{"id":2493,"date":"2019-05-04T03:18:37","date_gmt":"2019-05-03T20:18:37","guid":{"rendered":"https:\/\/humanit.asia\/?p=2493"},"modified":"2019-07-22T13:41:26","modified_gmt":"2019-07-22T06:41:26","slug":"aa19-122a","status":"publish","type":"post","link":"https:\/\/old.humanit.asia\/th\/aa19-122a\/","title":{"rendered":"AA19-122A: New Exploits for Unsecure SAP Systems"},"content":{"rendered":"<div>Original release date: May 02, 2019 | Last revised: May 03, 2019<\/p>\n<h3>Summary<\/h3>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) is issuing this activity alert in response to recently disclosed exploits that target unsecure configurations of SAP components. [<a href=\"https:\/\/github.com\/comaeio\/OPCDE\/tree\/master\/2019\/Emirates\/(SAP)%20Gateway%20to%20Heaven%20-%20Dmitry%20Chastuhin%2C%20Mathieu%20Geli\">1<\/a>]<\/p>\n<h3>Technical Details<\/h3>\n<p>A presentation at the April 2019 Operation for Community Development and Empowerment (OPCDE) cybersecurity conference describes SAP systems with unsecure configurations exposed to the internet. Typically, SAP systems are not intended to be exposed to the internet as it is an untrusted network. Malicious cyber actors can attack and compromise these unsecure systems with publicly available exploit tools, termed \u201c10KBLAZE.\u201d The presentation details the new exploit tools and reports on systems exposed to the internet.<\/p>\n<h4>SAP Gateway ACL<\/h4>\n<p>The SAP Gateway allows non-SAP applications to communicate with SAP applications. If SAP Gateway access control lists (ACLs) are not configured properly (e.g., gw\/acl_mode = 0), anonymous users can run operating system (OS) commands.[<a href=\"https:\/\/wiki.scn.sap.com\/wiki\/display\/SI\/Gateway+Access+Control+Lists\">2<\/a>] According to the OPCDE presentation, about 900 U.S. internet-facing systems were detected in this vulnerable condition.<\/p>\n<h4>SAP Router secinfo<\/h4>\n<p>The SAP router is a program that helps connect SAP systems with external networks. The default <code>secinfo<\/code> configuration for a SAP Gateway allows any internal host to run OS commands anonymously. If an attacker can access a misconfigured SAP router, the router can act as an internal host and proxy the attacker\u2019s requests, which may result in remote code execution.<\/p>\n<p>According to the OPCDE presentation, 1,181 SAP routers were exposed to the internet. It is unclear if the exposed systems were confirmed to be vulnerable or were simply running the SAP router service.<\/p>\n<h4>SAP Message Server<\/h4>\n<p>SAP Message Servers act as brokers between Application Servers (AS). By default, Message Servers listen on a port 39XX and have no authentication. If an attacker can access a Message Server, they can redirect and\/or execute legitimate man-in-the-middle (MITM) requests, thereby gaining credentials. Those credentials can be used to execute code or operations on AS servers (assuming the attacker can reach them). According to the OPCDE presentation, there are 693 Message Servers exposed to the internet in the United States. The Message Server ACL must be protected by the customer in all releases.<\/p>\n<h4>Signature<\/h4>\n<p>CISA worked with security researchers from Onapsis Inc.[<a href=\"https:\/\/www.onapsis.com\/\">3<\/a>] to develop the following Snort signature that can be used to detect the exploits:<\/p>\n<div style=\"background: #eeeeee; padding: 5px 10px; border: 1px solid #cccccc;\">alert tcp $EXTERNAL_NET any -&gt; $HOME_NET any (msg:&#8221;10KBLAZE SAP Exploit execute attempt&#8221;; flow:established,to_server; content:&#8221;|06 cb 03|&#8221;; offset:4; depth:3; content:&#8221;SAPXPG_START_XPG&#8221;; nocase; distance:0; fast_pattern; content:&#8221;37D581E3889AF16DA00A000C290099D0001&#8243;; nocase; distance:0; content:&#8221;extprog&#8221;; nocase; distance:0; sid:1; rev:1;)<\/div>\n<h3>Mitigations<\/h3>\n<p>CISA recommends administrators of SAP systems implement the following to mitigate the vulnerabilities included in the OPCDE presentation:<\/p>\n<ul>\n<li>Ensure a secure configuration of their SAP landscape.<\/li>\n<li>Restrict access to SAP Message Server.\n<ul>\n<li>Review SAP Notes 1408081 and 821875. Restrict authorized hosts via ACL files on Gateways (<code>gw\/acl_mode <\/code>and <code>secinfo<\/code>) and Message Servers (<code>ms\/acl_info<\/code>).[<a href=\"https:\/\/launchpad.support.sap.com\/#\/notes\/1408081\">4<\/a>], [<a href=\"https:\/\/launchpad.support.sap.com\/#\/notes\/821875\">5<\/a>]<\/li>\n<li>Review SAP Note 1421005. Split MS internal\/public:<code> rdisp\/msserv=0 rdisp\/msserv_internal=39NN<\/code>. [<a href=\"https:\/\/launchpad.support.sap.com\/#\/notes\/1421005\">6<\/a>]<\/li>\n<li>Restrict access to Message Server internal port (<code>tcp\/39NN<\/code>) to clients or the internet.<\/li>\n<li>Enable Secure Network Communications (SNC) for clients.<\/li>\n<\/ul>\n<\/li>\n<li>Scan for exposed SAP components.\n<ul>\n<li>Ensure that SAP components are not exposed to the internet.<\/li>\n<li>Remove or secure any exposed SAP components.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3>References<\/h3>\n<ul>\n<li><a href=\"https:\/\/github.com\/comaeio\/OPCDE\/tree\/master\/2019\/Emirates\/(SAP)%20Gateway%20to%20Heaven%20-%20Dmitry%20Chastuhin%2C%20Mathieu%20Geli\">[1] Comae Technologies: Operation for Community Development and Empowerment (OPCDE) Cybersecurity Conference Materials <\/a><\/li>\n<li><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/display\/SI\/Gateway+Access+Control+Lists\">[2] SAP: Gateway Access Control Lists <\/a><\/li>\n<li><a href=\"https:\/\/www.onapsis.com\/\">[3] Onapsis Inc. website <\/a><\/li>\n<li><a href=\"https:\/\/launchpad.support.sap.com\/#\/notes\/1408081\">[4] SAP Note 1408081 <\/a><\/li>\n<li><a href=\"https:\/\/launchpad.support.sap.com\/#\/notes\/821875\">[5] SAP Note 821875 <\/a><\/li>\n<li><a href=\"https:\/\/launchpad.support.sap.com\/#\/notes\/1421005\">[6] SAP Note 1421005 <\/a><\/li>\n<\/ul>\n<h3>Revisions<\/h3>\n<ul>\n<li>May 2, 2019: Initial version<\/li>\n<\/ul>\n<hr \/>\n<p>This product is provided subject to this <a href=\"http:\/\/www.us-cert.gov\/privacy\/notification\">Notification<\/a> and this <a href=\"http:\/\/www.us-cert.gov\/privacy\/\">Privacy &amp; Use<\/a> policy.<\/p>\n<\/div>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener noreferrer\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original release date: May 02, 2019 | Last revised: May [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2030,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[106],"tags":[],"class_list":["post-2493","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alerts-th"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AA19-122A: New Exploits for Unsecure SAP Systems - humanit managed services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/old.humanit.asia\/aa19-122a\/\" \/>\n<meta property=\"og:locale\" content=\"th_TH\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AA19-122A: New Exploits for Unsecure SAP Systems - humanit managed services\" \/>\n<meta property=\"og:description\" content=\"Original release date: May 02, 2019 | Last revised: May [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/old.humanit.asia\/aa19-122a\/\" \/>\n<meta property=\"og:site_name\" content=\"humanit managed services\" \/>\n<meta property=\"article:published_time\" content=\"2019-05-03T20:18:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-22T06:41:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/old.humanit.asia\/wp-content\/uploads\/2018\/08\/308-name05821-chim-eye.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1680\" \/>\n\t<meta property=\"og:image:height\" content=\"1154\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u0e19\u0e32\u0e17\u0e35\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"headline\":\"AA19-122A: New Exploits for Unsecure SAP Systems\",\"datePublished\":\"2019-05-03T20:18:37+00:00\",\"dateModified\":\"2019-07-22T06:41:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/\"},\"wordCount\":579,\"image\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/old.humanit.asia\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/308-name05821-chim-eye.jpg\",\"articleSection\":[\"Alerts\"],\"inLanguage\":\"th\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/\",\"url\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/\",\"name\":\"AA19-122A: New Exploits for Unsecure SAP Systems - humanit managed services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/old.humanit.asia\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/308-name05821-chim-eye.jpg\",\"datePublished\":\"2019-05-03T20:18:37+00:00\",\"dateModified\":\"2019-07-22T06:41:26+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/#breadcrumb\"},\"inLanguage\":\"th\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"th\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/#primaryimage\",\"url\":\"https:\\\/\\\/old.humanit.asia\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/308-name05821-chim-eye.jpg\",\"contentUrl\":\"https:\\\/\\\/old.humanit.asia\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/308-name05821-chim-eye.jpg\",\"width\":1680,\"height\":1154},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/aa19-122a\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/old.humanit.asia\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AA19-122A: New Exploits for Unsecure SAP Systems\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\",\"url\":\"https:\\\/\\\/old.old.humanit.asia\\\/\",\"name\":\"humanit managed services\",\"description\":\"making technology easy\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/old.old.humanit.asia\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"th\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"th\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"caption\":\"Admin\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AA19-122A: New Exploits for Unsecure SAP Systems - humanit managed services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/old.humanit.asia\/aa19-122a\/","og_locale":"th_TH","og_type":"article","og_title":"AA19-122A: New Exploits for Unsecure SAP Systems - humanit managed services","og_description":"Original release date: May 02, 2019 | Last revised: May [&hellip;]","og_url":"https:\/\/old.humanit.asia\/aa19-122a\/","og_site_name":"humanit managed services","article_published_time":"2019-05-03T20:18:37+00:00","article_modified_time":"2019-07-22T06:41:26+00:00","og_image":[{"width":1680,"height":1154,"url":"https:\/\/old.humanit.asia\/wp-content\/uploads\/2018\/08\/308-name05821-chim-eye.jpg","type":"image\/jpeg"}],"author":"Admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Admin","Est. reading time":"3 \u0e19\u0e32\u0e17\u0e35"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/old.humanit.asia\/aa19-122a\/#article","isPartOf":{"@id":"https:\/\/old.humanit.asia\/aa19-122a\/"},"author":{"name":"Admin","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"headline":"AA19-122A: New Exploits for Unsecure SAP Systems","datePublished":"2019-05-03T20:18:37+00:00","dateModified":"2019-07-22T06:41:26+00:00","mainEntityOfPage":{"@id":"https:\/\/old.humanit.asia\/aa19-122a\/"},"wordCount":579,"image":{"@id":"https:\/\/old.humanit.asia\/aa19-122a\/#primaryimage"},"thumbnailUrl":"https:\/\/old.humanit.asia\/wp-content\/uploads\/2018\/08\/308-name05821-chim-eye.jpg","articleSection":["Alerts"],"inLanguage":"th"},{"@type":"WebPage","@id":"https:\/\/old.humanit.asia\/aa19-122a\/","url":"https:\/\/old.humanit.asia\/aa19-122a\/","name":"AA19-122A: New Exploits for Unsecure SAP Systems - humanit managed services","isPartOf":{"@id":"https:\/\/old.old.humanit.asia\/#website"},"primaryImageOfPage":{"@id":"https:\/\/old.humanit.asia\/aa19-122a\/#primaryimage"},"image":{"@id":"https:\/\/old.humanit.asia\/aa19-122a\/#primaryimage"},"thumbnailUrl":"https:\/\/old.humanit.asia\/wp-content\/uploads\/2018\/08\/308-name05821-chim-eye.jpg","datePublished":"2019-05-03T20:18:37+00:00","dateModified":"2019-07-22T06:41:26+00:00","author":{"@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"breadcrumb":{"@id":"https:\/\/old.humanit.asia\/aa19-122a\/#breadcrumb"},"inLanguage":"th","potentialAction":[{"@type":"ReadAction","target":["https:\/\/old.humanit.asia\/aa19-122a\/"]}]},{"@type":"ImageObject","inLanguage":"th","@id":"https:\/\/old.humanit.asia\/aa19-122a\/#primaryimage","url":"https:\/\/old.humanit.asia\/wp-content\/uploads\/2018\/08\/308-name05821-chim-eye.jpg","contentUrl":"https:\/\/old.humanit.asia\/wp-content\/uploads\/2018\/08\/308-name05821-chim-eye.jpg","width":1680,"height":1154},{"@type":"BreadcrumbList","@id":"https:\/\/old.humanit.asia\/aa19-122a\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/old.humanit.asia\/"},{"@type":"ListItem","position":2,"name":"AA19-122A: New Exploits for Unsecure SAP Systems"}]},{"@type":"WebSite","@id":"https:\/\/old.old.humanit.asia\/#website","url":"https:\/\/old.old.humanit.asia\/","name":"humanit managed services","description":"making technology easy","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/old.old.humanit.asia\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"th"},{"@type":"Person","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c","name":"Admin","image":{"@type":"ImageObject","inLanguage":"th","@id":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","caption":"Admin"}}]}},"_links":{"self":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/comments?post=2493"}],"version-history":[{"count":2,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2493\/revisions"}],"predecessor-version":[{"id":2846,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2493\/revisions\/2846"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/media\/2030"}],"wp:attachment":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/media?parent=2493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/categories?post=2493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/tags?post=2493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}