www.wired.com/threatlevel/2012/01/scada-exploits/&quot;&gt;http://www.wired.com/threatlevel/2012/01/scada-exploits/&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://reversemode.com/downloads/logix_report_basecamp.pdf&quot;&gt;http://reversemode.com/downloads/logix_report_basecamp.pdf&lt;/a&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=71</link>
<guid>http://dsecrg.com/pages/news/show.php?id=71</guid>
<title>ERPScan Company enters the Google and Yandex Halls of Fame for work in information security</title>
<description>&lt;p&gt;&lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG &lt;/a&gt; researchers Dmitry Chastukhin and Alexey Sintsov were inducted into the Google Company Hall of Fame (&lt;a href=&quot;http://www.google.com/about/corporate/company/halloffame.html&quot;&gt;http://www.google.com/about/corporate/company/halloffame.html&lt;/a&gt;) within the vulnerability search section. The goal of the program is recognition of information security specialists who found and reported about the vulnerabilities in WEB resources of Google Company.&lt;/p&gt;

&lt;p&gt;During the research a very interesting and unique vulnerability at the Google Documents resource was found that allowed the addition of random EXCEL formulas into the documents via Google Forms. Using the given vulnerability potential malefactors can obtain critical data from user charts.&lt;/p&gt;

&lt;p&gt;Google specialists considered the vulnerability in &#8219;elite&#8220; sum $1337 class, expressing their surprise and noted the originality of the found attack vector.&lt;/p&gt;

&lt;p&gt;Also at the &lt;a href=&quot;http://www.zeronights.org/&quot;&gt;ZeroNights 2011 Conference &lt;/a&gt; the results of the &#8219;Month of searching for the vulnerabilities&#8220; competition from Yandex were summed up.&lt;/p&gt;

&lt;p&gt;Alexey Sintsov, the head of information security audit department at &lt;a href=&quot;http://www.erpscan.com/&quot;&gt;ERPScan&lt;/a&gt; took the second place and recieved $3000 as well as a place in the Yandex Hall of Fame.&lt;/p&gt;

&lt;p&gt;According to an agreement with Yandex, in two months we will be able to reveal technical details of found vulnerability.&lt;/p&gt;

&lt;p&gt;It is worth noting that Yandex Company became a pioneer in similar kinds of programs in Russian Internet segment and is not going to stop on conducting of only one competition.&lt;/p&gt;

&lt;p&gt;&lt;i&gt;&#8219;By these awards, received for the researches, connected with searching for the vulnerabilities in the products of two leading searchers, we clearly demonstrated the highest level of our employees&#8217; qualification, who constantly sharpen their skills, including in the similar researches&#8220;&lt;/i&gt;-noted Ilya Medvedovsky, ERPScan CEO.&lt;/p&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=70</link>
<guid>http://dsecrg.com/pages/news/show.php?id=70</guid>
<title>SAP critical patch update October 2011  </title>
<description>&lt;p&gt;&lt;a href=&quot;http://www.sap.com/&quot;&gt;SAP&lt;/a&gt; released monthly critical patch update for October 2011. This patch update closes many vulnerabilities in SAP products. 6 of those vulnerabilities were found by different experts. Traditionally Dmitry Evdokimov , &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG&lt;/a&gt; researcher, is among them.&lt;/p&gt;
&lt;p&gt;SAP traditionally sent acknowledgements for found vulnerabilities to security researchers from DSecRG on their &lt;a href=&quot;http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a&quot;&gt; acknowledgement page&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Detailed list of corrected vulnerabilities is below:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt; XSS vulnerability.  Update is available in sap note 1585652. Criticality according to CVSS is 4.3.
An attacker can use XSS vulnerability by sending a link on malicious script to an unaware user via an e-mail, messaging or social networks. Thus, an attacker can gain access to user session and gain control on business-critical information which can be accessed by a victim.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It is highly recommended to patch all those issues to prevent business risks.&lt;/p&gt;
&lt;p&gt;Solutions for those issues are available in SAP Notes: 1585652&lt;/p&gt;
&lt;p&gt;Advisories for those issues with technical details will be available in 3 months on &lt;a href=&quot;http://www.erpscan.com/&quot;&gt;erpscan.com&lt;/a&gt; and also on &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG.com&lt;/a&gt; site.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=69</link>
<guid>http://dsecrg.com/pages/news/show.php?id=69</guid>
<title>SAPocalypse - concept of a new SAP worm will be presented at HITB Malaysia</title>
<description>&lt;p&gt;Two months have passed since the report on critical vulnerability in SAP's J2EE engine was published. Though it is a serious vulnerability, some people didn't estimate it, pointing to the fact that only systems on the JAVA basis which sometimes don't store critical data, as ERP or BI do and used for these systems' connection and collaboration.&lt;br&gt;&lt;br&gt;&lt;/p&gt;

&lt;p&gt;In a new report which will be presented at the &lt;a href=&quot;http://conference.hitb.org/hitbsecconf2011kul/&quot;&gt;HITB&lt;/a&gt; conference in Malaysia, &lt;a href=&quot;http://www.erpscan.com/&quot;&gt;ERPScan&lt;/a&gt; specialists will show prototype of a new worm with a code name SAPacalypse. It will use a vulnerability in SAP NetWeaver JAVA server, available via the Internet and then connects to the connected ABAP servers in the internal network, where ERP, CRM, BI and other applications can be installed. After it virus steals critical data and data for connection to other linked servers from these systems. Taking into account a deep integration of business processes and as a result a multiple connections using internal links, it will allow to get into almost any corporate systems via the only vulnerable.&lt;br&gt;&lt;br&gt;&lt;/p&gt;

&lt;a href=&quot;http://conference.hitb.org/hitbsecconf2011kul/?page_id=1806&quot; title=&quot;http://conference.hitb.org/hitbsecconf2011kul/?page_id=1806&quot;&gt;&lt;/a&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=68</link>
<guid>http://dsecrg.com/pages/news/show.php?id=68</guid>
<title>Whitepaper &quot;Python arsenal for Reverse Engeneering&quot; have been updated to version 1.0 </title>
<description>We are happy to announce that Whitepaper &lt;a href=http://dsecrg.com/pages/pub/show.php?id=39&gt;Python arsenal for Reverse Engeneering&lt;/a&gt; updated to version 1.0.&lt;br&gt;&lt;br&gt; New interesting projects have been added.
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=67</link>
<guid>http://dsecrg.com/pages/news/show.php?id=67</guid>
<title>DSecRG researchers took part in Brucon conference and conducted a meeting with SAP.</title>
<description>&lt;p&gt;&lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG&lt;/a&gt; specialists took part in &lt;a href=&quot;http://2011.brucon.org/index.php/Main_Page&quot;&gt;Brucon&lt;/a&gt; conference which was held in September, 19-20 in Brussels (Belgium). An updated talk, devoted to program and architect vulnerabilities in J2EE engine of SAP NetWeaver platform, was presented at the conference. There were presented two new vulnerabilities, which allow getting information unauthorized about users&#8217; names in the system, and also conducting a company internal network scanning  via servers, available in the Internet.&lt;/p&gt;
&lt;p&gt;After the conference there was a meeting with Security Response Team of &lt;a href=&quot;http://www.sap.com/&quot;&gt;SAP&lt;/a&gt; Company on the questions of cooperation in the field of vulnerabilities&#8217; founding and remediation. A closer cooperation of DSecRG specialists with development team and Response Team at the stages of vulnerabilities&#8217; closure and patches&#8217; testing will allow reducing the time of critical updates&#8217; publication.&lt;/p&gt;
&lt;p&gt;Slides from Brucon presentation are available at our web site in the &lt;a href=&quot; http://erpscan.com/presentations/presentation-a-crushing-blow-at-the-heart-of-sap-j2ee-engine-version-1-1-from-brucon-2011/&quot;&gt;presentations&#8217;&lt;/a&gt; section.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=66</link>
<guid>http://dsecrg.com/pages/news/show.php?id=66</guid>
<title>ERPScan appeared at the SecurityByte conference</title>
<description>&lt;p&gt;Researchers from &lt;a href=&quot;http://erpscan.com&quot;&gt; ERPScan&lt;/a&gt; took part in the largest information security conference in India -  &lt;a href=&quot;http://www.securitybyte.org/&quot;&gt; SecurityByte&lt;/a&gt;. 
&lt;p&gt;A conference in information security - SecurityByte - was held from 6 to 9 September in Indian Silicon Valley - electronic city (Bangalor suburb).&lt;/p&gt;
&lt;img src=&quot;http://dsec.ru/images/dsec1.JPG&quot; width=&quot;669&quot; height= &quot;446&quot; border=&quot;0&quot; align=&quot;center&quot; /&gt;
&lt;p&gt;Senior managers from RSA, (ICS)2, EC-Council, well-known persons such as Whitfield  Diffie  (pioneer of public-key cryptography), and also such Indian top officials as Karanataka state governor and Indian army general were invited.&lt;/p&gt;
&lt;img src=&quot;http://dsec.ru/images/dsec2.JPG&quot; width=&quot;669&quot; height= &quot;446&quot; border=&quot;0&quot; align=&quot;center&quot; /&gt;

&lt;p&gt;ERPScan Company took part in a section of reports, trainings and round tables.&lt;/p&gt;
&lt;p&gt;Alexander Polyakov made a presentation about security of J2EE of SAP engine, and also conducted a one-day training concerning hack and security of SAP systems. Remarkably that one of the vulnerable application developers attended this presentation. Moreover, Alexander took part in a round table, devoted to mobile devices&#8217; security.&lt;/p&gt;
&lt;img src=&quot;http://dsec.ru/images/dsec3.JPG&quot; width=&quot;669&quot; height= &quot;446&quot; border=&quot;0&quot; align=&quot;center&quot; /&gt;

&lt;p&gt;We remind you that for securing SAP from the presented attacks ERPScan developed free utility &lt;a href=&quot;http://erpscan.com/products/erpscan-webxml-checker/&quot;&gt; ERPScan web.xml checker&lt;/a&gt; which is a part of &lt;a href=&quot;http://erpscan.com&quot;&gt;ERPScan security scanner for SAP&lt;/a&gt; and allows to check J2EE security settings of SAP applications on the presence of 9 different configuration mistakes. It  can help administrator to set up system securely by himself and understand where there are lacks.&lt;/p&gt;
&lt;p&gt;Next ERPScan performances will be at:&lt;/p&gt;

&lt;p&gt;19 September &ndash; &lt;a href=&quot;http://2011.brucon.org/index.php/Main_Page&quot;&gt; Brucon&lt;/a&gt; (Belgium, Brussels);&lt;/p&gt;
&lt;p&gt;28-30 September &ndash; &lt;a href=&quot;http://www.infosecurityrussia.ru/&quot;&gt; InfosecurityRussia &lt;/a&gt;(Russia, Moscow);&lt;/p&gt;
&lt;p&gt;12 October &ndash;&lt;a href=&quot;http://conference.hitb.org/hitbsecconf2011kul/&quot;&gt;HITB KUL&lt;/a&gt; (Malaysia, Kuala Lumpur);&lt;/p&gt;
&lt;p&gt;27 October &ndash; &lt;a href=&quot;http://www.hackerhalted.com/2011/&quot;&gt;Hacker Halted&lt;/a&gt;(USA, Miami).&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=65</link>
<guid>http://dsecrg.com/pages/news/show.php?id=65</guid>
<title>SAP critical patch update september 2011</title>
<description>&lt;p&gt;&lt;a href=&quot;http://www.sap.com/&quot;&gt;SAP&lt;/a&gt; released monthly critical patch update for september 2011. This patch update closes about 70 vulnerabilities in SAP products. 17 of those vulnerabilities were founded by different experts. Traditionnaly &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG&lt;/a&gt; researchers Alexander Polyakov, Alexey Tuyrin and Evgeniy Neyolov who found 3 vulnerabilities are among them.&lt;/p&gt;
&lt;p&gt;SAP traditionally sent acknowledgements for founded vulnerabilities to security researchers from DSecRG on their &lt;a href=&quot;http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a&quot;&gt;  acknowledgement page&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Detailed list of corrected vulnerabilities is below:&lt;/p&gt;
&lt;p&gt;&bull;	The most critical vulnerability is bypassing authentication and authorization mechanisms in one of the WEB applications. Update is available is sap note 1567389. Criticality according to CVSS is 6.4. &lt;/p&gt;
&lt;p&gt;&bull;	XSS vulnerability. Update is available in sap note 1591749. Criticality according to CVSS is 4.3.&lt;/p&gt;
&lt;p&gt;&bull;	SMBrelay vulnerability in one of reports. Update is available in sap note 1591146. Criticality according to CVSS is 3.4.&lt;/p&gt;
&lt;p&gt;It is highly recommended to patch all those issues to prevent business risks.&lt;/p&gt;
&lt;p&gt;Solutions for those issues are available in SAP Notes: 1567389, 1591749, 1591146&lt;/p&gt;
&lt;p&gt;Advisories for those issues with technical details will be available in 3 months on &lt;a href=&quot;http://www.erpscan.com/&quot;&gt;erpscan.com&lt;/a&gt; and also on &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG.com&lt;/a&gt; site.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=64</link>
<guid>http://dsecrg.com/pages/news/show.php?id=64</guid>
<title>ERPScan warns about new vulnerabilities of DIAG protocol in SAP</title>
<description>&lt;p&gt;SAP security topic gathers pace at the hacker conferences. Thus, at the recent &lt;a href=&quot;http://www.44con.com/&quot;&gt;44con&lt;/a&gt; conference employees of &lt;a href=&quot;http://www.sensepost.com/&quot;&gt;Sensepost Company&lt;/a&gt;  turned to the questions of &lt;a href=&quot;http://www.sap.com/index.epx&quot;&gt;SAP&lt;/a&gt; client applications&#8217; security, continuing previously started researches of &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG&lt;/a&gt; researchers. &lt;a href=&quot;http://www.sensepost.com/&quot;&gt;Sensepost&lt;/a&gt; employees made a presentation, where they showed a dissection of algorithm of data encryption of DIAG protocol, which is used for data transmission between &lt;a href=&quot;http://www.sap.com/index.epx&quot;&gt;SAP&lt;/a&gt; client and server. Theoretical possibility of data decoding was known in narrow group of people for a long time, but practical examples, except for interception of passwords, were not available for public use. &lt;a href=&quot;http://www.sensepost.com/&quot;&gt;Sensepost&lt;/a&gt; specialists published two utilities, allowing fully intercepting, decrypting and modifying client-server requests very fast, thereby opening the ways for different MITM attacks. The second utility works as Proxy and created mostly for the searching for new vulnerabilities, and allows modifying requests for client and server and searching for new vulnerabilities in handling by fuzzing method.&lt;/p&gt;
&lt;p&gt;So, it is possible that in the nearest future in the presence of such a powerful tool the amount of new vulnerabilities in &lt;a href=&quot;http://www.sap.com/index.epx&quot;&gt;SAP&lt;/a&gt; can significantly grow.&lt;/p&gt;
&lt;p&gt;Continuing topic about security of &lt;a href=&quot;http://www.sap.com/index.epx&quot;&gt;SAP&lt;/a&gt; client applications, we remind that there is a free service &lt;a href=&quot;http://online.erpscan.com/&quot;&gt;online.erpscan.com&lt;/a&gt;, developed by the &lt;a href=&quot;http://erpscan.com/&quot;&gt;ERPScan&lt;/a&gt; experts and allowing checking &lt;a href=&quot;http://www.sap.com/index.epx&quot;&gt;SAP&lt;/a&gt; Frontend on presence of the latest vulnerabilities.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=63</link>
<guid>http://dsecrg.com/pages/news/show.php?id=63</guid>
<title>SAP security threads at the worldwide conferences</title>
<description>&lt;p&gt;In the near future a series of worldwide conferences will take place, within which &lt;a href=&quot;http://erpscan.com&quot;&gt; ERPScan&lt;/a&gt; will present reports with new details about the latest vulnerabilities, found in SAP, and also will conduct trainings on SAP security. For example, at the Hack In The Box conference at Kuala Lumpur it will be shown how it is possible, aside from the control over the J2EE server which is available remotely and on which Portal or Solution Manager is usually located, to get access to Company internal resources and to the ERP system, even if it is closed by the firewalls.&lt;/p&gt;

&lt;p&gt;Recent events:&lt;/p&gt;
&lt;p&gt;6 September &ndash; &lt;a href=&quot;http://www.securitybyte.org/&quot;&gt; SecurityByte&lt;/a&gt; (India, Bangalore);&lt;/p&gt;
&lt;p&gt;19 September &ndash; &lt;a href=&quot;http://2011.brucon.org/index.php/Main_Page&quot;&gt; Brucon&lt;/a&gt;  (Belgium, Brussels);&lt;/p&gt;
&lt;p&gt;28-30 September &ndash; &lt;a href=&quot;http://www.infosecurityrussia.ru/&quot;&gt; InfosecurityRussia &lt;/a&gt; (Russia, Moscow);&lt;/p&gt;
&lt;p&gt;12 October -&lt;a href=&quot;http://conference.hitb.org/hitbsecconf2011kul/&quot;&gt;HITB KUL&lt;/a&gt; (Malaysia, Kuala Lumpur);&lt;/p&gt;
&lt;p&gt;25 October - &lt;a href=&quot;http://www.hackerhalted.com/2011/&quot;&gt;Hacker Halted&lt;/a&gt; (USA, Miami).&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=62</link>
<guid>http://dsecrg.com/pages/news/show.php?id=62</guid>
<title>Vulnerability detected in SAP got into the list of the most dangerous, presented at the recent BlackHat and Defcon conferences</title>
<description>
&lt;p&gt;Vulnerability detected by &lt;a href=&quot;http://dsecrg.ru&quot;&gt; DSecRG&lt;/a&gt; specialists (&lt;a href=&quot;http://erpscan.com&quot;&gt; ERPScan&lt;/a&gt; subdivision), allowing to manipulate HTTP headings for the authentication bypass in &lt;a href=&quot;http://sap.com&quot;&gt; SAP&lt;/a&gt; WEB applications, got into the list of the most dangerous threads presented at the recent &lt;a href=&quot;http://blackhat.com&quot;&gt; BlackHat&lt;/a&gt; and &lt;a href=&quot;http://defcon.com&quot;&gt; Defcon&lt;/a&gt; along with such researches as vulnerabilities in Siemens PLC, machine theft by the commands&#8217; emulation  via wireless interface,  remote  disconnection of  insulin pumps and other no less dangerous hacks.&lt;/p&gt;
&lt;a href=&quot;http://podcasts.infoworld.com/d/security/the-10-scariest-hacks-black-hat-and-defcon-170259?_kip_ipx=949115097-1314167837&quot;&gt;http://podcasts.infoworld.com/d/security/the-10-scariest-hacks-black-hat-and-defcon-170259?_kip_ipx=949115097-1314167837&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Because of the criticality of the detected vulnerability, ERPScan developed free utility &lt;a href=&quot;http://erpscan.com/products/erpscan-webxml-checker/&quot;&gt; ERPScan web.xml checker&lt;/a&gt;, which is a part of &lt;a href=&quot;http://erpscan.com&quot;&gt; ERPScan Security scanner for SAP&lt;/a&gt; and allows to check the J2EE security settings of SAP applications for the presence of 9 different configuration mistakes, what can help administrator to set the system securely by himself and understand, where the lacks are.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=61</link>
<guid>http://dsecrg.com/pages/news/show.php?id=61</guid>
<title>ERPScan participation in BlackHat and Defcon conferences</title>
<description>&lt;p&gt;Two world biggest conferences devoted to security aspects were held in Las-Vegas from 4 to 9 August; this event  gathered 8500 and 15000 visitors simultaneously. This year &lt;a href=&quot;http://erpscan.com&quot;&gt;ERPScan&lt;/a&gt; specialists gave a talk at  the &lt;a href=&quot;http://blackhat.com&quot;&gt; BlackHat&lt;/a&gt; and took part in &lt;a href=&quot;http://defcon.com&quot;&gt; Defcon CTF&lt;/a&gt; (Capture The Flag)  competition, where practical skills in reverse-engineering, exploitation, pen-tests and remote attacks defense were needed.&lt;/p&gt;
&lt;p&gt;The  team (IV) where our employee took part  won 4th place and left behind a lot of old school participants of this event. Such a result is great for the first time.
The report about new security threats in J2EE engine of SAP NetWeaver platform made by Alexander Polyakov  made noise in mass-media even before the presentation. So after the presentation that was high-rated by the audience and foreign colleagues, it was covered by world-famous editions like &lt;a href=&quot;http://www.cio.com/&quot;&gt;CIO&lt;/a&gt;, &lt;a href=&quot;http://www.pcworld.com/&quot;&gt;PCWORLD&lt;/a&gt;, &lt;a href=&quot;http://www.itproportal.com/&quot;&gt;ItProPortal&lt;/a&gt;, &lt;a href=&quot;http://www.cbronline.com/&quot;&gt;CbrOnline&lt;/a&gt; and also on &lt;a href=&quot;http://www.sdn.sap.com/irj/scn/weblogs?blog=/pub/wlg/25792&quot;&gt; the internal portal&lt;/a&gt; of SAP Company.&lt;/p&gt;

&lt;p&gt;Press attention was paid to the new vulnerability allowing manipulating with HTTP headers to avoid authentication in SAP web applications. Thus  by sending Head request instead of GET to the interface of one undocumented application you could execute any actions in the system. The example performed on the conference showed how the account with the administrative access was created by the anonymous request; that could be used by the attackers for getting critical data and full control over the system. Another vulnerable application gives the opportunity to execute DoS attack by rewriting any system file.&lt;/p&gt;
&lt;p&gt;At the moment SAP has closed only 2 examples of vulnerabilities of this type, but according to the results of our research there are about 40 potentially vulnerable SAP applications as well as user-made applications.&lt;/p&gt; 

&lt;p&gt;ERPScan has created free utility called &lt;a href=&quot;http://erpscan.com/products/erpscan-webxml-checker/&quot;&gt;ERPScan web.xml checker &lt;/a&gt; that is a part of ERPScan Security Scanner which helps to check J2EE SAP applications security settings; there are 9 different typical misconfigurations, so the analysis will help the administrator to securely tune the system and show if there are any flaws.&lt;/p&gt;

&lt;p&gt;After the talk Alexander was interviewed by &lt;a href=&quot;http://www.reuters.com/article/2011/08/05/us-sap-security-idUSTRE7740B420110805&quot;&gt;Reuters &lt;/a&gt; edition; he also commented on the situation with SAP security in &lt;a href=&quot;http://player.vimeo.com/video/27384573?title=0&amp;amp;byline=0&amp;amp;portrait=0&quot;&gt; video&lt;/a&gt; interview to Infosecland portal.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://erpscan.com/wp-content/uploads/2011/08/A_crushing_blow_at_the_heart_of_SAP_J2EE_Engine.pdf&quot;&gt;Presentation &lt;/a&gt; and &lt;a href=&quot;http://erpscan.com/wp-content/uploads/2011/08/A-crushing-blow-at-the-heart-SAP-J2EE-engine_whitepaper.pdf&quot;&gt;research details&lt;/a&gt;  in English are available on &lt;a href=&quot;http://erpscan.com&quot;&gt;ERPScan.com.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Links:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.sdn.sap.com/irj/scn/weblogs?blog=/pub/wlg/25792&quot;&gt;http://www.sdn.sap.com/irj/scn/weblogs?blog=/pub/wlg/25792&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.itproportal.com/2011/08/05/sap-vulnerability-dawns-at-black-hat/&quot;&gt;http://www.itproportal.com/2011/08/05/sap-vulnerability-dawns-at-black-hat/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.cio.com/article/687249/SAP_Will_Issue_Patch_for_NetWeaver_Vulnerability&quot;&gt;http://www.cio.com/article/687249/SAP_Will_Issue_Patch_for_NetWeaver_Vulnerability&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.pcworld.com/businesscenter/article/237373/sap_will_issue_patch_for_netweaver_vulnerability.html&quot;&gt; http://www.pcworld.com/businesscenter/article/237373/sap_will_issue_patch_for_netweaver_vulnerability.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.reuters.com/article/2011/08/05/us-sap-security-idUSTRE7740B420110805&quot;&gt; http://www.reuters.com/article/2011/08/05/us-sap-security-idUSTRE7740B420110805&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.darkreading.com/compliance/167901112/security/application-security/231003085/over-half-of-sap-servers-on-the-internet-are-vulnerable-to-attack-researcher-says.html&quot;&gt;http://www.darkreading.com/compliance/167901112/security/application-security/231003085/over-half-of-sap-servers-on-the-internet-are-vulnerable-to-attack-researcher-says.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://security.cbronline.com/news/security-expert-reveals-new-class-of-vulnerabilities-in-sap-software-050811&quot;&gt;http://security.cbronline.com/news/security-expert-reveals-new-class-of-vulnerabilities-in-sap-software-050811 &lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://podcasts.infoworld.com/d/security/the-10-scariest-hacks-black-hat-and-defcon-170259?_kip_ipx=949115097-1314167837&quot;&gt; http://podcasts.infoworld.com/d/security/the-10-scariest-hacks-black-hat-and-defcon-170259?_kip_ipx=949115097-1314167837&lt;/a&gt;&lt;/p&gt;


&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=60</link>
<guid>http://dsecrg.com/pages/news/show.php?id=60</guid>
<title>SAP critical patch update august 2011</title>
<description>&lt;p&gt;&lt;a href=&quot;http://sap.com&quot;&gt;SAP&lt;/a&gt; Company has released august monthly set of updates. This set of updates closes more than 40 vulnerabilities is SAP products, 7 of which were found by outsider researchers.&lt;/p&gt;
&lt;p&gt;In this set 5 vulnerabilities were found by &lt;a href=&quot;http://www.dsecrg.com&quot;&gt;DSecRG&lt;/a&gt; employees.&lt;/p&gt;

&lt;p&gt;SAP Company traditionally gave thanks to DSecRG researchers for the found vulnerabilities and promotion for its closure on their portal.
&lt;p&gt;The set of updates consists of patches for a number of dangerous vulnerabilities, including those which were published at the recent &lt;a href=&quot;http://www.blackhat.com&quot;&gt;BlackHat&lt;/a&gt; conference in Las Vegas. Detailed list of corrected vulnerabilities is below:
&lt;p&gt;&bull;	The most critical vulnerability is bypassing authentication and authorization mechanisms in JAVA engine and as the result &ndash; getting administrator rights on the server. Update is available is sap note 1589525. Criticality according to CVSS is 10. Priority is 1 according to SAP metrics.&lt;/p&gt;
&lt;p&gt;&bull;	Possibility of creating a user in a system with any rights via CSRF attack. Update is available in sap note 1616058. Criticality according to CVSS is 7.8. Priority is 1 according to SAP metrics.&lt;/p&gt;
&lt;p&gt;&bull;	Implementation of random code of OS via vulnerable RFC module. Update is available in sap note 1580017. Criticality according to CVSS is 6.0. Priority is 2 according to SAP metrics.&lt;/p&gt;
&lt;p&gt;&bull;	XSS in SAP BW. Update is available in sap note 1572325. Criticality according to CVSS is 4.3. Priority is 2 according to SAP metrics.&lt;/p&gt;
&lt;p&gt;&bull;	SMBrelay vulnerability in one of reports. Update is available in sap note 1583286. Criticality according to CVSS is 2.3. Priority is 2 according to SAP metrics.&lt;/p&gt;

&lt;p&gt;Details of two first mentioned vulnerabilities and also other information about J2EE applications security of SAP platform are available in the document &lt;a href=&quot;http://erpscan.com/wp-content/uploads/2011/08/A-crushing-blow-at-the-heart-SAP-J2EE-engine_whitepaper.pdf&quot;&gt;http://erpscan.com/wp-content/uploads/2011/08/A-crushing-blow-at-the-heart-SAP-J2EE-engine_whitepaper.pdf&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;It is highly recommended to download the updates which close the given vulnerabilities.
The information about updates is available from the following SAP notes: 1589525, 1616058, 1580017, 1572325, 1583286&lt;/p&gt;

&lt;p&gt;Recommendations disclosing technical details of these vulnerabilities will be available in 3 months at &lt;a href=&quot;http://www.erpscan.com&quot;&gt;erpscan.com&lt;/a&gt; and &lt;a href=&quot;http://www.dsecrg.com&quot;&gt;DSecRG.com&lt;/a&gt; . Verifications on presence of these vulnerabilities are available at &lt;a href=&quot;http://erpscan.com&quot;&gt;ERPScan Security Scanner for SAP&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=59</link>
<guid>http://dsecrg.com/pages/news/show.php?id=59</guid>
<title>Next week a half of SAP systems, available in Internet, can be hacked</title>
<description>&lt;p&gt;On the 4th of august at the world  largest technical security  conference - &lt;a href=&quot;https://www.blackhat.com/&quot;&gt;BlackHat USA 2011&lt;/a&gt;, which will take place in Las Vegas, SAP security expert and CTO of &lt;a href=&quot;http://erpscan.com//&quot;&gt;ERPScan&lt;/a&gt; Alexander Polyakov will show how any malicious attacker can get access to the systems running on  SAP via Internet using new  critical  vulnerability.&lt;/p&gt;
                &lt;p&gt;SAP systems are used in more than 100 000 world companies to handle business-critical data and processes. Almost in each company from Forbes 500 system data are set for the handling of any process beginning from purchasing, human resources and financial reporting and ending with communication with other business systems. Thus receiving an access by the malicious attacker leads to complete control over the financial flow of the company, which can be used for espionage, sabotage and fraudful actions against hacked company.&lt;/p&gt;
           &lt;p&gt; The given attack is possible due to dangerous vulnerability of the new type, detected by Alexander in J2EE engine of SAP NetWeaver software, which allows bypassing authorization checks. For example it is possible to create a user and assign him to the administrators group using two unauthorized requests to the system.  It is also dangerous because that attack is possible on systems, protected by the two-factor authentication systems, in which it is needed to know secret key and password to get access.
To prove it researchers from ERPScan created a program, which detects SAP servers in the Internet with help of secret Google keyword and checks found servers on potential dangerous vulnerability. As the result, more than half of available servers could be hacked with help of found vulnerability.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;&#8219;Danger is in that it is not only a new vulnerability, but a whole class of vulnerabilities that was theoretically described earlier but not popular in practice. During our research we only detected several examples in standard system configuration, and because each company customizes the system under its own business processes, new examples of vulnerabilities of the given class can be potentially detected at each company in the future. We have developed a free program which can detect unique vulnerabilities of such type in order to protect companies on time and it is also included in our professional product &ndash; ERPScan Security Scanner for SAP.&#8220;&lt;/i&gt; &mdash; noted Alexander.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=58</link>
<guid>http://dsecrg.com/pages/news/show.php?id=58</guid>
<title>SAP critical patch update july 2011 </title>
<description>&lt;p&gt;SAP released monthly critical patch update for july 2011. This patch update closes about 40 vulnerabilities in SAP products. 9 of those vulnerabilities were founded by different experts. Traditionnaly  DSecRG researchers Dmitriy Chastuhin and Dmitriy Evdokimov who found 2 vulnerabilities are among them.&lt;/p&gt;
&lt;p&gt;SAP traditionally sent acknowledgements for founded vulnerabilities to security researchers from DSecRG on their &lt;a href=&quot;http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a&quot; target=&quot;_blank&quot;&gt;acknowledgement page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Most critycal vulnerability are found in BAPI component and can be exploited to execute unwanted functions without authorization. Malicious user may use this to impersonate the user on the front-end system and access all information with the same rights as the target user.&lt;/p&gt;
&lt;p&gt;It is highly recommended to patch all those issues to prevent business risks.&lt;/p&gt;
&lt;p&gt;Solutions for those issues are available in SAP Notes: 546307, 1599550.&lt;/p&gt;
&lt;p&gt;Advisories for those issues with technical details will be available in 3 months on &lt;a href=&quot;http://erpscan.com/category/advisories/&quot; target=&quot;_blank&quot;&gt;erpscan.com&lt;/a&gt; and also on &lt;a href=&quot;http://dsecrg.com/pages/vul/&quot; target=&quot;_blank&quot;&gt;DSecRG.com&lt;/a&gt; site.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=57</link>
<guid>http://dsecrg.com/pages/news/show.php?id=57</guid>
<title>DSecRG researchers invited to present at BlackHat and take part at Defcon CTF</title>
<description>CTO at &lt;a href=&quot;http://erpscan.com&quot;&gt;ERPScan&lt;/a&gt; and the Head of&amp;nbsp; &lt;a href=&quot;http://dsecrg.com&quot;&gt;DSecRG&lt;/a&gt; Research Center Alexander Polyakov was once again invited to&amp;nbsp;the &lt;a href=&quot;https://www.blackhat.com/&quot;&gt;BlackHat&lt;/a&gt; conference, which will take place in&amp;nbsp;Las Vegas, to&amp;nbsp;make a&amp;nbsp;presentation about newest attacks on&amp;nbsp;JAVA-kernel of&amp;nbsp;SAP system, which is&amp;nbsp;used in&amp;nbsp;such applications as&amp;nbsp;SAP Portal. &lt;/p&gt;
&lt;p&gt;BlackHat conference has been held since 1997 and collects more than 10,000 visitors at&amp;nbsp;the annual briefing in&amp;nbsp;Las-Vegas and is&amp;nbsp;the main event in&amp;nbsp;the world of&amp;nbsp;information security, some kind of&amp;nbsp;Mecca for technical specialists, pentesters, auditors, researchers, hackers, students of&amp;nbsp;technical universities, SCO's of&amp;nbsp;the largest companies and people who are somehow related to&amp;nbsp;hacking and security, which are the most actual information security questions for today.&lt;/p&gt;
&lt;p&gt;BlackHat conference is&amp;nbsp;famous for the presentation of&amp;nbsp;the latest researches and unique, unknown before attacks. The leading researchers from all over the world tell about these attacks. This year there will be researchers from &amp;nbsp;NSA, U.S. Army, Carnegie Mellon University, Stanford, Intel, IBM, Symantec, McAfee, Qualys, Verizon, Rapid7 and other companies and organisations.&lt;/p&gt;
&lt;p&gt;Moreover, DSecRG employees joined the team &amp;quot;IV&amp;laquo;,which got the fourth place in &lt;a href=&quot;https://www.defcon.org/&quot;&gt; Defcon CTF&lt;/a&gt; international competitions. The team called &amp;laquo;IV&amp;raquo; (&amp;laquo;four&amp;raquo;) is&amp;nbsp;a&amp;nbsp;combined team of&amp;nbsp;four teams&amp;nbsp;&amp;mdash; &amp;laquo;Leet More&amp;raquo;, &amp;laquo;Smoked Chicken&amp;raquo;, &amp;laquo;SiBears&amp;raquo;, &amp;laquo;HackerDom&amp;raquo;. As&amp;nbsp;the result of&amp;nbsp;hard and difficult qualifying games the team managed to&amp;nbsp;take 4th place and get to&amp;nbsp;the finale, which will take place at&amp;nbsp;the Defcon conference in&amp;nbsp;Las-Vegas. It&amp;nbsp;is&amp;nbsp;worth noting that the captain of&amp;nbsp;the &amp;laquo;Leet More&amp;raquo; team&amp;nbsp;&amp;mdash; Alexander Minozhenko, an&amp;nbsp;employee of DSecRG (Research center of ERPScan).&lt;/p&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=56</link>
<guid>http://dsecrg.com/pages/news/show.php?id=56</guid>
<title>SAP critical patch update june 2011</title>
<description>&lt;p&gt;SAP released monthly critical patch update for june 2011. This patch updates close about 40 vulnerabilities in SAP products. 10 of those vulnerabilities were founded by different experts. Traditionnaly  DSecRG researcher Dmitriy Chastuhin who found 2 vulnerabilities is among them.&lt;/p&gt;
&lt;p&gt;SAP traditionally send acknowledgements for founded vulnerabilities to security researchers from DSecRG on their &lt;a href=&quot;http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a&quot; target=&quot;_blank&quot;&gt;acknowledgement page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Both vulnerabilities have medium security level (5.0 and 4.3 by CVSS). Vulnerabilities are found in SAP NetWeaver J2EE Engine and can give attacker access to user's session.&lt;/p&gt;
&lt;p&gt;It is highly recommended to patch all those issues to prevent business risks.&lt;/p&gt;
&lt;p&gt;Solutions for those issues are available in SAP Notes: 1545883, 1562292.&lt;/p&gt;
&lt;p&gt;Advisories for those issues with technical details will be available in 3 months on &lt;a href=&quot;http://erpscan.com/category/advisories/&quot; target=&quot;_blank&quot;&gt;erpscan.com&lt;/a&gt; and also on &lt;a href=&quot;http://dsecrg.com/pages/vul/&quot; target=&quot;_blank&quot;&gt;DSecRG.com&lt;/a&gt; site.&lt;/p&gt;

&lt;p&gt;We also published details about vulnerabilities that were closed 3 month ago in march 2011&lt;/p&gt;&lt;br&gt;

&lt;a href=&quot;http://erpscan.com/?p=1631&quot;&gt;DSECRG-11-023&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://erpscan.com/?p=1634&quot;&gt;DSECRG-11-024&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://erpscan.com/?p=1637&quot;&gt;DSECRG-11-025&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://erpscan.com/?p=1639&quot;&gt;DSECRG-11-026&lt;/a&gt;&lt;br&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=55</link>
<guid>http://dsecrg.com/pages/news/show.php?id=55</guid>
<title>Critical vulnerabilities in Oracle Business Intelligence applications are found out by DSecRG experts.</title>
<description>&lt;p&gt;Vulnerability allows the legitimate user of business analytics system to raise the privileges up to the administrative level, and also to get access to an operating system and to all critical for business data.&lt;/p&gt;

&lt;p&gt;&#8219;The patch for founded vulnerability was released in April, but we decided to give to users two more months on installation of the given updating before publishing an exploit code.&lt;/p&gt;

&lt;p&gt;The given research was held by DSecRG in the field of business applications security research  and working out of the  ERPScan Security Scanner, aimed at business applications security audit, which is at present realized for SAP system security assessment&#8220; &ndash; commented Alexander Polyakov CTO at ERPScan  and the head of DSecRG research center.&lt;/p&gt;

&lt;p&gt;Additional information about exploiting Oracle BI can be found on DSecRG blog:
&lt;a href=http://dsecrg.blogspot.com/2011/06/hacking-oracle-business-intellegence.html&gt;http://dsecrg.blogspot.com/2011/06/hacking-oracle-business-intellegence.html&lt;/a&gt;&lt;/p&gt;


&lt;p&gt;Details about vulnerabilities are available on the following websites:
 &lt;a href=http://erpscan.com&gt;http://erpscan.com&lt;/a&gt; and  &lt;a href=http://dsecrg.com&gt;http://dsecrg.com&lt;/a&gt;:&lt;/p&gt;

&lt;a href=http://erpscan.com/advisories/dsecrg-11-021-oracle-bi-%E2%80%94-wb_olap_aw_remove_solve_id-%E2%80%93-%D0%BF%D0%BE%D0%B2%D1%8B%D1%88%D0%B5%D0%BD%D0%B8%D0%B5-%D0%BF%D1%80%D0%B8%D0%B2%D0%B8%D0%BB%D0%B5%D0%B3%D0%B8%D0%B9/&gt;http://erpscan.com/advisories/dsecrg-11-021-oracle-bi-%E2%80%94-wb_olap_aw_remove_solve_id-%E2%80%93-%D0%BF%D0%BE%D0%B2%D1%8B%D1%88%D0%B5%D0%BD%D0%B8%D0%B5-%D0%BF%D1%80%D0%B8%D0%B2%D0%B8%D0%BB%D0%B5%D0%B3%D0%B8%D0%B9/
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=54</link>
<guid>http://dsecrg.com/pages/news/show.php?id=54</guid>
<title>SAP Critical Patch Update for May 2011</title>
<description>&lt;p&gt;SAP released monthly critical patch update for May 2011. This patch updates close 10 public vulnerabilities in SAP products. 2 of those vulnerabilities were founded by DSecRG researchers Alexey Sintsov and Dmitriy Evdokimov.&lt;/p&gt;
&lt;p&gt;SAP traditionally send acknowledgements for founded vulnerabilities to security researchers from DSecRG on their &lt;a href=&quot;http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a&quot; target=&quot;_blank&quot;&gt;acknowledgement page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The most critical one is missing authorization check vulnerability in one of the RFC modules which can lead to privilege escalation and SMB relay attacks (priority 2 according to SAP metrics). Second vulnerability is XSS in one of the Java application.&lt;/p&gt;
&lt;p&gt;It is highly recommended to patch all those issues to prevent business risks.&lt;/p&gt;
&lt;p&gt;Solutions for those issues are available in SAP Notes: 1554030, 1553292.&lt;/p&gt;
&lt;p&gt;Advisories for those issues with technical details will be available in 3 months on &lt;a href=&quot;http://erpscan.com/category/advisories/&quot; target=&quot;_blank&quot;&gt;erpscan.com&lt;/a&gt; and also on &lt;a href=&quot;http://dsecrg.com/pages/vul/&quot; target=&quot;_blank&quot;&gt;DSecRG.com&lt;/a&gt; site.&lt;/p&gt;  
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=53</link>
<guid>http://dsecrg.com/pages/news/show.php?id=53</guid>
<title>SAP Critical patch update April 2011  </title>
<description>SAP released monthly critical patch update for April 2011. This patch updates close 8 public vulnerabilities in SAP products.  3 of those vulnerabilities were founded by DSecRG researchers. &lt;br&gt; SAP traditionally send acknowledgements for founded vulnerabilities to security researchers from DSecRG on their &lt;a href=&#8220;http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a&#8220;&gt;acknowledgement page&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
The most critical one is critical unauthorized information disclose and memory corruption in SAP Kernel  which have CVSS score 7.5 (priority 1 according to SAP metrics). Others are cross-site scripting vulnerabilities in SAP NetWeaver.&lt;br&gt;&lt;br&gt;
It is highly recommended to patch all those issues to prevent business risks.&lt;br&gt;&lt;br&gt;
Solutions for those issues are available in sap notes: 

1548548 1543318 1442517&lt;br&gt;&lt;br&gt;

Advisories for those issues with technical details will be available in 3 months on &lt;a href=&quot;http://erpscan.com&quot;&gt;erpscan.com&lt;/a&gt; and also on &lt;a href=&quot;http://dsecrg.com/pages/vul/&quot;&gt;DSecRG.com&lt;/a&gt; site.  
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=50</link>
<guid>http://dsecrg.com/pages/news/show.php?id=50</guid>
<title>SMBRealay Bible blog series overview part one</title>
<description>About 2 month ago we started our new blog series about &lt;a href=&#8220;http://dsecrg.blogspot.com/search/label/SMBRelay%20bible&#8220;&gt;smbrelay attacks&lt;/a&gt;.&lt;br&gt;&lt;br&gt;

&lt;i&gt;&#8219;&hellip;The goal of this encyclopedia is to collect all possibilities of obtaining NTLM authentication for conducting SMB-relay attacks or stealing credentials. We are often using those methodologies in different penetration testing and business- application security assessments and decide to collect all this information in one place. It is very useful area in penetration tests and great example of tactical exploitation methodologies because you don&#8217;t need to use any exploit to get full access in corporate network, just pass and relay!&#8220;&lt;/i&gt; - from first post.&lt;br&gt;&lt;br&gt;

Since the first announcement we had published 5 blog posts describing different areas which can be attacked from ERP and Database to Security products like Kaspersky AV and client-side attacks.We also get many feedback and some reposts (thanks to &lt;a href=&quot;http://www.blogger.com/profile/11458732726033638737&quot;&gt;marcello&lt;/a&gt;).&lt;br&gt;

&lt;b&gt;You can read it all here:&lt;/b&gt;&lt;br&gt;&lt;br&gt;

&lt;a href='http://dsecrg.blogspot.com/2011/04/smbrelay-bible-5-smbrelay-attacks-on.html'&gt;SMBRelay Bible 5: SMBRelay attacks on corporate users&lt;/a&gt;&lt;br&gt;&lt;br&gt;

&lt;a href='http://dsecrg.blogspot.com/2011/03/smbrelay-bible-4-smbrelay-with-no.html'&gt;SMBRelay Bible 4: SMBrelay with no action or attacking security software ( Kaspersky AV,Symantec DLP, GFI Languard 0-days)&lt;/a&gt;&lt;br&gt;&lt;br&gt;

&lt;a href='http://dsecrg.blogspot.com/2011/03/smbrelay-bible-3-smbrelay-by-oracle.html'&gt;SMBRelay bible 3: SMBRelay by Oracle&lt;/a&gt;&lt;br&gt;&lt;br&gt;

&lt;a href='http://dsecrg.blogspot.com/2011/02/smbrelay-bible-2-smbrelay-by-ms-sql.html'&gt;SMBRelay bible 2: SMBRelay by MS SQL server&lt;/a&gt;&lt;br&gt;&lt;br&gt;

&lt;a href='http://dsecrg.blogspot.com/2011/01/passthehash-bible-1-attacking.html'&gt;SMBRelay bible 1: Attacking Enterprise business (ERP)&lt;/a&gt;&lt;br&gt;&lt;br&gt;

&lt;a href=&#8220;http://dsecrg.blogspot.com/2011/01/new-blog-section-passthehash-bible.html&#8220;&gt;New blog section: SMBRelay Bible&lt;/a&gt;&lt;br&gt;&lt;br&gt;



We still have many interesting attacks unpublished end will publish them in near future. So say thanks to  main contributors of this topic: Alexey Tyurin and &lt;a href=&quot;http://twitter.com/asintsov&quot;&gt;Alexey Sintsov  and keep watching on our blog! Don&#8217;t miss. 
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=52</link>
<guid>http://dsecrg.com/pages/news/show.php?id=52</guid>
<title>SAP Critical patch update march 2011</title>
<description>SAP released monthly critical patch update for April 2011. This patch updates close 7 public vulnerabilities in SAP products.  4 of those vulnerabilities were founded by DSecRG researchers Alexander Polyakov and Dmitriy Evdokimov .&lt;br&gt; SAP traditionally send acknowledgements for founded vulnerabilities to security researchers from DSecRG on their &lt;a href=&#8220;http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a&#8220;&gt;acknowledgement page&lt;/a&gt;.&lt;br&gt;&lt;br&gt;

The most critical one is authentication bypass that can be exploited remotely to gain unauthorized access to SAP NetWeaver systems which have CVSS score 9.0 (priority 1 according to SAP metrics). Others are cross-site scripting and information disclosure vulnerabilities in SAP NetWeaver. &lt;br&gt;&lt;br&gt;
It is highly recommended to patch all those issues to prevent business risks.&lt;br&gt;&lt;br&gt;
Solutions for those issues are available in sap notes: 
1503579, 1503856,1475767, 1486679&lt;br&gt;&lt;br&gt;
Advisories for those issues with technical details will be available in 3 month on &lt;a href=&quot;http://erpscan.com&quot;&gt;erpscan.com&lt;/a&gt; and also on &lt;a href=&quot;http://dsecrg.com/pages/vul/&quot;&gt;DSecRG.com&lt;/a&gt; site.  
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=49</link>
<guid>http://dsecrg.com/pages/news/show.php?id=49</guid>
<title>Espionage, sabotage and fraudful actions:  about attacks on ERP &ndash; systems on the BlackHat DC conference</title>
<description>&lt;div style=&quot;text-align:justify&quot;&gt;
&lt;p&gt;During the &lt;a href=&quot;http://www.blackhat.com/html/bh-dc-11/bh-dc-11-home.html&quot;&gt; BlackHat DC conference&lt;/a&gt;  &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG&lt;/a&gt; experts have told about attacks on corporate business-applications which can be used by cybercriminals for espionage, sabotage and fraudful actions concerning competitors.  At the conference unknown earlier methods of attacks were presented on popular ERP-systems, such as SAP, JD Edwards, and also on RDBMS Open Edge, which is a universal platform for development custom business-applications.&lt;/p&gt;

&lt;p&gt;Despite of the fact, such companies like SAP and Oracle, regularly release security  updates in their products, they still are a subject for attacks, pointed  on architectural vulnerabilities and configuration errors.  In the &lt;a href=&quot;http://dsecrg.com/pages/pub/show.php?id=35&quot;&gt;report&lt;/a&gt; of Alexander Polyakov, and Head of DSecRG, the attention was paid to the architectural vulnerabilities of the listed systems, different methods of exploitation of these vulnerabilities were shown. Given vulnerabilities in the majority are hard to patch, and it entails the possibility of their exploitation in future. &lt;/p&gt;

&lt;p&gt;&lt;i&gt;&#8219;Very few administrators of SAP-systems install updates regularly, and extremely few people who deeply understand technical details of ERP-systems, in the best limiting by SOD problems. That is why we see insecurely configured systems as the result of security assessments&#8220; &lt;/i&gt;, - stated &lt;b&gt;Alexander Polyakov.&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;There is an example in his report when during audit there was found JD Edwards system of one decade&#8217;s prescription version, which had an architectural vulnerability, allowing any user to get access to all business-critical data. This vulnerability still exist in 2-tier installation with fat client. Another example of architectural vulnerability was found in RDBMS &#8219;Open Edge&#8220;, which is used in many companies from the list &#8219;Fortune TOP 100 companies&#8220;. In this application the trivial error takes place during authentification. Verification  of a password&#8217;s hash was implemented on the client side (part), therefore the authentification in system is possible, without knowing the password and the user name. The problem is that such vulnerability won&#8217;t be corrected by the manufacturer because of the necessity of the rewriting of all architecture. &lt;/p&gt;

&lt;p&gt;Another example is a system SAP SRM, which is used among all other for the organization of tenders&#8217; system. As a result of one architectural misconfiguration any supplier can get access to tenders of others suppliers, and also upload the Trojan program to a competitor network, that may be used for an industrial espionage..&lt;/p&gt;

&lt;p&gt;&lt;i&gt;&#8219;The majority of the examples considered in the report tells us that security of ERP-applications is at level of one decade&#8217;s prescription and with the trend to post business-applications on the Internet for exchanging data between branches of companies or suppliers all these systems became accessible to a wide range of people seeking to use these loopholes for personal purpose. Till now the companies spent millions of dollars, eliminating SOD conflicts, and though it is an integral part of the ERP security, the amount of technical vulnerabilities is growing exponentially, as an interest of attackers to these systems&#8220;&lt;/i&gt;, &#8220; &ndash; noted  &lt;b&gt;Alexander Polyakov.&lt;/b&gt;&lt;/p&gt;

&lt;/div&gt;


&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=48</link>
<guid>http://dsecrg.com/pages/news/show.php?id=48</guid>
<title>Oracle released Critical Patch Updates Advisory - January  2011</title>
<description>In this &lt;a href=&quot;http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html&quot;&gt;CPU&lt;/a&gt; Oracle gives recognition to four DSecRG experts for founded security vulnerabilities in business applications.&lt;br&gt;&lt;br&gt;Recognitions goes to Alexander Polyakov, Alexey Sintsov, Dmitriy Evdokimov and Andrey Labunets. This is our third year of getting recognitions from Oracle.&lt;br&gt;&lt;br&gt;

There were published multiple vulnerabilities in Oracle Document Capture and Peoplesoft application that can be found  &lt;a href=&quot;http://dsecrg.com/pages/vul/&quot;&gt;here&lt;/a&gt;

&lt;br&gt;&lt;br&gt;Earlier DSecRG received recognitions 8 times from January 2008&lt;br&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=47</link>
<guid>http://dsecrg.com/pages/news/show.php?id=47</guid>
<title>DSecRG Performance in 2010</title>
<description>&lt;div style=&quot;text-align: justify&quot;&gt;2010 &ndash; the third year of DSecRG public work has come to an end. This year was quite complicated, but very productive. In 2010 multiple vulnerabilities were found, though the amount of vulnerabilities published is less than previously as the vendors have not yet introduced updates allowing their disclosure. Moreover, vulnerabilities have become more critical and diversified, while the scope of applications under research was broadened with banking software and new ERP systems.&lt;br&gt; 
Significant research expertise in several areas was accumulated within these three years, and what is important for goal setting and continuous advancement is that there have been worked out the core research area &ndash; thus we are going to proceed. The main research area is business-critical systems, applications and technologies, and among them we are making research under ERP systems, corporate DBMS, as well as banking and processing software. This year we have turned our attention to SCADA and technological system security as one of the current research areas, making a review of &lt;a href=&quot;http://dsec.ru/about/articles/stuxnet/&quot;&gt;Stuxnet&lt;/a&gt;.&lt;br&gt;  
During the last year apart from vulnerability research and their publication we were frequently invited to speak at international conferences. The talks were given at 8 European and Asian information security conferences known worldwide:&lt;br&gt;&lt;br&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://party10.cc.org.ru/&quot;&gt;Chaos Constructions&#8217; 2010&lt;/a&gt; in St.Petersburg, Russia &ndash; &lt;i&gt;&lt;a href=&quot;http://dsecrg.ru/pages/pub/show.php?id=28&quot;&gt;Defeating Windows security (ROP)&lt;/a&gt;&lt;/i&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://troopers10.org/content/&quot;&gt;Troopers10&lt;/a&gt; in Heidelberg, Germany &ndash; &lt;i&gt;&lt;a href=&quot;http://dsecrg.com/pages/pub/show.php?id=29&quot;&gt;Some Notes on SAP Security&lt;/a&gt;&lt;/i&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://2010.confidence.org.pl/&quot;&gt;CONFidence 2010&lt;/a&gt; in Krakow, Poland &ndash; &lt;a href=&quot;http://dsecrg.com/pages/pub/show.php?id=25&quot;&gt;&lt;i&gt;You can&#8217;t stop us: latest trends on exploit techniques&lt;/i&gt;&lt;/a&gt;,&lt;/li&gt; 
&lt;li&gt;&lt;a href=&quot;https://conference.hackinthebox.org/hitbsecconf2010ams/&quot;&gt;Hack In The Box 2010 in Amsterdam, The Netherlands &ndash; &lt;a href=&quot;http://dsecrg.com/pages/pub/show.php?id=27&quot;&gt;&lt;i&gt;Attacking SAP Users with Sapsploit&lt;/i&gt;&lt;/a&gt; and &lt;a href=&quot;http://dsecrg.com/pages/pub/show.php?id=26&quot;&gt;&lt;i&gt;JIT-Spray Attacks and Advanced Shellcode&lt;/i&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.sourceconference.com/barcelona/speakers_2010.asp&quot;&gt;Source Barcelona&lt;/a&gt; 2010 in Barcelona, Spain &ndash; &lt;a href=&quot;http://dsecrg.com/pages/pub/show.php?id=30&quot;&gt;&lt;i&gt;ERP Security. Myths, Problems, Solutions&lt;/i&gt;&lt;/a&gt;,&lt;/li&gt; 
&lt;li&gt;&lt;a href=&quot;https://conference.hackinthebox.org/hitbsecconf2010kul/&quot;&gt;Hack In The Box 2010&lt;/a&gt; in Kuala-Lumpur, Malaysia &ndash; &lt;a href=&quot;http://dsecrg.com/pages/pub/show.php?id=33&quot;&gt;&lt;i&gt;Attacking SAP users with sapsploit Extended&lt;/i&gt;&lt;/a&gt;,&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://deepsec.net/&quot;&gt;DEEPSEC 2010&lt;/a&gt; in Vienna, Austria &ndash; &lt;a href=&quot;http://dsecrg.com/pages/pub/show.php?id=34&quot;&gt;&lt;i&gt;Attacking SAP Users with Sapsploit Extended 1.1&lt;/i&gt;&lt;/a&gt;,&lt;/li&gt; 
&lt;li&gt;&lt;a href=&quot;http://201002.confidence.org.pl/&quot;&gt;CONFidence 2.0 2010&lt;/a&gt; in Prague, Czech Republic &ndash; &lt;i&gt;Stupid Mistakes. Architecture and Business Logic Vulnerabilities&lt;/i&gt;.&lt;/li&gt;&lt;/ul&gt;
&lt;br&gt;
Speaking at these conferences enabled us to share our new results of research work with international community, get to know many experts, and broaden the outlook regarding new methods and technologies.&lt;br&gt;
The report and research work in 2010 was mostly dedicated to SAP security. Since September 2010 we started receiving official monthly &lt;a href=&quot;http://dsecrg.com/pages/news/show.php?id=38&quot;&gt;acknowledgements&lt;/a&gt; (at &lt;a href=&quot;http://sdn.sap.com&quot;&gt;http://sdn.sap.com&lt;/a&gt;) for the vulnerabilities found in security updates, keeping up the leadership in the quantity of the vulnerabilities found. Moreover we launched free service that helps SAP users assess their awareness level and security level of the SAP GUI client software and new NetWeaver Business Client. The service at &lt;a href=&quot;http://erpscan.com&quot;&gt;http://erpscan.com&lt;/a&gt; will be updated and completed with the latest vulnerabilities and new analyzed software.&lt;br&gt;
What concerns business application security, in 2010 we started taking part in OWASP and now we are working under the &lt;a href=&quot;http://www.owasp.org/index.php/Category:OWASP_Enterprise_Application_Security_Project#tab=Main&quot;&gt;OWASP_EAS&lt;/a&gt; project dedicated to enterprise business applications. Speaking about banking security we continued annual &lt;a href=&quot;http://dsecrg.com/pages/news/show.php?id=37&quot;&gt;Bank-Client&lt;/a&gt; security analysis of popular Russian software.
&lt;br&gt;&lt;br&gt;

&lt;b&gt;Facts of interest&lt;/b&gt;&lt;br&gt;&lt;br&gt;

&lt;ul&gt;&lt;li&gt;We support our blog and our plan for the next year is to add several columns, thus significantly extending its content;&lt;/li&gt; 
&lt;li&gt;All of us registered on Twitter to get instant access to current news and enhance its distribution;&lt;/li&gt;
&lt;li&gt;Our four experts are writing articles and several columns for the Hacker magazine;&lt;/li&gt;
&lt;li&gt;New research groups started springing up in Russia following DSecRG;&lt;/li&gt;
&lt;li&gt;Our page &lt;a href=&quot;http://dsecrg.com/pages/about/&quot;&gt;About&lt;/a&gt; and name are copied by young researchers from various countries.&lt;/li&gt;&lt;/ul&gt;
&lt;br&gt;
&lt;b&gt;Prospects&lt;/b&gt;&lt;br&gt;&lt;br&gt;

New year 2011 is starting for us on January 18, the day we will speak at the top-ranked information security conference &ndash; &lt;a href=&quot;http://dsecrg.com/pages/news/show.php?id=45&quot;&gt;BlackHat DC 2011&lt;/a&gt; held in Virginia, USA. We will talk about our research work within ERP security and demonstrate the difference in the approach towards the common pentest and the pentest aimed at critical business applications (security analysis) at the same time drawing examples of different vulnerabilities and misconfigurations in the architecture. In addition we will keep on speaking at various conferences during the whole year.
This year most of the projects have been implemented and considering the fact that the main efforts have turned to development of our ERPScan security scanner for SAP systems, this year has proved to be very fruitful.&lt;/div&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=45</link>
<guid>http://dsecrg.com/pages/news/show.php?id=45</guid>
<title>DSecRG will give a talk at BlackHat DC 2011 </title>
<description>&lt;div style=&quot;text-align: justify&quot;&gt;The annual &lt;a href=&quot;https://www.blackhat.com&quot;&gt;BlackHat DC&lt;/a&gt; conference is held in Virginia, USA 16-19 January. This is the most prominent event in information security around the world, where the newest research trends of attack and security constantly spoken about.&lt;br&gt;&lt;br&gt;

This year &lt;a href=&quot;http://twitter.com/sh2kerr&quot;&gt;Alexander Polyakov&lt;/a&gt;, CTO of Digital Security and Head of DSecRG together with Val Smith from &lt;a href=&quot;http://www.attackresearch.com&quot;&gt;AttackResearch&lt;/a&gt; will give a talk at the conference. The event is a breakthrough for Russian experts as there were no speakers representing Russian market of information security consulting before.&lt;br&gt;&lt;br&gt;

&lt;b&gt;Agenda:&lt;/b&gt;
&lt;br&gt;&lt;i&gt;
&#8219;Do you know where all the critical company data is stored? Do you know how easily you can be attacked by cybercriminals targeting this data? How can an attacker sabotage or commit espionage against your company having access just to one system? This paper will describe some basic and advanced threats and attacks on Enterprise Business Applications &ndash; the core of many companies.&#8220;
&lt;/i&gt;&lt;/br&gt;&lt;br&gt;

The talk will be about enterprise business applications, the way attackers can gain access to critical business data, steal money or disable technological corporate network like SCADA, using vulnerabilities and misconfigurations in the architecture of business applications. We will show the examples of various business applications including custom ones as well as the more popular ones, like SAP and JD Edwards and previously unknown vulnerabilities and attack methods that can be exploited not just for popping a shell, but to gain unauthorized access to business-critical data. These attack methods can also be useful in penetration tests against ERP systems. Many problems that will be shown cannot be easily patched because they are design flaws or business logic problems requiring re-design of a system. 
&lt;br&gt;&lt;br&gt;


After this talk people will understand the differences in approaches for pentesting standard networks and business-critical systems. &lt;br&gt;&lt;br&gt;

There will be drawn ERP-systems known in Russia and worldwide, as an example.&lt;br&gt;&lt;br&gt; &lt;a href=&quot;https://www.blackhat.com/html/bh-dc-11/bh-dc-11-speaker_bios.html#Polyakov.&quot;&gt;Talk abstract&lt;/a&gt;&lt;/div&gt;



&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
</channel>
</rss>

