Skip to main content

New SAPocalypse worm will be presented at HITBSecConf2011 - Malaysia

posted onOctober 5, 2011
by l33tdawg

L33tdawg: Further details of Alexander Polyakov's SAPocalypse presentation is here. Online registration closes on the 7th but walk-in registrations are still accepted there after.

Two months have passed since the report on critical vulnerability in SAP's J2EE engine was published. Though it is a serious vulnerability, some people didn't estimate it, pointing to the fact that only systems on the JAVA basis which sometimes don't store critical data, as ERP or BI do and used for these systems' connection and collaboration.

In a new report which will be presented at the HITB conference in Malaysia, ERPScan specialists will show prototype of a new worm with a code name SAPacalypse. It will use a vulnerability in SAP NetWeaver JAVA server, available via the Internet and then connects to the connected ABAP servers in the internal network, where ERP, CRM, BI and other applications can be installed. After it virus steals critical data and data for connection to other linked servers from these systems. Taking into account a deep integration of business processes and as a result a multiple connections using internal links, it will allow to get into almost any corporate systems via the only vulnerable.

Source

Tags

Security HITB2011KUL HITBSecConf SAP

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th