Home > SAP News > SAP applications could be hacked, expert warns
SAP News:
EMAIL THIS LICENSING & REPRINTS

SAP applications could be hacked, expert warns

By Robert Westervelt, News Editor
14 Sep 2006 | SearchSAP.com

SAP news, tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

LAS VEGAS -- If you think your applications are secure, think again.

By running a few lines of script a determined hacker could bypass a company firewall and trick an application to gain sensitive information. Web-based SAP applications are at great risk because firewalls and intrusion detection systems give a false sense of security, according to Andreas Wiegenstein, who serves as chief technology officer of Germany-based application security firm Virtual Forge.

"With applications, it's all about the side effects that you don't think about," Wiegenstein said.

In a presentation at the SAP TechEd 2006 conference, Wiegenstein highlighted the top five application security threats and how NetWeaver developers can avoid them.

SQL injection

An attacker could execute arbitrary SQL commands remotely on applications that directly create and execute SQL statements, Wiegenstein said. Hackers could manipulate SQL requests to change the content of a database table. The vulnerability also allows hackers to execute a shell command on a Web server leaking potentially sensitive data, Wiegenstein said.

Prepared statements should be used as a countermeasure where possible. A prepared statement gets a placeholder for data input, enabling an application to better protect itself, Wiegenstein said.

The latest from SAP TechEd:

SAP promises no major software release until 2010

SAP Muse interface could be next business browser

Cross-site scripting

All applications that create HTML GUIs are vulnerable to cross-site scripting, Wiegenstein said. This type of attack tricks a server into believing a hacker is a legitimate user.

To avoid cross- site scripting, HTML should be rendered through Web Dynpro, a programming model for user interfaces. Wiegenstein suggests that companies concerned about this issue should consult a security expert.

"This is a very difficult problem to solve," he said. "No company has succeeded in solving this problem themselves."

Cookie poisoning

There are false assumptions that cookies can't be manipulated, according to Wiegenstein, but a good hacker can trick application logic by changing a cookie value.

SAP customers should avoid storing important information, such as an item price, in a server-side cookie, he said. The use of Web Dynpro also helps alleviate this problem, he said.

Client-side validation

If an attacker is not using a browser or a modified tool to gain remote access to a company's systems, applications that rely on client-side validation are at high risk, Wiegenstein said. A hacker can trick the application logic by manipulating a validated value, he said.

Companies should not rely on client-side validation to avoid this problem, he said. Validation should also be repeated on the server.

Forceful browsing

With forceful browsing, a hacker can trick the application logic enabling buttons or other resources within an application menu that should be unavailable, Wiegenstein said. In a demonstration, Wiegenstein showed how an attacker could enable an edit function on a bill of sale, which is only available to an administrator

"An attacker can cause a server to skip the same validations," he said.

The use of Web Dynpro and authority checks for actions originating from a client will alleviate the vulnerability, Wiegenstein said.

The most important countermeasures for all five attacks is for a company to be proactive with security, Wiegenstein said. Start planning by setting a security policy, get help from experts and hold security trainings to avoid the most common security mistakes among employees, he said.

"Many companies fail to build in security when developing an application," Wiegenstein said. "You can't just build something and add on security like it's glue. That doesn't work."

Sound Off! -   Be the first to post a message to Sound Off!


Tags: SAP securitySAP trends and market projectionsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


HomeNewsTopicsBlogsTipsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
SearchSAP.com is a search service provided by TechTarget and is completely
independent of and not affiliated with SAP AG.
  TechTarget - The IT Media ROI Experts