“SAP from an Attacker's Perspective”: usd Experts Speaking at German OWASP Day 2024

8. November 2024

The German Chapter of the Open Worldwide Application Security Project (OWASP) is once again organizing its national conference this year. On November 12 and 13, a variety of seminars, talks and evening events await all interested participants in Leipzig - all with the aim of sharing knowledge and experience.

The main event day on November 13, 2024 in particular offers a wide range of technical and non-technical presentations on the topic of application security. Experts from usd will also be speaking on the topic: „SAP from an Attacker's Perspective – Common Vulnerabilities and Pitfalls“.

Nicolas Schickert and Ole Wagner, pentesters at usd HeroLab, regularly conduct pentests of SAP systems and are aware of the special aspects, required expertise and pitfalls that are important when analyzing SAP infrastructures. They would therefore like to share their findings from a large number of tests with the community.

„The security of SAP systems is an increasing challenge for companies. Our presentation will highlight common vulnerabilities and attack vectors in SAP systems from an attacker's perspective and offer practical advice on how to mitigate these threats. Using examples and tools such as our sncscan, we want to show administrators and other security experts how they can evaluate encryption and signing settings of SAP systems to ensure the confidentiality and integrity of sensitive data.“

Nicolas Schickert, usd HeroLab

In view of the important role of the German OWASP Day for the exchange between security experts, usd AG also supports the event as a sponsor.


About OWASP:

The Open Worldwide Application Security Project (OWASP) is a non-profit organization with the aim of improving the security of applications, services and software in general. By creating transparency, end users and organizations should be able to make informed decisions about real security risks in software.

Therefore, OWASP helps build impactful projects, develops and nurtures communities through events and chapter meetings worldwide, and provides publications and resources to enable developers to write better software and empower security professionals to make software more secure.


Update 14 November 2024: Recording avaible

For anyone who could not participate in Leipzig, the Chaos Computer Club streamed all sessions and made the recoding of our talk available here: https://media.ccc.de/v/god2024-56278-sap-from-an-attackers-pers

Also interesting:

Andrea Tubach is the new CEO of usd AG

Andrea Tubach is the new CEO of usd AG

Yesterday, at usd's Annual General Meeting and the subsequent meeting of the new Supervisory Board, long-prepared personnel changes were unanimously approved and then celebrated with an atmosphere of deep friendship: Andrea Tubach takes over as CEO. The founder and...

Security Advisories on Vtiger

Security Advisories on Vtiger

The pentest professionals at usd HeroLab examined Vtiger Open Source Edition 8.2.0 during the execution of their pentests. Our analysts discovered two vulnerabilities in the Vtiger software that allow low-privileged authorized users to upload files and execute...

NIS-2 Draft Bill under Examination: Everything You Need to Know

NIS-2 Draft Bill under Examination: Everything You Need to Know

A few days ago, the AG KRITIS published the latest draft bill on the NIS-2 Implementation Law (NIS2UmsuCG) on its website. Which requirements could become relevant for you if the law is passed in this version? Our experts have analyzed the draft for you and summarized...

Categories

Categories