<?xml version="1.0" encoding="windows-1251"?>
<rss version="2.0"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<link>http://dsecrg.com/</link>
<title>Digital Security Research Group</title>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=419</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=419</guid>
<title>Vulnerabilities: vCenter Orchestrator - password disclosure</title>
<description>The vCenter Orchestrator (vCO) Web Configuration tool reflects back saved passwords as part of web page.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=418</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=418</guid>
<title>Vulnerabilities: Oracle Application Server - multiple security vulnerabilities</title>
<description>Oracle Application Server Containers has multiple HTTP Response Splitting vulnerabilities.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=417</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=417</guid>
<title>Vulnerabilities: ASUS Net4Switch ipswcom.dll ActiveX - buffer overflow vulnerability </title>
<description>ASUS Net4Switch contains ActiveX component ipswcom.dll which is vulnerable to buffer overflow attack.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=416</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=416</guid>
<title>Vulnerabilities: SAP MessagingSystem - information disclosure</title>
<description>Information disclosure in MessagingSystem servlet.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=414</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=414</guid>
<title>Vulnerabilities: SAP Internet Sales - XSS</title>
<description>SAP NetWeaver 7.0 Internet Sales (crm.b2b) has XSS vulnerability.
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/expl/show.php?id=30</link>
<guid>http://dsecrg.com/pages/expl/show.php?id=30</guid>
<title>Exploits: ProSSHD v 1.2. Remote bind shell exploit (w/ASLR and DEP bypass using ROP) </title>
<description></description>
</item>
<item>
<link>http://dsecrg.com/pages/expl/show.php?id=29</link>
<guid>http://dsecrg.com/pages/expl/show.php?id=29</guid>
<title>Exploits: SAP GUI 7.10 WebViewer3D ActiveX - JIT-Spray Exploit</title>
<description></description>
</item>
<item>
<link>http://dsecrg.com/pages/expl/show.php?id=28</link>
<guid>http://dsecrg.com/pages/expl/show.php?id=28</guid>
<title>Exploits: Oracle Document Capture (EasyMail Objects EMSMTP.DLL 6.0.1) ActiveX Control BOF - JIT-Spray Exploit</title>
<description></description>
</item>
<item>
<link>http://dsecrg.com/pages/expl/show.php?id=27</link>
<guid>http://dsecrg.com/pages/expl/show.php?id=27</guid>
<title>Exploits: Oracle Document Capture (EasyMail Objects EMSMTP.DLL 6.0.1) ActiveX Control BOF - hardware DEP bypass</title>
<description></description>
</item>
<item>
<link>http://dsecrg.com/pages/expl/show.php?id=26</link>
<guid>http://dsecrg.com/pages/expl/show.php?id=26</guid>
<title>Exploits: Oracle Document Capture (EasyMail Objects EMSMTP.DLL 6.0.1) ActiveX Control BOF</title>
<description></description>
</item>
<item>
<link>http://dsecrg.com/pages/pub/show.php?id=42</link>
<guid>http://dsecrg.com/pages/pub/show.php?id=42</guid>
<title>Publications: Whitepaper &quot;Python arsenal for Reverse Engineering&quot; version 1.1</title>
<description>Python programming language has become a language of hackers. And it is not
surprising, because it has all the necessary qualities:
&amp;#8722; Free
&amp;#8722; Portable
&amp;#8722; Powerful
&amp;#8722; Mixable
&amp;#8722; Easy to learn
etc.

A great role in this were played by such projects as IDA Pro, WinDBG, OllyDebug, gdb, which, being a
de-facto standard among disassemblers and debuggers, eventually began to support the scripting
engines in Python. Of course, they had maintained their own API for plug-in developing, and it was not
a small number of them, but exactly with the appearance of the Python support they received a strong
push in the development: increased the number of plug-in, increased community, and of course their
flexibility also increased, which allowed them to interact both with each other and with other applications, using the best aspects of each other. But in the beginning of the path there was naturally only hacker spirit and idea.&lt;br&gt;&lt;a target='_blank' href='http://dsecrg.com/files/pub/pdf/Python arsenal for RE 1.1.pdf'&gt;Python arsenal for RE 1.1.pdf&lt;/a&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
<media:group>
<media:content url="http://dsecrg.com/files/pub/pdf/Python arsenal for RE 1.1.pdf" expression="sample">
</media:content>
</media:group>
</item>
<item>
<link>http://dsecrg.com/pages/pub/show.php?id=40</link>
<guid>http://dsecrg.com/pages/pub/show.php?id=40</guid>
<title>Publications: Whitepaper &quot;Architecture and program vulnerabilities in SAP&#8217;s J2EE engine&quot; from BlackHat USA 2011</title>
<description>Today, SAP NetWeaver is the most widespread platform for developing enterprise business applications. This talk will focus on one of the black holes called SAP J2EE engine.

Some of the critical SAP products like SAP Portal, SAP Mobile, SAP XI and many other applications lay on J2EE engine which is apart from ABAP engine is less discussed but also critical. We will explain the architecture of SAP&#8217;s J2EE engine and give a complete tour into its internals. Thereafter, we will show a number of previously unknown architecture and program vulnerabilities from auth bypasses, smbrelays, internal scans, xml/soap attacks to insecure encryption algorithms and cross-system vulnerabilities in J2EE platform.

Finally a chained attack which use multiple logic vulnerabilities and gives full control on SAP&#8217;s J2EE Engine will be demoed. A free tool will also be presented to automatically scan custom applications against this attack.&#8220;

 &lt;br&gt;&lt;a target='_blank' href='http://dsecrg.com/files/pub/pdf/A crushing blow at the heart SAP J2EE engine_whitepaper.pdf'&gt;A crushing blow at the heart SAP J2EE engine_whitepaper.pdf&lt;/a&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
<media:group>
<media:content url="http://dsecrg.com/files/pub/pdf/A crushing blow at the heart SAP J2EE engine_whitepaper.pdf" expression="sample">
</media:content>
</media:group>
</item>
<item>
<link>http://dsecrg.com/pages/pub/show.php?id=39</link>
<guid>http://dsecrg.com/pages/pub/show.php?id=39</guid>
<title>Publications: Whitepaper &quot;Python arsenal for Reverse Engineering&quot; version 1.0</title>
<description>Python programming language has become a language of hackers. And it is not
surprising, because it has all the necessary qualities:
&amp;#8722; Free
&amp;#8722; Portable
&amp;#8722; Powerful
&amp;#8722; Mixable
&amp;#8722; Easy to learn
etc.

A great role in this were played by such projects as IDA Pro, WinDBG, OllyDebug, gdb, which, being a
de-facto standard among disassemblers and debuggers, eventually began to support the scripting
engines in Python. Of course, they had maintained their own API for plug-in developing, and it was not
a small number of them, but exactly with the appearance of the Python support they received a strong
push in the development: increased the number of plug-in, increased community, and of course their
flexibility also increased, which allowed them to interact both with each other and with other applications, using the best aspects of each other. But in the beginning of the path there was naturally only hacker spirit and idea.&lt;br&gt;&lt;a target='_blank' href='http://dsecrg.com/files/pub/pdf/Python arsenal for RE.pdf'&gt;Python arsenal for RE.pdf&lt;/a&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
<media:group>
<media:content url="http://dsecrg.com/files/pub/pdf/Python arsenal for RE.pdf" expression="sample">
</media:content>
</media:group>
</item>
<item>
<link>http://dsecrg.com/pages/pub/show.php?id=37</link>
<guid>http://dsecrg.com/pages/pub/show.php?id=37</guid>
<title>Publications: Presentation &quot;DNS for EVIL&quot; from CONFidence Krakov 2011</title>
<description>Talk about DNS reverse tunnel that author uses for penetration  tests. Finally was published own reverse DNS shellcode and payload  that was written special for pen-test tasks. This work also demonstrates how malware C&amp;C and BOT can work  together. The main idea of this work that it&#8217;s necessary to pay more attention to the DNS traffic.
&lt;br&gt;&lt;a target='_blank' href='http://dsecrg.com/files/pub/pdf/dns_shl[1].pdf'&gt;dns_shl[1].pdf&lt;/a&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
<media:group>
<media:content url="http://dsecrg.com/files/pub/pdf/dns_shl[1].pdf" expression="sample">
</media:content>
</media:group>
</item>
<item>
<link>http://dsecrg.com/pages/pub/show.php?id=35</link>
<guid>http://dsecrg.com/pages/pub/show.php?id=35</guid>
<title>Publications: Presentation &quot;Forgotten World: Corporate Business Application Systems&quot;  from BlackHat DC 2011</title>
<description>Agenda: 
&lt;i&gt;&#8219;Do you know where all the critical company data is stored? Do you know how easily you can be attacked by cybercriminals targeting this data? How can an attacker sabotage or commit espionage against your company having access just to one system? This paper will describe some basic and advanced threats and attacks on Enterprise Business Applications &ndash; the core of many companies.&#8220;&lt;/i&gt;&lt;br&gt;&lt;br&gt;

The talk will be about enterprise business applications, the way attackers can gain access to critical business data, steal money or disable technological corporate network like SCADA, using vulnerabilities and misconfigurations in the architecture of business applications. We will show the examples of various business applications including custom ones as well as the more popular ones, like SAP and JD Edwards and previously unknown vulnerabilities and attack methods that can be exploited not just for popping a shell, but to gain unauthorized access to business-critical data. These attack methods can also be useful in penetration tests against ERP systems. Many problems that will be shown cannot be easily patched because they are design flaws or business logic problems requiring re-design of a system.&lt;br&gt;&lt;br&gt;


&lt;a href=&quot;http://www.dsecrg.com/files/pub/pdf/Forgotten%20World.%20Corporate%20Business%20Application%20Systems-Whitepaper.pdf&quot;&gt;Whitepaper can be downloaded here&lt;/a&gt;

&lt;br&gt;&lt;a target='_blank' href='http://dsecrg.com/files/pub/pdf/Forgotten World - Corporate Business Application Systems (Polyakov,Smith at BlackHat DC).pdf'&gt;Forgotten World - Corporate Business Application Systems (Polyakov,Smith at BlackHat DC).pdf&lt;/a&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
<media:group>
<media:content url="http://dsecrg.com/files/pub/pdf/Forgotten World - Corporate Business Application Systems (Polyakov,Smith at BlackHat DC).pdf" expression="sample">
</media:content>
</media:group>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=88</link>
<guid>http://dsecrg.com/pages/news/show.php?id=88</guid>
<title>News: ERPScan researchers guard Adobe</title>
<description>&lt;div align=&quot;justify&quot;&gt;&lt;p&gt;Adobe, the global leader in digital marketing and digital media solutions, &lt;a href=&quot;http://www.adobe.com/support/security/bulletins/securityacknowledgments.html&quot;&gt;thanks&lt;/a&gt; &lt;b&gt;Dmitry Chastukhin&lt;/b&gt;, &lt;b&gt;ERPScan&lt;/b&gt; lead assessor, for the dangerous vulnerabilities that he has found at &lt;a href=&quot;http://www.adobe.com&quot;&gt;Adobe.Com&lt;/a&gt; in the framework of research conducted by Digital Security Research Group, a subdivision of &lt;b&gt;ERPScan&lt;/b&gt;.&lt;/p&gt;&lt;p&gt;
The website contained several vulnerabilities which allow compromising user accounts and getting additional information about the system so that an attacker could devise specific attack vectors with the gathered data. A possibility of injecting malicious code into the web page was also revealed, which would do serious harm to the public image of the company if exploited. In the course of one of the possible attacks, a hacker could replace legitimate content with malware, so that downloading a regular Adobe Flash Player update would lead to infection of millions PCs worldwide. Thanks to &lt;b&gt;ERPScan&lt;/b&gt; researchers, no hacker can exploit the security breach anymore.&lt;/p&gt;&lt;p&gt;
&#8219;&lt;i&gt;I hope other world-famous corporations like Adobe will follow suit and pay more attention to the security of their web sites. A web representation of company as a basis for their reputation must be undervalued&lt;/i&gt;&#8220;, Dmitry comments on his findings.&lt;/p&gt;&lt;/div&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=87</link>
<guid>http://dsecrg.com/pages/news/show.php?id=87</guid>
<title>News: ERPScan has released a new version of Security Scanner for SAP: ERPScan v2.0</title>
<description>&lt;a href=&quot;http://erpscan.com/wp-content/uploads/2012/04/ERPScan-SAP-2.png&quot;&gt;&lt;img src=&quot;http://erpscan.com/wp-content/uploads/2012/04/ERPScan-SAP-2-300x83.png&quot; alt=&quot;&quot; title=&quot;ERPScan-SAP 2&quot; width=&quot;300&quot; height=&quot;83&quot; class=&quot;alignnone size-medium wp-image-2709&quot; /&gt;&lt;/a&gt;
&lt;br&gt;
&lt;div align=&quot;justify&quot;&gt;&lt;p&gt;ERPScan company, one of the key players in ERP security, has released&nbsp; ERPScan Security Scanner for SAP 2.0 &ndash; a complex solution to continuously monitor all areas of SAP security, from vulnerability assessment and misconfigurations to ABAP code review and analysis of business-critical privileges.&lt;/p&gt;&lt;p&gt;

One of the most significant changes is a new module which can make static analysis of ABAP code security. It makes ERPScan the only solution on the market which makes both security assessment of platform and code review. We have also significantly increased the number of anonymous checks which can be performed in Penetration testing mode to help companies identify issues without using credentials in the system. The new engine can help to perform audit and compliance checks not just through RFC &ndash; it allows making complete scan through the web-interface which is a great feature for external penetration tests and can make pen-testers&#8217; lives easier.&lt;/p&gt;


&lt;p&gt;
&#8219;&lt;em&gt;Today, almost all critical operations like procurements, stock resources management, human resources management, financial reports and much more, and all the data related to them, are stored in SAP system. This is why the main target for an insider or an external attacker would be to gain illicit access to SAP with the purpose of malicious manipulation of company resources. In spite of the increasing popularity of ERP systems security in the security community, companies are still vulnerable to cybercriminal and insider attacks. At this moment SAP has released more than 2000 Security notes closing various vulnerabilities, which is quite a lot, especially if you keep in mind that sometimes it is enough to get access to all business critical data through only one issue. An example was presented at BlackHat last summer. On the other side, almost every company develops custom ABAP code which can also have vulnerabilities and backdoors left by developers&lt;/em&gt;&#8220;, said &lt;strong&gt;Alexander Polyakov&lt;/strong&gt;, CTO of ERPScan.

&lt;/p&gt;

&lt;p&gt;
Using ERPScan, all kinds of customers can decrease their expenses and get different benefits.&lt;/p&gt;&lt;p&gt;

&lt;ul&gt;
	&lt;li&gt;Consulting companies can save time and resources. ERPScan allows them to significantly simplify the task of assessment by automating most of the ordinary checks, so auditors can pay more attention to the analysis of the customized part. Moreover, the unique database of checks gives consulting companies competitive advantages.&lt;/li&gt;

	&lt;li&gt;CISOs can effectively monitor security of SAP systems and prevent insider and hacker threats.&lt;/li&gt;

	&lt;li&gt;Penetration testers can easily perform black-box and white-box assessments of SAP with the largest knowledge base in the world and 0-day vulnerabilities.&lt;/li&gt;

	&lt;li&gt;SAP team can manage business-critical authorizations and control development by applying preventive measures.&lt;/li&gt;
&lt;/ul&gt;

&lt;/p&gt;&lt;p&gt;


&#8219;&lt;em&gt;SAP security assessment, according to our experience, usually takes quite a long time. Additionally, the complexity of the system and the large amount of different installation types require the participation of specialists from various fields of security. Even the application server may have either ABAP or Java platform, and they require completely different specialists, not to mention particular applications and modules. ERPScan allows you to significantly simplify the task of assessment by automating most of the ordinary checks, so you can pay more attention to the analysis of the customized part&lt;/em&gt;&#8220;, said &lt;strong&gt;Alexander Polyakov&lt;/strong&gt;.
&lt;/p&gt;&lt;p&gt;
More new functions:&lt;/p&gt;&lt;p&gt;

&lt;ul&gt;
	&lt;li&gt;Support of different web application types (bsp/iviews/jsp/webservices/webdynpro&#8217;s)&lt;/li&gt;


	&lt;li&gt;More than 5000 different checks covering misconfigurations, vulnerabilities, access to web-applications; search for 50 different types of&nbsp; vulnerabilities in ABAP code&lt;/li&gt;


	&lt;li&gt;Elaborated black-box vulnerability assessment&lt;/li&gt;

	&lt;li&gt;Cataloguing of SAP systems and services&lt;/li&gt;
&lt;/ul&gt;


&lt;/p&gt;&lt;p&gt;

&#8219;&lt;em&gt;Earlier, you needed to implement many different solutions to secure SAP from threats, now it is all in one place&lt;/em&gt;&#8220;, said &lt;strong&gt;Ilya Medvedovsky&lt;/strong&gt;, CEO of ERPScan.&lt;/p&gt;&lt;/div&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=86</link>
<guid>http://dsecrg.com/pages/news/show.php?id=86</guid>
<title>News: Installation of vendor's patch does not always guarantee security</title>
<description>&lt;p&gt;
Experts from &lt;a href=&quot;http://www.erpscan.com&quot;&gt;ERPScan Company&lt;/a&gt;, specialized in business applications security and SAP security, found out that even well-timed installation of vendor&#8217;s patch does not always guarantee security because the fixes are not always correct. In 2011, three critical patches from the key software vendors like SAP, IBM and VMware actually did not fix or not completely fixed vulnerabilities that ERPScan or other researchers had found in their products. This allows potential attackers to continue exploiting the vulnerabilities, whereas all most scanners and auditors would say that the problem is no more because patch is installed.&lt;/p&gt;
&lt;p&gt;On the BlackHat Europe conference held from March 14 to March 16, &lt;b&gt;Alexey Sintsov&lt;/b&gt;, head of information security audit department in &lt;a href=&quot;http://www.erpscan.com&quot;&gt;ERPScan Company&lt;/a&gt;, shared his experience in penetration testing and presented the results of a recently conducted &lt;a href=&quot;http://erpscan.com/wp-content/uploads/2012/03/bh-eu-12-Sintsov-Lotus_Domino-WP.pdf&quot;&gt;research&lt;/a&gt; of Lotus Domino security.&lt;/p&gt;&lt;p&gt;
His presentation told about lack of time and frequently desire for companies to dig into the details of existing vulnerabilities to exploit them, and how it often impairs the quality of their work.&lt;/p&gt;&lt;p&gt;
In the demonstration, a private vulnerability in Lotus Domino was quite quickly disassembled, the resulting exploit used, the existing patch bypassed and a critical 0-day vulnerability found. The result was an attack on the Domino Controller service (the Lotus Domino administration service) which allows full server compromise.&lt;/p&gt;&lt;p&gt;
Vulnerable services were also exposed which, one would suppose, should not be accessible from the Internet. Moreover, in the course of the research, services with the 0-day vulnerability and ever older vulnerabilities were found on the USA government servers (the .gov domain), on the servers of Russian universities and, curiously enough, even in the corporate network of IBM itself.&lt;/p&gt;&lt;p&gt;
Thus, it can be concluded that penetration threats are quite easily actualized for pretty much any network; even governments and corporate giants are vulnerable to attacks from the Internet, such as those made by LulzSec and Anonymous.&lt;/p&gt;
&lt;p&gt; Links to vulnerabilities:&lt;/p&gt;
  Vulnerability in IBM Lotus (&lt;a href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-11-110/&quot;&gt;ZDI&lt;/a&gt;)&lt;/br&gt;
  Vulnerability in VMware (&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=342&quot;&gt;Advisory&lt;/a&gt;,&lt;a href=&quot;http://www.vmware.com/security/advisories/VMSA-2011-0014.html&quot;&gt;Vendor&#8217;s patch&lt;/a&gt;)&lt;/br&gt;
  Vulnerabilities in SAP (&lt;a href=&quot;http://erpscan.com/advisories/dsecrg-11-039-sap-netweaver-th_grep-module-code-injection-vulnerability-new/&quot;&gt;Advisory&lt;/a&gt;,
&lt;a href=&quot;https://service.sap.com/sap/support/notes/1580017&quot;&gt;New patch&lt;/a&gt;,
&lt;a href=&quot;https://service.sap.com/sap/support/notes/1433101&quot;&gt;Old patch&lt;/a&gt;); another one is still being patched again.&lt;/p&gt;&lt;p&gt;
Alexey&#8217;s presentation can be found &lt;a href=&quot;http://erpscan.com/wp-content/uploads/2012/03/bh-eu-12-Sintsov-Lotus_Domino-Slides.pdf&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=85</link>
<guid>http://dsecrg.com/pages/news/show.php?id=85</guid>
<title>News: SAP critical patch update March 2012</title>
<description>&lt;p&gt;&lt;a href=&quot;http://www.sap.com/&quot;&gt;SAP&lt;/a&gt; has released monthly critical patch update for March 2012. This patch update closes many vulnerabilities in SAP products. This month, 2 vulnerabilities found by &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;ERPScan&lt;/a&gt;  researchers Dmitriy Chastukhin and Alexey Tyurin were closed.&lt;/p&gt;

&lt;p&gt;Detailed list of corrected vulnerabilities is below:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt; An XSS vulnerability was found in SAP Portal. An attacker can use the XSS vulnerability by sending a link to malicious script to an unaware user via an e-mail, messaging or social networks. Thus, an attacker can gain access to user session and gain control over business-critical information which can be accessed by victim. Update is available in SAP Note 1656549. Criticality, according to CVSS, is 4.3.&lt;/li&gt;


&lt;li&gt; Missing authorization checks in RFC function from BASIS module. Update is available in SAP Note 1657891. Criticality, according to CVSS, is 2.3. An attacker can execute vulnerable transaction, program or RFC function remotely without authentication because authorization check is missing. It can lead to different threats from information disclosure to full system compromise.&lt;/li&gt;&lt;/ul&gt;

&lt;p&gt;SAP has traditionally published acknowledgements for found vulnerabilities to security researchers from DSecRG on their &lt;a href=&quot;http://scn.sap.com/docs/DOC-8218&quot;&gt;  acknowledgement page&lt;/a&gt;.&lt;/p&gt;
 
&lt;p&gt;It is highly recommended to patch all those issues to prevent business risks.&lt;/p&gt;


&lt;p&gt;Advisories for those issues with technical details will be available within 3 months on &lt;a href=&quot;http://www.erpscan.com/&quot;&gt;ERPScan.com&lt;/a&gt; and also on &lt;a href=&quot;http://www.dsecrg.com/&quot;&gt;DSecRG.com&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Exploits will be available soon in &lt;a href=&quot;http://www.erpscan.com/&quot;&gt;ERPScan Security Scanner&lt;/a&gt; and ERPScan SaaS.&lt;/p&gt;&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/news/show.php?id=84</link>
<guid>http://dsecrg.com/pages/news/show.php?id=84</guid>
<title>News: DSecRG supports Project BaseCamp by releasing WAGO PLC 0-day vulnerabilities</title>
<description>&lt;p&gt; One of the key events in SCADA and PLC security &ndash; &lt;a href=&quot;http://www.digitalbond.com/s4&quot;&gt; the S4ICS symposium &lt;/a&gt; &ndash; took place in Miami on January, 18 to 19.&lt;/p&gt;&lt;p&gt;
Aside from several reports and SCADA security trainings, the results of a colossal &lt;a href=&quot;http://www.digitalbond.com/2012/01/19/project-basecamp-at-s4&quot;&gt; project&lt;/a&gt;, dedicated to research of vulnerabilities in industrial controllers, were presented to the symposium.&lt;/p&gt;&lt;p&gt;
The project was named Project Basecamp.
&lt;/p&gt;&lt;p&gt;
The following industrial controllers were examined:
&lt;/p&gt;&lt;p&gt;
&lt;ul&gt;
&lt;li&gt; General Electric D20ME &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Koyo/Direct LOGIC H4-ES &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Rockwell Automation/Allen-Bradley ControlLogix &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Rockwell Automation/Allen-Bradley MicroLogix &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Schneider Electric Modicon Quantum &lt;/li&gt;&lt;/br&gt;
&lt;li&gt; Schweitzer SEL-2032 (a communication module for relays) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt; The DSecRG researchers decided to support the project by their independent research and added the 750 series WAGO controller to the list. They have also published a variety of 0-day vulnerabilities for this controller and for the SCADA systems of wellintech KingSCADA and OPC Systems.NET, to draw the public attention to this problem once more.
&lt;/p&gt;&lt;p&gt;
The following links lead to the details about found vulnerabilities:&lt;/p&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=401&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=401&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=402&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=402&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=403&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=403&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=404&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=404&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=405&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=405&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=406&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=406&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://dsecrg.com/pages/vul/show.php?id=407&quot;&gt;http://dsecrg.com/pages/vul/show.php?id=407&lt;/a&gt;
&lt;p&gt; The results of the Project BaseCamp research are available here:&lt;/p&gt;
&lt;a href=&quot;http://www.digitalbond.com/2012/01/19/project-basecamp-at-s4/&quot;&gt;http://www.digitalbond.com/2012/01/19/project-basecamp-at-s4/&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://www.wired.com/threatlevel/2012/01/scada-exploits/&quot;&gt;http://www.wired.com/threatlevel/2012/01/scada-exploits/&lt;/a&gt;&lt;/br&gt;
&lt;a href=&quot;http://reversemode.com/downloads/logix_report_basecamp.pdf&quot;&gt;http://reversemode.com/downloads/logix_report_basecamp.pdf&lt;/a&gt;
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
</channel>
</rss>

