Uncovering SAP Vulnerabilities - Dissecting and Breaking the Diag Protocol
BruCON Security Conference via YouTube
Google AI Professional Certificate - Learn AI Skills That Get You Hired
Finance Certifications Goldman Sachs & Amazon Teams Trust
Overview
Syllabus
Intro
Agenda
Introduction
Previous work on Diag protocol
Motivation
SAP Netweaver architecture
Relevant concepts and components
SAP Protocols layout
Dissecting and understanding the Diag protocol
Diag protocol security highlights
Packet dissection - SAP plugin for Wireshark
Packet crafting - pysap
Fuzzing approach
Vulnerabilities found
Attack scenarios
Recent changes
Defenses and countermeasures
Conclusion
Future work
Taught by
BruCON Security Conference