Onapsis Podcast

Onapsis Podcast

Transcript

Back to episode

00:00:03: Hello everyone and thanks for joining today's webinar, Hacking & Defending SAP Applications Episode three.

00:00:09: How methods like AI models can hack SAP applications?

00:00:14: My name is Cecilia Deloy.

00:00:16: I will be managing the session before we get started on housekeeping notes.

00:00:21: First i want to point out a questions module within the On-Trenty-Fourth platform.

00:00:25: We welcome you.

00:00:26: enter your question at any time during this presentation.

00:00:31: you will answer whatever questions we can at the end of this session.

00:00:35: Also there is an

00:00:35: option

00:00:36: to request a meeting with our experts, feel free to fill out the form on your left hand side.

00:00:42: You can always adjust the size of the media player to make it bigger or smaller depending upon your preference.

00:00:48: And finally please note that this session has been recorded and we'll share a link for the session after we wrap up today.

00:00:55: Now I'm going to pass it over to our presenters.

00:00:57: For that Today We have Pablo Artuso Tech Lead, Eponaxis Research Lab and Hector Estinosa, Sales Engineer at Eponaxus.

00:01:07: They will be taking us through real-world scenarios And with that I'm handing it over to our speakers.

00:01:16: Thank you Cecile.

00:01:18: Welcome everybody!

00:01:19: To this episode number three of the DocuSeries Hacking and Defending SAP Applications.

00:01:25: In this opportunity we are going to be speaking about how artificial intelligence models can be used to hook into SAP applications.

00:01:34: So, hope you enjoyed

00:01:35: and earn

00:01:36: something new from today!

00:01:37: This is our agenda.

00:01:40: first we're going start with a quick brief interaction then were gonna move in the main point of discussion here that I see what they call AI perfect storm.

00:01:51: Then have an entire chapter on attacking demos that i hope that you enjoy it And finally will talk about how protect your business.

00:02:02: Hector will show how our platform could help you with this effect.

00:02:06: I'm fine, of course we're going to have some time for questions and answers.

00:02:13: So

00:02:13: before starting i would like to introduce quickly ourselves.

00:02:17: Hector You want to start?

00:02:19: Sure sure.

00:02:20: hi everyone.

00:02:21: my name is Hector Espinosa And i am a senior sales engineer.

00:02:24: i've been an abscess for almost twelve years now so pretty familiar With the solution in the company.

00:02:31: Great

00:02:31: thankyou.

00:02:33: My name is Pablo Artuso, I'm the leader of the Anapsis Institute Research Labs.

00:02:38: My background is mainly technical and I've been doing executing pen tests that are in trainings at conferences but mostly do boonability research for last twelve years as well since I joined Anapses.

00:02:53: So let's start with the main point before diving deep into today.

00:03:01: Let me stop here and talk a little bit about why we do these live local services.

00:03:07: So there are multiple reasons, but if I have to name one i would say that We identify That There is A big gap between the defenders on The attackers knowledge nowadays.

00:03:17: Oh of course talking About ACP Knowledge Attackers Already Have the tools Have the knowledge And as we showed in some reports They already are unknown and have the techniques and tactics on how to perpetrate or assess, including also compromise SAP systems.

00:03:40: Defenders from other side may lack them.

00:03:42: so we believe it was imperative to demonstrate our attacks carried out nowadays basically to empower defenders to help them be much more protected specifically in times where AI could a powerful tool specifically for threat actors.

00:04:02: Each of these series will be covered by at least one person from the RL Labs, which is a team I'm part of and The main reason for this Is that we have exposure We have experience And we have deep understanding Of these attacks.

00:04:19: Sometimes even because One of our main tasks is to discover a series That sometimes we report These kinds of attacks and work together with SAP, sharing them the knowledge that we have in order to contribute let's say for safer work.

00:04:39: In terms of goals what we are looking at is as I was telling you first of all try to empower defenders.

00:04:47: second of all trying to keep spreading awareness around SAP applications how important it is.

00:04:56: and also finally to keep spreading the knowledge, and to keep contributing with SAP.

00:05:04: So I already talked about ORL.

00:05:08: but what is this?

00:05:11: The Onapsys Research Lab has a specific unit inside the onapsys company which at least we can separate it or split in two big tasks.

00:05:21: Well let's say gather thread into data.

00:05:25: so by continuously monitoring through a deploying network of sensors, continuously monitoring the tactics and techniques.

00:05:35: How what attackers are targeting SAP applications?

00:05:38: And how they're using them?

00:05:41: Our second task could be related to deep SAP cybersecurity expertise that we have with contact pentests from time-to-time insurance response projects but mainly focused on identifying security vulnerabilities, what we call CODs or previously unknown capabilities with the goal of sharing this knowledge later with ACP Pro response team so they can inform and issue a patch to protect let's say and fix whatever it was exposed.

00:06:19: The consequences directly impact every SAP customer in the world.

00:06:29: Because for example, if we consider all of their reports that as a charter one that was published some time ago or even all information that were able to gather around CV- those information came thanks to this task that we did.

00:07:00: And of course, That's also the reason why were able close work with SAP Closer and help them with mitigating this attack.

00:07:14: but when we talk about our expertise on vulnerability research and vulnerability discoveries We can mention some campaigns based on whatever it is that we found, like Recon, ICMD before chains.

00:07:28: and yes all the campaigns are an awareness around how to protect against these amounts.

00:07:34: That's it!

00:07:36: It's one of these customers who benefit most from our team work Every discovery and every piece of research.

00:07:42: let say We do feedbacks into the product in multiple ways For example as sero-day rules which she pre-patched, so our customers are already being protected against those vulnerabilities of new threat intel centers campaigns and so on.

00:08:08: So let's start with the main topic The SAP Threat Landscape.

00:08:14: How was the SAP Thread Landscape previous to Mythos?

00:08:18: And how is today that said previously we can consider these.

00:08:24: let's say that meters appear, or more-or-less the LLMs like we all know them really empowered.

00:08:32: Let's see if we start seeing then in the bounce level at a final part of twenty-five and more less November when Opus four point five six over four point six was released.

00:08:44: before that right?

00:08:46: We already knew that pictures from a defender perspective were not very great so Already we analyzed that from twenty, twenty-one to twenty three.

00:08:56: We saw four hundred percentage increase in terms of a ransomware attacks.

00:09:01: We identified there were public exploits being released working exploits right?

00:09:09: Three day even less than three days after the patch was published increasing prices on the black market In regards to SAP exploits.

00:09:19: so Yeah, numbers that clearly said the picture was not very good.

00:09:26: And if you want to keep exploring around these numbers and some references I really recommend you go see our Tata report.

00:09:35: Also we saw there were a lot of news in terms of ADP cybersecurity tasks or security topics But also, most importantly on twenty-twenty five as I already mentioned we saw the appearance of a new studio that was being exploited in the wild and hit dozens of companies.

00:09:56: That we can consider to be pretty much mythos right?

00:09:59: And even surprisingly the Mtrends which is Mondians company Google Animal Threat Intelligence Report for first time listed an SAP related vulnerability And not only that, but that same vulnerability was categorized at the single most exploited vulnerability in twenty-five.

00:10:20: So clearly again a picture wasn't very great.

00:10:26: I Very much like this slide because i think it shows much better than express these words But previously right let's say couple of years ago whenever you want to know how to assess How to compromise?

00:10:45: How to say security?

00:10:46: You need it know a lot of property knowledge.

00:10:50: For example, you need to know kernel components what is the message server and gateway which are different protocols that are appropriate protocols like RFC or Direct Protocols.

00:11:01: You can also know about mechanisms, standard users, profiles techniques concepts.

00:11:08: so there was alot of knowledge required in order assess from a security perspective on SAP system.

00:11:18: Today, all that knowledge or most of the knowledge is held by DLM and these LMs with no specific training around SAP.

00:11:33: this what we want to show you today.

00:11:35: The main goal for today Is how simple it's to craft a prompt right?

00:11:42: That requires zero sub-knowledge And with this kind of simple prompts, it's even possible to compromise entirely SAP applications.

00:11:56: So in terms of threat landscape post-nitils we can mention some things that some of them will be cross SAP so not only shared with SAP but also other application platforms because you're talking about things like a pretty general HNPKI In Shintex AI, today LLMs for instance.

00:12:20: they have the knowledge.

00:12:21: Our nations know how to use that knowledge.

00:12:24: They know how run security tools and craft code.

00:12:28: How do you execute it?

00:12:29: How learn from their results And how to iterate a code.

00:12:34: in terms of surface For instance We had all these protocols, these misconfigurations Again, an expert person should have known in order to assess an SAP system.

00:12:47: Now it's held by ELM so its possible to produce that

00:12:51: gap

00:12:52: for a person who maybe has no SAP knowledge To access the SAP systems and interact with them.

00:12:59: In terms of public POCs The Asians are just one Google search away Of downloading a working POC And launching against an SAP System that could be unmitigated and therefore compromise it.

00:13:15: And of course, in terms of current keywords we all know that SAP stores the most important data company financial data intellect for personal information whatever... ...and the consequences of compromising an SAP system sometimes would even be immeasurable.

00:13:36: In terms of models We can divide two big groups.

00:13:40: I will not state too much in this one, but we can mention those kind of models that are general purpose like chapter activity five or four sonnet opus even fable.

00:13:51: That was with the latest.

00:13:52: you know it was disabled for the time being.

00:13:55: But all these Models our focusing on general purposes nonetheless They execute pretty well when he comes to some security things and i'm gonna show You also that they all attack demos that you're going to see afterwards were done with these kind of models.

00:14:16: Whereas also, what is called security-focused models like mythos, like chat.gd.find.polyfine slash cyber which are dedicated especially to cybersecurity tasks and yet they are even more important or interesting to analyze when it comes.

00:14:36: So, enough with that interaction.

00:14:42: Let's move on and let start the attack.

00:14:45: light.

00:14:45: demos.

00:14:46: Before starting I would like to mention we have three demos.

00:14:50: The first two are strictly following more or less this loop which is First of all map All things that system can be exposing Like a different landscape.

00:15:04: Then reason about that.

00:15:06: Try to understand what means that they have, for example this specific port exposed.

00:15:14: A third phase would be try to exploit ads.

00:15:17: and the fourth bug will be impact right?

00:15:20: The impact it's being caused.

00:15:22: And first two demos.

00:15:23: we're going see that the prompt is almost the same only thing you are gonna change in objective of those thought that two demos was already enough to show you how simple it could be, to graph Azure sub-knowledge prompt to compromise on SAP system.

00:15:42: So we made a step forward and were gonna see the demo is not guiding anything.

00:15:49: It's not specifically saying something that requires an SAP knowledge but its going to focus like giving specific information about how to pursue based just reading then use, let's say nothing in terms of technically from SAP.

00:16:09: So let's go with the first one.

00:16:19: this is the screen of the attacker will be using Cloud Code In This Case.

00:16:25: so first it showing that he has nothing already pre-configured and you want to see for us the prompt.

00:16:33: as I was telling you its gonna mention something about.

00:16:37: okay here is a system we need to assess.

00:16:40: This is the plan, first map then reason and exploit.

00:16:42: And what we want?

00:16:44: you to create a new user... ...and tell me all different steps that I have to do to connect with this new user.

00:16:54: That's it!

00:16:56: We are not entering more prompts.

00:16:59: Of course AI will work.

00:17:02: It has been working for thirteen or fourteen minutes.

00:17:05: In the phase one is mapping all the threat landscape and it already says that he has a major finding, something around ACP star.

00:17:15: The attacker just posted or I suppose to show you demo.

00:17:17: but in Phase two let's reason.

00:17:20: now we have these findings.

00:17:22: what should i do?

00:17:25: It will start with their recommendation which is strategy A. so phase three is just explained again.

00:17:34: We have been working more or less for twenty, twenty-two minutes and the AI tells hey are

00:17:40: you ready

00:17:41: finished?

00:17:41: You have your new user.

00:17:44: This new user has admin privileges And this is a way to connect with the system.

00:17:50: So if we see there There's that URL The attacker is connecting to that URL Using credentials of the AI provided Once it's logged in which is, yeah I've already.

00:18:05: the attacker has a user with full privileges inside the SAP system.

00:18:09: This is incredible and just to show you when you go to profiles this user had SAP all.

00:18:17: so the consequences are vast because it means that he has full power on that system and can do whatever she wants shuttle system compromise it mobilatorily or So as a kind of summary, a quick summary.

00:18:34: Again the prompt can be summarized in The following sentence I

00:18:40: don't

00:18:40: know anything about this IP so i would complete a relying loop.

00:18:43: that's literally what the prompt says.

00:18:46: Then again maps everything propose ways and exploit a CVE or a misconfiguration?

00:18:51: Don't care.

00:18:52: And What I want was to you to create an new privileged user and give me the credentials.

00:18:58: That's the prompt!

00:18:59: What happens technically?

00:19:02: So basically, the AI first assess or maps the landscape of a system.

00:19:08: Then it finds out that the client's zero-zero one is misconfigured and ACP star able to be used as login user which is a critical misconfiguration.

00:19:18: And then through an HTTP interface It has been able execute RFC functions.

00:19:25: Finally logging also through an ACP or HTTP interface.

00:19:29: but this was done as you saw automatically.

00:19:32: The attackers just give one prompt, no SAP expertise and no specific data.

00:19:41: Let's move to the second one.

00:19:43: so in case we're going to go a bit further on the idea is change the vendors bank account vendor.

00:19:52: So initially in these demo were gonna see at first that it will start As likewise as the other one, launching code code.

00:20:02: And here is the prompt which is exactly the same.

00:20:06: The system changes and again the objective.

00:20:10: so instead of now creating a user what I want you to do is execute something exploit something for it and give me privileged access.

00:20:20: that's all.

00:20:22: So this was more complex.

00:20:26: but First of all is assessing a map in the system landscape, different ports and service.

00:20:32: It realizes that there's... The gateway is misconfigured but it downloaded a public POC But didn't work because some small details.

00:20:43: So here you can see There are second prompt which is again not saying anything specific from SAP.

00:20:48: Just say more information like Python.

00:20:51: choose install Because he was trying to use Python three.

00:20:54: And please consider seeing the results, analyzing their result that you are getting and trying to change what it did but nothing specifically.

00:21:03: And after a couple more minutes of work I would say between...I don't recall exactly about let's say ten or twelve minutes we're gonna start seeing that.

00:21:13: um The AI realizes that the remote core execution is confirmed.

00:21:21: That is possible without any kind of authentication remote code in the system, remote commands.

00:21:32: So here we are.

00:21:33: so as you can see there uh We have the exploit already finished or yeah and it's possible to be used.

00:21:40: so The attacker now what is doing?

00:21:42: Is okay.

00:21:43: Now with the access that you have I would like to talk to list the top ten vendors ordered by billing.

00:21:50: grab the first one And modify the bank account of that vendor and put some values that the attacker wants.

00:21:59: So here, what you're going to see now is like let's change our shoes.

00:22:04: and we are at the admin stand of the system And we are logging it through SAP GUI.

00:22:08: This is not part of attack.

00:22:09: this is just to show You That The Vendor data well off these specific vendor that is gonna be changed Is there?

00:22:26: doing basically is through the OS command execution, it's launching SQL queries directly to the database and modifying those data.

00:22:35: Those are routing number on their account number.

00:22:39: so at the end we're gonna see a message after fifty minutes more or less before work when I say final message of the plug code saying that they changed was already done as you can see there.

00:22:51: So then new value for the routing number in the account number all ready in place.

00:22:56: So again, if we show this from an admin perspective and will launch the system when we showed information on the vendor.

00:23:05: We're going to see that new values are written over there.

00:23:13: so um Again in summary what we have here is That uh From the prompt perspective it was exactly same.

00:23:23: once you know it's nothing specific which has changed that?

00:23:27: We want to gain previous access instead of email user in comparison with demo one.

00:23:32: And finally, that's an extra prompt of trying to modify those vendors bank account data from a technical perspective.

00:23:40: what happened was first at the AI again assessing the landscape without authentication using the sub star service specific component.

00:23:49: once they realized it that the gateway was open because of a set info misconfiguration It executed commands abusing that misconfiguration.

00:23:59: And finally, as a first step once it was possible to execute OS commands.

00:24:06: It pivoted into HANA in the database and modified the bank account of the vendor without again this was provided with out authentication just because simple problems.

00:24:23: let's move on to the final demo number three which is related to shutting down the system.

00:24:30: In this case We're going to see again the same framework of attack, launching clock code.

00:24:38: The prompt is a little bit different now but it says nothing specific about SAP.

00:24:42: It's just saying this system and I heard that there was an exploit from twenty-twenty five out there created by this threat group.

00:24:53: please try to assess if these systems are vulnerable.

00:24:57: so first thing we do is collecting different POCs that are published online and start analyzing them.

00:25:06: Downloaded then analyze it, this also I think was instructed by the probe because we didn't want to run any kind of POC.

00:25:16: so he tried to look for the POCs assess them analyze them try to understand which one could really work Because with specific vulnerability there were a lot of POCs publicly that we're not working at all.

00:25:31: So here, you have a ranking and it's grabbing the first one-the most recommended right?

00:25:36: In this case is just say hey yeah I don't know.

00:25:39: run this one.

00:25:40: try to confirm if there are remote execution possible in these system.

00:25:48: One way of exploiting was very famous was to upload a web shell.

00:25:52: This is exactly what this script is doing.

00:25:56: What is going to happen now, it's that LAI has already demonstrated the full remote correction is working and its uploading this web shell right?

00:26:09: To that specific URL.

00:26:11: So finished, there are no questions possible.

00:26:14: so if you just as an attacker copied these I wanted try by yourself to confirm here.

00:26:20: You can see at a workshop was deployed and he's actually working.

00:26:24: So you have remote code execution in the system, again once more.

00:26:27: In this time we had a system.

00:26:29: so now The main goal of these demo was to shut down the system?

00:26:34: So if they're tackling this case is just prompting This to the AI asking him to shut on the system.

00:26:42: could the Attacker be with command in the web shell?

00:26:47: yes Of course but the idea will see.

00:26:48: you say I. so just ask it please try it out for me.

00:26:52: so afterwards if we go back to the web browser and refresh, you're going see that system is already down.

00:27:04: So again as a quick summary on the left We have the prompt.

00:27:09: The prompt didn't say anything.

00:27:10: rather than just here's the system.

00:27:12: there were POC about it.

00:27:15: sorry CD about it.

00:27:17: look for POCs improve RCE And then shutdown the system.

00:27:23: What happened?

00:27:24: On the technical side look for different public POCs, it analyzes them.

00:27:30: It confirmed that the vulnerability was possible to exploit.

00:27:33: It exploited and dropped a white shell which shut down this system.

00:27:38: All of those were done only by just few instructions as you saw Which didn't require SAP knowledge at all.

00:27:50: So that's everything about attacker demos.

00:27:54: on the attacker part I hope now it could be possible to do with AI nowadays.

00:28:04: Let's go and change our shoes, let us put them on the defender side.

00:28:08: so how can we protect our business?

00:28:11: which are the remunerations and defenses that we can implement?

00:28:15: So specifically for these demos I will do this part a little bit quickly because the actor would explain better than me about his demos.

00:28:27: but

00:28:28: On demo one, we of the hacker exploited the default credentials.

00:28:32: Something that is well known as kernel emergency mechanism.

00:28:36: that exists from the nidis and um as a general recommendation in order to be protected against these.

00:28:42: there are a few configurations in terms of profile parameters ,in terms of properly configuration on default users that can be applied.

00:28:49: But in our, on the analysis platform that let's say in a product.

00:28:55: you're going to see that afterwards Hector will show this.

00:28:58: You have two parts when there is access and whether it's defend quickly mentioned in days assesses like they'd say their product way of analyzing system understanding if it is vulnerable or not.

00:29:09: And then it's more reactive part where alerts you what something happened.

00:29:15: So from the assets part a couple of modules that can list you when ACP Star is not properly configured.

00:29:24: Proper parameter isn't configured, et cetera.

00:29:26: and from the defense side we catch, we monitor or we alert When somebody logs in as ACP star and grants ACPO privileges to our user.

00:29:36: The demo two was about also very well known an attack on misconfiguration That it's this gateway misconfiguration over there while permission allowed as set info.

00:29:46: It was known as part of the Chinca Blazapak in the year, and the general recommendation is to tie it a little bit more.

00:29:54: The Gateway ACL to protect more the second fold which sounds simple but actually really complex when you come through.

00:30:03: So from a set perspective we also have different modules that will let us know once the key foots widely open on.

00:30:10: for the defense side We detect every time the registrations happen.

00:30:15: The first two were misconfigurations, which means that can come back at any point in the time with error or human error.

00:30:24: Or a tool error.

00:30:25: The demo three was about vulnerability, which is probably already patched unless it's a bypass.

00:30:32: so the only recommendation here would be to apply the patch from a safe point of view it's possible to, I mean on Apsis reports whenever there is an impact system.

00:30:45: And from a different point of view OP also mentions when ever another every time that this is exploited.

00:30:54: so these are the kind of coverages we can mention that exist.

00:31:00: and finally in this is a slide more for reference rather than for me explaining now because three main points.

00:31:11: So the last general recommendations will be to reduce the surface, limit the port and service to just teams that actually need to use them.

00:31:19: And finally to monitor the crown shovels which is monitoring your system in every kind of activity that could be problematic.

00:31:30: So protecting against this attack This part of Hector we'll further explain so I hand it over to you Hector.

00:31:39: Perfect.

00:31:41: Thank you so much, Pablo.

00:31:43: So perfect.

00:31:44: what I'm going to do now is...I am gonna present how with the onapsis platform our customers can be protected against those basically attacks that Pablo just demonstrate and i'm gonna share my screen okay?

00:32:07: Okay!

00:32:08: Now You Can See My Screen.

00:32:09: First Attack.

00:32:10: Basically We With the Napsys platform, there are basically two phases or two steps that you need to take into action for every issue.

00:32:20: So number one we want to identify if your system is vulnerable for that attack?

00:32:26: of course where?

00:32:27: We already know that were looking for any information related to sub start user and not being configured correctly.

00:32:35: The Napsy's platform with that report showing all the different results from three thousand plus test cases that we have in our solution.

00:32:43: Actually, that number keeps increasing.

00:32:45: but in this specific scenario what Pablo was mentioning is about hey if that sub-star user properly secure and also it is properly secured like a someone who's basically able to use them.

00:33:00: so our solution is telling us here for example that in SH five, which is one of the system where they attack was executed.

00:33:10: The sub-star user was it's not actually enabled and here we can see that a sub star user It's now properly secured.

00:33:20: One more thing that on apps is going to provide also for each of those issues.

00:33:24: Is this solution?

00:33:25: So what would you have to do To protect your season against that scenario or that misconfiguration?

00:33:31: In this case?

00:33:33: apart from that what you will see is from the on-appsys platform, it's okay while you are basically fixing those issues how we can monitor your system.

00:33:44: How we can ensure or that your SAP System is still protected because at the end of the day if you don't apply the configuration for changing the systems then you're still unprotected.

00:33:56: so the on appsy solution seems like hey there some type activity in this system.

00:34:01: So number one, and if you think about the LLM what it's doing is basically pinging different clients to see which ones he's receiving a feedback.

00:34:10: Which one is enabled?

00:34:13: With that being said they say that client zero-zero-one didn't have a sub start user enable.

00:34:19: now its basically sending or receiving a response to their LLm also from the on apps with different protocols monitoring capability.

00:34:32: It's also telling us that someone locks in with the sub-star user into this system, which makes it again part of their exploitation process.

00:34:40: that Pablo just demonstrated now.

00:34:43: The NAPSY is capturing all that information to different products.

00:34:48: and last one but not least on is look at the scenario.

00:34:54: once you're logging in a sub star user they attack basically what Look, they create another user.

00:35:01: They assign a high profile.

00:35:03: so when the security team is trying to do the investigation and seeing what's happening in their system it's more difficult for them to detect that attack if possible or it was executed.

00:35:16: In this case while we are demonstrating with an Apsis platform we're telling the customer hey someone With a sub-star user logs into your system And basically connected and create another user in that high profile, which is something from the security perspective shouldn't happen.

00:35:38: That's a way we captured where first you're going to tell if your system is affected by mis-configuration.

00:35:45: then from the defense standpoint were gonna tell somebody using specific misconfigurations.

00:35:58: Then for the scenario number two, The main point of this one is a big configuration also.

00:36:05: So basically your gateway it's not configured correctly.

00:36:09: The onapsis platform as you can see here in this part after executing that full assessment It's telling us there are huge vulnerability or huge misconfiguration in system which affects multiple systems connected to our onapses platform.

00:36:24: One of them is TI-I.

00:36:27: Pablo executed the attack.

00:36:31: Then from this part, we can find a solution.

00:36:35: what would you have to do for the configuration standpoint?

00:36:38: To mitigate that risk?

00:36:40: That's why assess is going to be in charge

00:36:42: of.

00:36:44: and then The last one but not least on it is from another boy base or form they continue to monitor.

00:36:50: your Nazi Solution is capturing multiple events.

00:36:53: well the band that We are focusing right now is this one, starting potential and dangerous IFC execution.

00:36:59: So basically understanding that you have the risk in your environment someone is trying to remote execute commands through an SAP system In this case DI-One.

00:37:12: This is a user that was basically... This is the user that's executing those commands And then after solution when it go deeper into their results It's going to tell you how many times science, the defense product is enabled into that system.

00:37:30: That issue has been triggered.

00:37:31: but also it's gonna give you more in-depth information and this is a translation coming from your SAP logs.

00:37:38: so if you're familiar with SAP Logs takes time an effort basically make sense of what information its being recorded there.

00:37:47: but on apps while telling you are here putting away pretty readable and easy to understand and it's telling us from this GI-One system, someone is a super user basically try to remote execute commands on that specific systems.

00:38:06: And the connectivity in execution was successful.

00:38:10: so part of our information is going provide customers they can protect their system against these attacks.

00:38:20: And then last one, but not this one is regarding the visual composer.

00:38:24: This is a vulnerability that we found last year and it was actually pretty high in the scale of attacks have we see during last year?

00:38:35: The first thing I'm going to tell to the customers how you can protect your system against these vulnerabilities that you may not have information about because he's a zero date or something like our research lab discovering their wall and even we work with SAP for them to release a patch or fix that issue, is still there's gap in between because we know the information.

00:39:00: We want help our customers regarding those CODs attacks.

00:39:04: so we have our Trade Intel Center where put all of this information into just one pane of glass.

00:39:09: This information comes from our research lab And it basically tells us about the customer.

00:39:14: These are the latest things you need to be aware happening in SAP world.

00:39:21: So apart from that, like I said last year the Visual Composer we already have information before SAP recent patch where we tell the customer hey this is something pretty

00:39:34: high

00:39:35: right?

00:39:35: In the race of SAP systems This is something you should be aware it's happening and also please validate if your affected by that issue.

00:39:46: So when I go to assess and now, what do you need?

00:40:16: the time when we discovered this vulnerability and would release information to our customers, SAP didn't have a patch yet because they were working on that fix but it was something that was accepted.

00:40:29: And then on AppSys you know trying to be proactive will release a test case in an alert for our customer so they can be protected from things already no exist within the SAP world okay?

00:40:44: So, I know by then it was pretty quick but part of the idea is how simple and how quick we can protect our SAP environments.

00:40:55: Okay?

00:40:55: From the asset standpoint its more from identification.

00:40:59: for the defense standpoint Its more from continuous monitoring or compensating controls that were offered.

00:41:04: But also one more item is the threat intel center which number one capability that we have in our on-appsys platform, where our research team and the team is led by Pablo.

00:41:17: It's basically publishing information about their latest and greatest threats and SAP issues.

00:41:22: so everybody should be aware of what they're having there environment.

00:41:28: Then last will be the Compensating Control.

00:41:29: This something it'll help to maintain your system secure at end of day Once you connect your on-Appsys Platform through your SAP systems You gonna find multiple issues.

00:41:42: some of those issues are going to take longer, more than you know weeks or months.

00:41:46: To be fixed.

00:41:48: so the idea is to have a compensating control that it's monitoring your system.

00:41:52: twenty four seven That can allow You two keep working in the highest risk as an artist that you're having Your environment but also Having A police In The door like we said.

00:42:03: Two tell you if someone Is trying Take advantage Of this.

00:42:06: Issues We haven't been able to fix yet because It takes time and the change management controls etc.

00:42:14: So with that being said, does our demo in our presentation?

00:42:18: If you have any questions please feel free to put them on the chat.

00:42:23: Perfect!

00:42:23: Thank you so much for having me.

00:42:28: It was very interesting and I can see that the chat is busy already.

00:42:33: it's all we have.

00:42:35: a first question coming in an let me start how much of the attack chain was actually fully automated by the AI versus requiring human prompt engineering when dealing with SAP's proprietary protocols.

00:43:01: You mean Pablo?

00:43:03: Yeah, part of your mute

00:43:05: So sorry for that.

00:43:06: um yeah

00:43:07: I can take this one in the

00:43:09: live demos.

00:43:10: Actually we were not uh dealing with property protocols.

00:43:15: In reality, demo two is against the SAP Gateway who has some proprietary protocol which is RFC but it was all encapsulated inside a public exploit.

00:43:26: So we actually didn't have to deal with property protocols.

00:43:32: However what I can say?

00:43:36: that if I mean, we tried to reduce because it was the goal of the demo.

00:43:41: To show almost no interaction going back and forth with AI rather than just a simple prompt.

00:43:48: but in real life if you want keep discussing and prompting the AI.

00:43:55: even an expert is behind on prompting.

00:44:00: Yeah, I will say that dealing with program protocols is not something it would be a big problem for the AI.

00:44:09: It'll take time to learn about but at end of day you mostly handle it pretty well.

00:44:22: Alright thank-you.

00:44:25: then let's go on.

00:44:27: Since AI allows attackers to move laterally and execute exploits at machine speed, traditional reactive testing cycles seem obsolete here.

00:44:38: How does an access autonomous defense catch these AI-paced zero day attacks before they can pivot from a BCT application into the S for HANA core?

00:44:54: On that piece, basically the different product is using their knowledge.

00:44:59: That it's coming from now for Pablo's teams.

00:45:02: so every time we found anything in there while with basically update our napsis customers database with the latest and greatest information but also from that standpoint they are an Information about you know from the assessment point week We need to also use in a way that we need to identify what are the misconfigurations that could potentially be used from this, you know?

00:45:28: From these attacks.

00:45:29: And also...from their defense standpoint We can create a specific custom alert for things in the wall.

00:45:40: Not only our research team is providing to customers but they want to monitor.

00:45:50: that will be the right use for on AppSysPath or on Assets.

00:45:53: Okay, then I would say it's just two

00:46:02: other questions and we need to rest here.

00:46:06: in your second demo The attacker changed a vendor's bank details directly into database without ever having a valid SAP user.

00:46:15: how is that possible?

00:46:18: Ah okay yes this really.

00:46:21: let us take our question.

00:46:24: But yes, once you have access to the OS of the SAP system and your running let's say OS commands as what is called an SAD-ADM which is the OS user from an SAP perspective.

00:46:38: There is like a trust inner thing trust circle between what it's call the OS on the database.

00:46:46: so even without having access which let's say lives in the application side inside of the SAP system, once you have access to the OS.

00:46:57: You can do whatever if you want Let's Say In The Database and this is something that it not very known but It Is Something Important To Understand Because It Could Happen Also From The Application Side Right?

00:47:12: If You Are Powerful Enough Inside The SAP System as deep, and you can even get to the OS from the database.

00:47:26: That's a very important concept for fully understanding.

00:47:32: Okay thank-you.

00:47:33: then I would say one last question.

00:47:37: in the BTP to FBHANA scenario You showed how an attacker could use AI guided exploit to poison business logic and trigger full operational shutdowns.

00:47:50: that doesn't have deep SAT expertise, what is the number one leading indicator or alert they should look for to know?

00:47:58: an AI driven attack if underway?

00:48:16: you know, yeah we provide a lot of information.

00:48:25: It's about the threats and issues that can identify in an SAP system.

00:48:29: so coming from authorization means configuration patches even on custom code like with put out a lot effort providing information to our customers not only by helping them automatically identifying their issue into this system but also what they will have do protect environment.

00:48:51: And apart from that, we're also gonna tell them okay if you don't do anything.

00:48:54: If you keep your system in the same way it is right now with that issue and environment this what would be worst outcome?

00:49:03: This information is all provided under access so being helpful for their security operations center teams because at end of day where see they've got... They are in charge to protect their SIP environments But at the same time, they don't have their knowledge.

00:49:21: They don't what we call the Japanese language to understand how to protect an SAP system.

00:49:27: Onapsis is putting a lot of effort on that piece and providing the necessary information so you can understand first why it's there risk?

00:49:36: What are the worst alcohols?

00:49:38: but also solution affecting in your SAP environment.

00:49:43: All that encapsulating into the assessed product Also from the threat intel center.

00:49:49: What is important, we need to understand what to protect.

00:49:53: But if you don't know where to protect like how are going do that?

00:49:57: So they're not just trading the center but it's all information fed by our research team.

00:50:02: It's gonna provide that type of information for customers so their gonna know.

00:50:07: okay from today these have biggest attacks or this has been the biggest threats that were facing or SAP customers are facing.

00:50:15: These things should be aware happening and then we're going to keep all the necessary information for customers.

00:50:22: But also, I can analyze your system if you are basically putting it out there.

00:50:29: So that's where our biggest effort is just providing all of this because sometimes security operations center teams don't have knowledge and visibility.

00:50:41: so how our on-app solution will be able to help our customers with that.

00:50:51: Amazing, thank you!

00:50:53: I would say it brings us time for any other questions in the chat.

00:50:58: we will be reaching out individually and get those answered as well.

00:51:02: Also just a brief reminder everyone listening this session has been recorded.

00:51:06: The link to recording is e-mailed afterwards.

00:51:11: Thanks again to all of your speakers and everybody joining this briefing.

00:51:15: Have a good day.

00:51:16: Thank You

00:51:18: Thank you, everyone.

00:51:19: Have a good day.

About this podcast

Welcome to our Onapsis Podcast, a podcast brought to you by Onapsis, the global leader in SAP cybersecurity.

Join us as we delve into the fascinating world of safeguarding SAP systems from cyber threats and uncover the secrets to protecting your organization's most critical assets.
In each episode, our expert hosts and special guests will explore a variety of captivating topics surrounding SAP cybersecurity, shedding light on the challenges, best practices, and cutting-edge solutions that help businesses maintain the integrity and resilience of their SAP landscapes.
From the latest emerging threats to innovative techniques for vulnerability management and threat detection, our podcast provides invaluable insights for professionals working with SAP systems or those interested in learning more about the importance of securing the digital core.

by Onapsis

Subscribe

Follow us