TROOPERS23: Everyone knows SAP, everyone uses SAP, everyone uses RFC, no one knows RFC

  Рет қаралды 773

TROOPERS IT Security Conference

TROOPERS IT Security Conference

11 ай бұрын

Talk by Fabian Hagg - June 29th, 2023 at TROOPERS23 IT security conference in Heidelberg, Germany hosted by @ERNW_ITSec
#TROOPERS23 #ITsecurity
troopers.de/troopers23/talks/...
More impressions:
/ wearetroopers
/ ernw_itsec
infosec.exchange/@WEareTROOPERS
infosec.exchange/@ERNW
ernw.de

Пікірлер: 1
@j.goerlich3227
@j.goerlich3227 10 ай бұрын
19:12 When comparing to the description given in SAP Note 2216306, one hase to refrain from setting values for which it is stated 'In the case of an RFC logon in the same system with the same user and client, no authorization check is executed.' and additionally the ones which only take effect for some FuBas 'if this is called from SAP GUI' (for other reasons). Knowing this, I end up with the value '2' (obsolete) and '9'. For the value '9' SAP states 'this value scarcely brings about any security improvement in comparison with the value 6.' It seems this statement misses the while internal conversation scenario. SAP should reconsider their recommendation. 47:13 Some month ago, I convinced SAP to make an adjustment in the UCON framework, as it blocked the assignment of certain function modules (mostly of group SRFC) to the SNC_CA. The fix was provided in SAP note 3352382.
TROOPERS23: Testing and Fuzzing the Kubernetes Admission Configuration
56:10
TROOPERS IT Security Conference
Рет қаралды 321
SAP Navigation For Beginners
16:16
QMS, Inc.
Рет қаралды 115 М.
Sigma Kid Hair #funny #sigma #comedy
00:33
CRAZY GREAPA
Рет қаралды 37 МЛН
Каха заблудился в горах
00:57
К-Media
Рет қаралды 8 МЛН
TROOPERS23: Beyond Java: Obfuscating Android Apps with Purely Native Code
1:02:04
TROOPERS IT Security Conference
Рет қаралды 169
What is an API?
3:25
MuleSoft Videos
Рет қаралды 5 МЛН
Gitlab Group Runner sharing on multiple Repositories and save it.
11:54
TROOPERS23: Monitoring Solutions: Attacking IT Infrastructure at its Core
56:41
TROOPERS IT Security Conference
Рет қаралды 501
TROOPERS23: Forensic analysis on real incidents inside Microsoft Remote Desktop Services
42:51
TROOPERS23: OAuth and Proof of Possession - The long way round
45:29
TROOPERS IT Security Conference
Рет қаралды 403
TROOPERS23: Horror Stories from the Automotive Industry
41:56
TROOPERS IT Security Conference
Рет қаралды 616
iPhone socket cleaning #Fixit
0:30
Tamar DB (mt)
Рет қаралды 17 МЛН
Проверил, как вам?
0:58
Коннор
Рет қаралды 13 М.
Looks very comfortable. #leddisplay #ledscreen #ledwall #eagerled
0:19
LED Screen Factory-EagerLED
Рет қаралды 6 МЛН
НОВЫЕ ФЕЙК iPHONE 🤯 #iphone
0:37
ALSER kz
Рет қаралды 327 М.