Onapsis Podcast

Onapsis Podcast

Transcript

Back to episode

00:00:00: Good morning and welcome to part four of our Hacking in Defending SAP Applications webinar series, Beyond the Perimeter.

00:00:08: Managing the expanded attack surface of SAP Cloud Migrations.

00:00:12: My name is Leah And before I hand things over To our presenters i have some housekeeping notes.

00:00:17: First i want to point out The questions module within the on-twenty-four platform.

00:00:22: If you Have Questions please enter them at any Point during this presentation.

00:00:28: We will answer whatever questions we can at the end of the discussion.

00:00:32: You can always adjust the size with a media player on your end to make it bigger or smaller, depending upon preference.

00:00:38: There'll be video components for this webinar so you want ensure that the media player is large enough.

00:00:44: and finally please note there's being recorded in the link sent.

00:00:54: Part two, RQSO Lead Offense Security Researcher and Hector Espinoza Senior Sales Engineer.

00:01:01: This Onapsis team will discuss the Cloudverse on-prem transition to reveal how misconfigurations invisibility gaps can create security liabilities.

00:01:12: with that JP Can you start us off?

00:01:15: Absolutely thanks Leah.

00:01:17: Thanks everyone for joining us.

00:01:19: it's really exciting everyone on this yet another episode of these docu-series.

00:01:27: We have a lot of content and great demos that we're going to be showing you, so let's kick this off!

00:01:36: Today's agenda is focusing around the expanded attack surface it's beyond the perimeter right?

00:01:46: So now We're going to get into the details of why.

00:01:51: today, leveraging the latest and the greatest technology from SAP introduces significant complexity in our landscapes.

00:02:03: And we need to be able understand that complexity so you can secure it.

00:02:08: So I'm gonna do an intro.

00:02:10: go through The attack demos on then were gonna wrap up with some recommendations how you can address this complexity through automation and controls.

00:02:27: About us, the speakers.

00:02:29: I'm going to let each one of you introduce yourself.

00:02:34: I'll start since I am already speaking.

00:02:36: JP, Leah provided a brief intro.

00:02:41: CTO on One of the founders of Onapsis working very closely with our research team ensuring that our customers get the best possible visibility and protection from the latest threats that threat actors are executing, driving through their attacks.

00:02:59: Part two do you want to continue?

00:03:04: Thank You!

00:03:04: Hello everybody my name is Pablo Artuso.

00:03:06: I've been working as a security researcher currently as tech lead of team for the last twelve years.

00:03:12: our, yeah.

00:03:13: Our main work from this team is to conduct vulnerability research find surveys on the pentest and also involving threat intelligence parts of.

00:03:23: I think JV will speak a little bit more about them but happy to be here once more so Hector?

00:03:31: Sure hi everyone.

00:03:33: my name is Hector Spinoza And i'm a senior self-signature.

00:03:36: I've been with Onapsis for almost twelve years now part of, you know the technical team and

00:03:44: then

00:03:45: they're self-steam now.

00:03:47: You are pretty familiar with the solution in their company And today I have the opportunity to give another presentation about the NAPI Solution and happy to be here Thank you If you want to

00:04:00: continue.

00:04:01: Absolutely thankyou Hector!

00:04:04: As you guys were introducing yourselves tenure here in the presenting team.

00:04:12: So there's a lot of experience and living through securing SAP customers amongst these three speakers, so happy to be part of this team.

00:04:24: All right!

00:04:26: What is the attacking or hacking and defending SAP applications like .series?

00:04:33: We started this specifically this year because urgent need by defenders to really understand the threat landscape, what threat actors do and be able to understand those attacks in order to secure their own systems from these attacks.

00:04:56: The threat landscape has been evolving and significantly increased specifically this year driven specifically driven by AI, right?

00:05:10: The generative models allow for an unprecedented acceleration of the threat landscape.

00:05:18: The capabilities of threat actors and we as defenders need to have as many tools and as many capabilities on knowledge—as much knowledge as possible —to be able to secure our systems.

00:05:36: So that's a whole goal of this doki series.

00:05:40: We want to

00:05:41: share

00:05:41: our learnings, we wanna share what we see threat actors doing.

00:05:47: so you on the other side as defenders can really leverage all these learnings and secure your systems which is shared goals right?

00:05:59: To secure SAP landscapes across the globe.

00:06:06: Both part two and myself are active members of the UNAXIS research labs with different capacities, different levels of involvement but we're working towards identifying threats.

00:06:20: Identifying the different elements that threat actors use when they target SAP applications.

00:06:31: how to protect SAP systems from those attacks, right?

00:06:39: So we have a large backlog of vulnerabilities that we have reported to SAP and other ERP vendors over time.

00:06:53: We basically leverage that knowledge leverage the reports that the Onaxis Research Labs performs to ERP vendors and specifically SAP, and compare their knowledge into content capabilities for the Onaxis platform.

00:07:20: So effectively periodically all of our customers are empowered with more visibility or capabilities through different specific capabilities of the Anapsis platform.

00:07:35: But also, something that I'm very proud off this Anapsist Research Labs team is we periodically report vulnerabilities to SAP and those vulnerabilities eventually materialize in security patches benefiting all SAP customers making SAP applications more secure across the globe.

00:07:57: so thats another shared objective when we talk about what we do is also not only our customers benefit from the output and knowledge of the analysis research labs, but effectively all customers too.

00:08:17: All right let's get into this specific topic today which is beyond a traditional perimeter And will be talking about the traditional perimeter if you go a couple of years back in time.

00:08:31: If some of you are long-time SAP users, SAP bases... You may be familiar with some of these right?

00:08:41: Some years ago it maybe true that SAP landscapes were something like this Of course oversimplifying but we had different SAP applications different products across landscapes with different tiers.

00:09:04: Some of these are most of this interconnected, but the common denominator across all of these systems was that these were beyond the firewall right?

00:09:15: So some of these applications we're internet facing in some cases But for the most part organizations where keeping applications beyond the firewall, not exposing them.

00:09:30: And that gave some sense of security to organizations because in some cases they were saying you know what?

00:09:41: We are behind

00:09:42: our corporate firewall.

00:09:44: we share the same protections at all other applications and while could have been true to some extent on some of those controls, this has evolved significantly over time.

00:10:01: Leveraging the capabilities and their technology that SAP was developing or acquiring in some cases adjusting to the latest trends and the latest innovations in IT such as cloud and expanding the attack surface while doing this significantly because now we are no longer running applications, business applications in our on-premise systems.

00:10:32: In our own premises behind the firewalls.

00:10:36: Now This also is a simplification of what today's landscapes looks like but it gives you an idea how much why there this footprint of different technologies really is.

00:10:53: because now we have the on-premises systems.

00:10:56: We may have private cloud, these on premises are mixing for most part of data centers and their own companies.

00:11:05: also some systems in AWS assure GCP depending on the provider's choice.

00:11:13: you will be running your system across different providers but also you may have parts of your landscapes in rice managed by SAP with a shared responsibility model.

00:11:27: Also,

00:11:28: most likely the majority of you already have BTP connected with on-premise systems through some cloud connector and also running public Cloud apps such as SuccessFactors, Arriva, Concure and many others.

00:11:47: So SAP has been expanding its portfolio of SaaS applications, in some cases using well-known SAP technology like UI five and application space on HANA or net weaver.

00:12:06: But other cases this is completely different technology, completely different concepts from a security perspective so it really increases the complexity and the footprint of different technologies.

00:12:21: So guess what?

00:12:23: This extended landscape, on this extended set of technologies also expands the attack surface And we need to understand that any attack in any of these elements could potentially imply further compromise across the rest Of the IT landscape of SAP applications.

00:12:44: And those are the examples that we're going to be looking at and that were gonna be covering today.

00:12:51: Just a wrap up on this introduction, they building blocks.

00:12:56: these are just some examples.

00:12:57: but as I mentioned on-premises cloud connectors BTP SAP rise or managed cloud applications also SAS applications many others potentially all of these interconnected And this is true for the majority of SAP customers today, right?

00:13:20: So five years ago it may be through that.

00:13:26: The majority were more on the on-prem slash private cloud but today that's shifting significantly because of SAPs

00:13:37: own push

00:13:38: off customers towards rise and really leveraging the latest products, and the latest innovations from SAP which are deployed within the cloud.

00:13:52: So we're going to be looking at specific attack scenarios as I mentioned actually three of them.

00:14:02: they involve these extended attack surface which is... We have on-premises systems BTP as an example of cloud application, and then we have Cloud Connector which basically connects both of them.

00:14:23: What I mentioned is hey depending on how the attacker is positioned in this technology landscape.

00:14:32: attackers could potentially move back-and forth across different elements.

00:14:37: so an example of how an attacker could potentially compromise and SAP Cloud Connector.

00:14:45: And from that system, jump into on-premise SAP application will also show someone compromising a non-premises SAP application by leveraging the existing connections.

00:15:00: who would enjoy jumping to BTP?

00:15:03: The other way we'll A compromise on a BTP application could be used to compromise on-premise applications, and the other direction.

00:15:18: Why is this important?

00:15:20: Because in the past we may believe that level of controls were sufficient to protect our SAP applications even if it's still arguable because you cannot rely on a firewall applications as complex SAP, as interconnected as SAP and critical as SAP applications.

00:15:45: But now even that is challenged.

00:15:48: today because we have way more complexity with more interconnectivity between different technologies it's important to understand potential security gaps across any of these layers could introduce risk across the entire landscape.

00:16:10: So with that, I'm going to

00:16:12: pass it over

00:16:12: to Part two.

00:16:14: who's gonna run you through the first demo?

00:16:19: Thank You JP!

00:16:22: So let's start speaking about what this demo is all about.

00:16:26: so as JP introduced The First one is how an attacker was able to somehow compromise.

00:16:34: a cloud connector Is able to jump on a prem system and potentially also compromising where to thread information.

00:16:42: Before starting that, I would like you share this architecture.

00:16:44: we're gonna go back to these in the future as well.

00:16:49: however i'm not going to focus on all of these parts and then focus just from the relevant part for this demo which is let's say The Orange Branch.

00:16:57: So On the left side of the slide You can see a sub-BTP account, subaccount sorry And basically an HR portal application Which Is running on the BTP site That Following the orange flow, this is connecting or pulling data from an on-prem system which is a human resources system.

00:17:17: Or run in a human resource model

00:17:20: and In

00:17:20: order to make that connection it has to go through the cloud connector.

00:17:23: right because again Those open-prem systems are not just exposed our chassis both through virtual holes inside of Cloud Connector.

00:17:31: So with these architecture in mind let's see how the VTP configuration is done.

00:17:37: so Here you can see the destination name that was set up in the BTP side pointing to a virtual host, which is in this case HCM.prod.

00:17:47: This is not really a host of system it's just a virtual hosts exposed by account connector.

00:17:52: and finally we can see there That There Is A User And The Password Stored In This BTP Destination.

00:18:00: Please Remember That Username Because We Are Going To Use It

00:18:02: Afterwards.

00:18:05: Thinking on the cloud connector side of configuration, what we have here is well the mapping as I was telling you right from virtual host which is part exposed to the internal hosts.

00:18:15: Which are real internal hosts in the on-prem system that once more not expose to the BTP site just a new virtual host being exposed.

00:18:26: so

00:18:26: also

00:18:27: JB said he had select and specific attack to show you and for today we selected a very weird trace that could be configured.

00:18:38: This race is called the Tuned Traffic Trace, according to SAP documentation once it's enabled have to be careful because sensitive data would specifically passwords user names even credit card numbers could be stored over there.

00:18:57: So, the demonstration that we have today would be which are the consequences of enabling this trace in your systems.

00:19:08: And how

00:19:08: were you going to show these?

00:19:09: The

00:19:09: vector for attack

00:19:10: will be following We assume that attacker has access to cloud connector with a support role Which means it has access read but not modify traces and without user It will end up or the target will end compromising HR system running on-prem.

00:19:30: So for this, we have a demo.

00:19:34: On the first part of the demo you're going to see a black screen.

00:19:36: This is the screen of the administrator.

00:19:38: It's actually not relevant For the attack but it's part Of that demonstrating how To enable these traits.

00:19:45: so here We can see How there Is uh this part of The configuration where You Can See the checkbox

00:19:51: down

00:19:51: There That once is checked

00:19:54: They are

00:19:54: Going to appear new files over there.

00:19:56: Now let's sum to the display of the attacker, the monitor user.

00:20:01: So we see those files over there and they are able to be read.

00:20:06: The monitor is able to read a traffic that it's going through the application To the HR system right?

00:20:12: so here you can see not only the password A user encoding B-SYC for but also the URL.

00:20:19: It's pretty easy For

00:20:20: an attacker

00:20:21: to decode this b-sysc for And get their real credentials That are used in the ptp destination.

00:20:27: After this, the attacker can do or is going to two different commands.

00:20:31: just take connectivity against the HR system that's running on-prem.

00:20:39: The first one will result in a photo one because no credentials were provided and

00:20:43: then last one.

00:20:45: luckily for the attacker it'll be resulting at two hundred because the credentials are valid.

00:20:50: so now the attacker does several things to test these credentials.

00:20:54: For instance, it could go to SAP doing and try to log into the system.

00:20:57: Unfortunately for the attacker this is not a valid user.

00:21:01: However you can use other ICF services... ...for instance the very well-known SoftRFC which is pretty dangerous.

00:21:08: Here we can see that the attacker realizes that he's activated.

00:21:11: So by using crafted script The attacker will create new users in the system with potentially very high privileges.

00:21:23: In this case, we'll try to use ACPO.

00:21:24: This could work or not depending on the authorizations of all end credentials but as you can see here it worked.

00:21:32: so now

00:21:33: the attacker can log in with a new created user using SAP GUI and just for the sake of this demonstration.

00:21:40: um It would show uh that the credentials uh sorry the authorisations obtained were actually acp.

00:21:51: So going back to the slides, how can we be secure against these actions that happened?

00:22:00: The first recommendation would be to properly configure the traces.

00:22:03: This let's say dangerous trace called a tunnel traffic trace which is documented by SAP and we are sharing links in not only previous slide but also final references like where it is basically say to be careful how to activate this.

00:22:20: and if highlights these four eyes principle, two deal with this topic.

00:22:25: A second thing that maybe's not that clear.

00:22:28: Is that?

00:22:29: If you realize the attackers told credentials That were meant to be used by a nature system an HR application But we those credentials.

00:22:38: It was able to create a new user on the ACP system.

00:22:42: so It is very important that every time you configure a VTB destination, the user that you are using there it's a scope to only be actions required for that application.

00:22:56: So most likely HR portal shouldn't have access of their possibility and create users with ACBO authorizations.

00:23:08: And finally, the final part of the attack was using an ICF service that is called SOAPRFC which is pretty well known and we all know it's very dangerous.

00:23:17: So the question is should that ICS service be running?

00:23:22: If its possible to deactivate then biggest recommendation would be do it.

00:23:28: if its not possible because there are some needs for market to run

00:23:34: it than

00:23:35: best way to operate with it would be to restrict the access, specifically this one and two other sensitive ICF services.

00:23:47: I think that was all.

00:23:47: now we'll hand out again back to JP for a second demo.

00:23:52: Sounds great.

00:23:53: Thank you Bartu For these first demos.

00:23:57: Now were gonna show The second attack scenario which is on-premise to cloud.

00:24:03: As i was saying We are talking about an On-premises system.

00:24:08: in this case This could be an Sforhana, for example.

00:24:12: It can be any type of ABAP-based solution and this system is configured with a destination pointing to a cloud application.

00:24:24: in these case the cloud applications that we are using for demo it's an ABAP on BTP but as just one example they could be something completely different.

00:24:37: The idea that these integrations

00:24:40: should be

00:24:41: defined with the specific concept of least privilege, right?

00:24:48: If there is

00:24:49: a set

00:24:50: of credentials and authentication already in place stored on the destination it should only assign the privileges required for that specific integration or use case.

00:25:05: In this case The user on the target system, on the ABAP on BTP has

00:25:12: two

00:25:13: communication arrangements.

00:25:14: This is a communication user with very specific set of assignments.

00:25:21: One is a communications arrangement for the purpose what this integration was built in and another one that wasn't specifically needed.

00:25:35: This could be a drift in the configuration, testing further leaked into production or different reasons.

00:25:46: With that what's going to happen is this S-for-HANA system

00:25:51: through

00:25:52: the integration with ABAP on BTP system will have specific authorizations are gonna be abused by someone who was able to compromise that.

00:26:03: on-premise systems All right, so let's jump into the demo itself.

00:26:10: Now

00:26:11: the demo.

00:26:12: I said that it is an Sfor system So its a system running either on private cloud or on-premises.

00:26:22: Going through SM-Fifty-Nine we can see the existing integration with Ava.com BTP We tested and its working.

00:26:31: Its pointing to specific intent of Ava.BTP and this has, there is a specific report that can be executed that shows us the connectivity some exchange of information with the remote system.

00:26:52: but then these attackers that compromise on-premise systems because thats an overall objective right showing that a compromise in one system could impact the rest of the systems.

00:27:06: In this case, these attacker is creating a specific report custom code that can be used to do different things.

00:27:15: we'll see what it's being done.

00:27:17: but because he realized there was an established trust relationship through his destination so is basically using this destination.

00:27:33: So these attackers listing the communication users first through this communication arrangement that was configured, then he's using the same communication arrangement to create another communication user and also through this same code it's called a could be doing anything, but in this case it's using the right APIs to connect with ABAP on BTP is creating also a business user and widening the privileges of that business user.

00:28:13: So through these integration they attacker was able actually get a whole foothold into their ABAP-on-BTP system as well as a business user.

00:28:29: And then now we go and list the users, Now We see this backdoor user that was created right?

00:28:35: This is just for the purpose of the demo.

00:28:37: um other things could be executed depending on their privileges, Depending On The Code That Is Deployed.

00:28:47: They Previse On Both The Target And The Source System And We Can See The Created Communication User There basically highlighting the compromise on the target system.

00:29:00: All right, so this was basically showing how these attack of on-premise systems could impact into a cloud system.

00:29:15: in this case again we're talking about an ABAP on BTP, there's going to be a BTPS account and other such solution.

00:29:23: The concept is same as a pre established integration with pre-established privileges, so what those privileges allow that user to do is very important and it should be further restricted.

00:29:39: So recommendations don't reuse passwords for specific destinations if possible don't store them on the credentials, use other type of authentication mechanisms.

00:29:56: Use principle propagation if possible, certificates more secure authentication mechanisms and also make sure that you secure both the privileges of.

00:30:10: the user is connecting into a target system but it's possible to restrict who can use these destinations as well.

00:30:20: So it's all a matter of privileges and really doing defense in depth, right?

00:30:25: Making sure that the more you restrict the elements of this integration.

00:30:32: The more layers of security we are introducing with that.

00:30:37: I'll pass over to part two for their third demo.

00:30:43: thank you JP.

00:30:44: okay let's go to compromise application that is running on the cloud and demonstrate how to jump into an on-prem system.

00:30:59: So here's back again, they're architecture.

00:31:01: in this case I will try to explain a full architecture.

00:31:04: we already explained there orange branch.

00:31:08: The green branch is more or less the same.

00:31:09: it's different application In this case called supply

00:31:12: portal

00:31:13: and its simple application getting data vendor data let say from an on prem system running Sfor.

00:31:20: In the middle, we have a CloudConnector destination configure that is one used.

00:31:25: But if you properly see this there's no...

00:31:31: The orange

00:31:31: flow and green flow looks pretty independent right?

00:31:34: There are no cross connection between them.

00:31:37: so let us think about it.

00:31:39: And also to share services, the destination service on connectivity service These two important services always running in BTP in a sub-account if you are using CloudConnector, for instance.

00:31:51: Because in order to create destinations You have to make use of these two services.

00:31:55: The destination service is the service that allows you to create designations

00:31:59: and

00:31:59: the connectivity service Is like kind an internal proxy That allows you actually route traffic And move through different layers In this case Through BTP To the cloud connector.

00:32:11: So let's see how this is reflected from the BTP connection side.

00:32:19: So, in this setup we already see these for HR Prod.

00:32:22: on the Super Prod you can look that is pretty similar or there's a different user because it has a different system as well and also with password which is stored over here.

00:32:35: From the cloud connector side We have the same as before mapping between the referral and turn host And afterwards, we have the different which is called the access control.

00:32:44: This is a very important screen because he actually here configured with our dn points that are allowed to be reached

00:32:51: through the

00:32:51: cloud connector for each system there is behind the Cloud Connector right?

00:32:55: So this Is A Very Important Screen To Perform Configurations.

00:33:01: Finally Here Yeah We Have The Let's Say The Connection Between The BTP Destination On The Cloud Connectors Configuration Where You Can See The Mapping Between The URL and build a host.

00:33:14: So how the attacker will look like, basically

00:33:18: an attacker.

00:33:19: we're going to assume this and attack her which is have access to the supplier portal.

00:33:23: A vulnerable

00:33:24: application.

00:33:25: it's gonna finally end up compromising DHR system Which again not connected at all because they two flows are pretty

00:33:33: bad ones.

00:33:35: so

00:33:36: let's sum to video.

00:33:37: Let's see How This Actually Works?

00:33:44: At first you're Gonna See The Screen of supplier portal application.

00:33:49: This is not very relevant to see what happens actually, but it's important that you recognize there is a vulnerability shown by the attacker now and also for this symbol because that screen is short or pretty small we can use directly the API as seen in a moment.

00:34:18: So in Cloud Foundry, there is this big app service which holds all the credentials that actual applications need to connect with the destination and the connectivity.

00:34:28: As you can see here

00:34:29: right?

00:34:31: In JSON format All of these information are stored on the OS.

00:34:35: so With this information a person or attacker who has access to it can craft tokens And use these services The Destination and the Co-Activity Service and dumping all the destinations with information that is in the shared service, here you'll see HR Prod and a supplier Prod.

00:34:57: With plain text passwords this is possible but it's not by default like this.

00:35:02: so now having these information we can use connectivity decision

00:35:08: right?

00:35:10: And try to grab and reach the system.

00:35:15: behind CloudConnect The quality service goes through an internal proxy as I told you.

00:35:21: So the only way to reach it is using a remote code execution, right?

00:35:30: So that's how what we did there first was try and see if it's reachable in this system And now what its gonna do Is try to dump all information That is exposed into HR System like If It Was Using The Other Application The HR Portal Application.

00:35:47: Here is a nicer way to see this information leaked, where you can see for instance the monthly income of each person or their company employee and even numbers.

00:36:02: So what happened here?

00:36:03: How do we protect it about these?

00:36:05: Well first of all It all started because vulnerable application.

00:36:10: so the first recommendation will be try to scan your code with static analyzers trying to identify vulnerabilities.

00:36:16: in this case was remote execution but other kind could also be abused.

00:36:23: The second and very important thing to have in mind is that spaces and organizations are not security boundaries, right?

00:36:31: So it's important to understand the shared services between sub-accounts as a kind of shared because of applications who have their own credentials but they're going to connect into same service.

00:36:43: once connected you can see all those parts of these two accounts.

00:36:47: Finally I said it's very important not to store all credentials, but use also principle propagation because in this case that would avoid the attack to happen.

00:37:00: And finally as I was telling you before these cloud connectors three where you configure a resource path is called the access control list... ...is very important and In this case he wasn't abused But its' very important for understanding if

00:37:14: e.g.,

00:37:15: that will have had the slash Let's say a path, it would allow the attacker to do same attack that he did in the attack number one.

00:37:25: In the demo number like rating an USB user.

00:37:30: So

00:37:31: I think there was all and i think its time now to shout out to the defense side of this presentation And for that I will hand out their presentation to Hector.

00:37:41: Perfect, perfect Pablo.

00:37:42: thank you so much.

00:37:44: Thank you JP For giving us these presentations about this demo, the live demo execution.

00:37:51: One thing it's really important for us as a customers and SAP users is to understand that

00:37:58: they are

00:37:59: bad actors trying to attack SAP systems in try take any advantage from their way you configure your SAP system or the way your current SAP system has been used etc.

00:38:15: So I'm going to share my screen right now, you can see my screen.

00:38:22: Now that we know these bad actors are basically attacking SAP system regardless of their locations We also need help.

00:38:33: at the end of day SAP is gonna help tremendously providing a lot information regarding SAP issues But also, you need to have that extra set of eyes and not that extra solution.

00:38:48: That it's gonna provide information for you to understand where do you need put your security measures to protect a SAP system?

00:38:57: For that I wanted introduce the Trade Intel Center which is basically JPEG team in.

00:39:04: Pablo's team will use this specific page of the Naples Solution to provide communications about the latest and greatest states that they see in their world, right?

00:39:17: For SAP products.

00:39:20: So yesterday we gave you an idea from last week.

00:39:23: there was a new known public exploit that I was attacking or those focusing on specific vulnerability And this is the type of information that on apps it's going to provide weekly two SAP customers.

00:39:41: but also thinking about how you can protect your SAP environments, regardless of locations and regardless all the attacks.

00:39:49: About the latest and greatest strength?

00:39:50: How do we know...how don't we do

00:39:52: that?".

00:39:53: And part of information that SAP is going to release it's gonna help you tremendously in the sleeper.

00:39:57: Also You need to have another set of eyes with a set of knowledge That will provide the right and perfect information for you to protect SAP systems.

00:40:09: So imagine from last year We have this big, three one.

00:40:13: Three two four... This big vulnerability that was affecting every Java system they were.

00:40:22: we saw a lot of companies being breached and actually there's this huge company automotive company that was breached through the specific vulnerability And you know Through that specific attack A lot of components didn't know it exists but also they didn't have an easy way to understand what was that type of scenario?

00:40:45: What is the type of exploitation process.

00:40:48: So on Apsis Weekly, we released these types reports and information for our customers where you can see this specific issue about.

00:40:59: it doesn't matter if your system has some premise like an ECC system on BTP or it doesn't matter if is in cloud to like a, I don't know.

00:41:10: Like a sub rise type of environment.

00:41:13: Or NAPSIS has gathered all that information and its going put into the way that its readable for you And also you can understand what's currently happening but Also an easy way To see If your system might affect.

00:41:24: You Can See here In this example That our NAPSSIS telling us This Is Our demo Environment But It's also Telling Us Like This Java System Is Already Affected By That Vulnerability.

00:41:35: Also, we are providing information about what could be the worst outcome if you don't do anything regarding that issue.

00:41:43: And also the technical solution in this case is by applying a specific SAP note But just imagine it's at zero day train.

00:41:52: This something that SAP still hasn't released a patch

00:41:56: or

00:41:57: a fix for this bunality.

00:41:59: Fifty-five percent of the hot and critical news release last year by SAP through the regular patch Tuesday, they came from our research lab.

00:42:11: This is providing information about how powerful and knowledgeable it's our ONAPSYS Research Lab And this makes us special in different than any other competitor on the market.

00:42:25: Also for the ONAPPSYSSES product we can see that I have this huge report with all the vulnerabilities that are currently in my SAP landscape, and my SAP environment.

00:42:41: And regardless of where your SAP systems are located for example i'm going to go grab an SAP ABAP system a BTP web dispatcher cloud connector on S or HANA system or a HANA database .I can filter All those reports or those type of systems.

00:43:03: Also, if you can see some of these vulnerabilities are going to be disclosed for the first time by the synopsis research team and also they're gonna provide a way four customers for this specific zero-day threats to identify If They Are Affected through a test case that we'll release continuously on our synopses customer.

00:43:28: but also one thing that we always like to, or kind of put a little bit more effort is for the vulnerabilities are basically critical in our environment.

00:43:40: That we know they exist and their affecting our environment.

00:43:44: on apps it's also providing compensating controls.

00:43:47: so we have a threat monitoring capability where can build with matter-of-one click that it's going to monitor, is gonna help us monitor this specific issue for real time attacks.

00:44:04: So from the assessment point on up just when I be able to identify if we're affected front of different standpoint or not this one identified If someone is trying to take advantage off any of those vulnerabilities to this issue or not just again, it's going provide in-depth information about that issues.

00:44:28: It is gonna tell us where your environment that specific vulnerability is identified but also its gonna provide the necessary information for security teams to protect their SAP system.

00:44:42: Remember as a security team

00:44:44: normally

00:44:45: they don't have the SAP knowledge.

00:44:47: They dont' have SAP access to protect those environments, but at the end of day they are the ones responsible for maintaining an SAP system secure.

00:45:01: So what if we provide all that type of information?

00:45:04: For them to understand why it's happening?

00:45:07: okay What could be the worst outcome If you don't do anything regardless that specific vulnerability?

00:45:13: But also We're going to provide a technical solution step-by-step remediation So they can understand, okay these are the changes that need to happen in my environment.

00:45:23: To protect against specific vulnerability that was discovered through their on-app access assessment.

00:45:30: Also you will see an external reference.

00:45:33: More information about SAP notes that SAP released regarding this specific issue.

00:45:38: Sometimes we even put information from blogs and SAP blogs related or speak specifically of those issues.

00:45:48: you will have all the necessary information to understand what it's up.

00:45:54: Last one, but not least one part of the information that an apps success is providing us also visibility for our customers.

00:46:01: so we're gonna provide information about issues related to authorizations or anything related to SODs and user access et cetera configuration.

00:46:12: So depending on how your configured systems your ECCs Your cloud connectors your HANA databases, we can all grab that information and put it in a way that is riddled for you.

00:46:24: You're going to understand what do you need to do?

00:46:25: And how do you protect your SAP systems against those attacks?

00:46:30: also from the missing patches standpoint on how we can automate our process We will automate up to eighty percent of their process telling the customer only they know are missing For this specific environment now reducing time and effort used every second or two months.

00:46:47: And also from the code perspective, you know all those consumer sessions that are occurring on premise again or in BTPs.

00:46:54: Or if we're doing it depending off of language and developing SAP systems were going to provide information about the threats potentially being introduced into your production system.

00:47:08: how can protect and have a little bit of visibility?

00:47:17: Well, last one but not least is from the defense standpoint like I mentioned before on Napsys through their research team.

00:47:24: It's basically providing all the intelligence and all that knowledge regarding All this a p different products.

00:47:30: are we support again going from there?

00:47:33: You know they CC world to the BTP words to the clock connector web dispatcher subprime or napsis.

00:47:39: it's gonna provide information about those different scenarios in all those different products And what we can see here is a way to communicate

00:47:47: the

00:47:49: intelligence and their knowledge from all those products through our customers.

00:47:54: So they, that are customers can create compensating controls in money told there's a system for these real attacks that exist in the wild.

00:48:03: you know some of those like Pablo NGP were just presenting in a few minutes.

00:48:09: okay

00:48:11: so with that being said

00:48:12: I'm

00:48:13: going to stop sharing, but i want to give you my a couple last comments.

00:48:21: SAP is gonna help tremendously to protect your SAP systems.

00:48:24: You're gonna need a little bit more help.

00:48:26: from the intelligence standpoint Our Onapsis Research Lab is recognized in their work as number one protecting SAP system and SAP products.

00:48:38: So we recommend using our onapsis platform to do that type of protection and you don't maintain your business, protecting the most critical application in your company.

00:48:54: With that being said I believe Leah will continue or yes?

00:49:01: Great thank you

00:49:06: so much Hector!

00:49:07: That was great.

00:49:08: um i don't know JP did.

00:49:12: We can go straight to questions.

00:49:14: Yeah, we do have

00:49:17: a few.

00:49:17: I can wrap up and then will jump two questions straight.

00:49:21: yeah just some additional context for you keep as reference in terms of the demo that Hector was performing.

00:49:33: so yes all these potential risks identified and mitigated through technology, to their access platform.

00:49:42: We have different capabilities that you can leverage on the platform throughout automation.

00:49:49: That's a good objective of this part.

00:49:55: I think with that we had really time for some questions.

00:50:00: so Leah back too?

00:50:02: Awesome thank you so much guys!

00:50:04: This has been tremendously informative.

00:50:08: We did get a few questions and I think maybe we could start at the top.

00:50:12: In the first demo, why was the attacker able to reach the SOAP RSC ICF service if the cloud connectors access control didn't allow it?

00:50:27: I can grab that and that's very detailed observation.

00:50:32: so yes The difference is stuff in their third demo where the backer actually where you see the access control being blocked.

00:50:43: Where in a first demo, the attacker doesn't go through the CloudConnector.

00:50:47: The attacker goes though its own machine because the attacker has access to the Cloud Connector is supposed to have access to their on-prem system most likely and that's the reason why.

00:50:57: so when the attacker tries to reach the SOPRC it does not go thru the cloud connector or directly into the system.

00:51:03: if he should try to do this from the demo free you know, the access control will help love that.

00:51:12: and but yeah very very detailed for their spirit.

00:51:17: Great okay so let's pick another one here.

00:51:20: um

00:51:22: Let's see before any of this could I have found?

00:51:24: That over permissioned integration user Before an attacker did or Did i only learn about it after?

00:51:32: so who wants to jump

00:51:36: in on that one?

00:51:36: Okay Yeah, that's where technology comes into play.

00:51:40: Right?

00:51:41: So of course you can learn that after the fact... After you identify the incident or compromise but you can perform preemptive assessments for both the configuration and integrations on the code to be able to identify these type of issues beforehand And address them before somebody else takes advantage The ability to do that in an automated way.

00:52:09: That's what Hector showed through the Onassis platform demo.

00:52:16: Awesome, thank you.

00:52:17: I think we'll just Do one more question and this one seemed like a good one.

00:52:22: with all of the complexity introduced by integrations How do we keep security from always being a step behind?

00:52:32: Who'd like to take that on?

00:52:33: Okay i'll Take that because it somehow related.

00:52:37: today We cannot escape from this complexity.

00:52:43: The integrations, if anything are growing becoming more pervasive or complex.

00:52:52: integrating multiple applications now with AI agents in the mix also having a genetic frameworks pulling data from our business applications integrate it with SAS pass, EAS on-prem.

00:53:10: So in order for that to be able to be managed there's no other alternative rather than being able to have eyes on it and automation addressing identifying potentially insecure integrations potential over privileged users And also monitoring those systems those integrations, so I would say technology is one way to solve this and that's what we showed here as

00:53:47: well.

00:53:49: Great thanks JP.

00:53:50: i think that's a good question to leave off on.

00:53:54: For any other questions in the chat, we will reach out to you individually to get those answered.

00:53:59: And just a brief reminder for everyone that this is a session that's been recorded and we'll be sending the link out to your.

00:54:08: With that thanks again to JP part two and Hector providing insights into mind of an attacker on how develop plan close vulnerability gaps ensure SAP transformation secure.

00:54:21: Thanks, thanks presenters and have a great day everybody.

00:54:24: Thank you.

00:54:26: Have

00:54:27: a good

00:54:29: date!

About this podcast

Welcome to our Onapsis Podcast, a podcast brought to you by Onapsis, the global leader in SAP cybersecurity.

Join us as we delve into the fascinating world of safeguarding SAP systems from cyber threats and uncover the secrets to protecting your organization's most critical assets.

In each episode, our expert hosts and special guests will explore a variety of captivating topics surrounding SAP cybersecurity, shedding light on the challenges, best practices, and cutting-edge solutions that help businesses maintain the integrity and resilience of their SAP landscapes.
From the latest emerging threats to innovative techniques for vulnerability management and threat detection, our podcast provides invaluable insights for professionals working with SAP systems or those interested in learning more about the importance of securing the digital core.

Onapsis delivers complete SAP security for the autonomous enterprise, protecting critical SAP applications from AI-powered threats while securely accelerating SAP AI and RISE adoption. As the global leader in SAP cybersecurity and compliance, the SAP-endorsed Onapsis Platform leverages the unmatched threat intelligence from Onapsis Research Labs and our Agentic AI Fabric to proactively prevent breaches, automate continuous compliance, and secure custom code for a Clean Core across RISE with SAP, S/4HANA, and hybrid landscapes. You have a business to run — Onapsis protects your core so you can transform with speed and confidence without trade-offs. Connect with Onapsis on LinkedIn, X, or visit onapsis.com.

by Onapsis

Subscribe

Follow us