Hacker conference to address emerging Web threats

The four-day conference will address enterprise applications, hardware and big-picture Internet issues

The Black Hat security conference will kick off next week in Barcelona, with training sessions and briefings from some of the most talented security researchers in the industry.

Facebook's chief security officer, Max Kelly, is scheduled for a keynote presentation on Wednesday morning following two days of training sessions. The last two days of the conference will focus on briefings featuring research into a variety of threats on the Internet and application vulnerabilities.

One of those presentations will focus on a way to insert a backdoor into SAP's ERP (enterprise resource planning) applications. SAP's business software is often the core of a company's operations and is used to manage invoicing, human resources, procurement and billing, among many other functions.

SAP's software uses databases from companies such as Oracle, said Mariano Nuñez Di Croce, director of research and development for Onapsis, a company that focuses on penetration testing for SAP systems and others such as Oracle's PeopleSoft and JD Edwards enterprise applications.

Many companies do not configure the Oracle database correctly, which makes the SAP system vulnerable to attack.

"What we have found is, it is possible instead of modifying the program you can connect to the database and modify the code directly in the database," Nuñez Di Croce said.

The problem with SAP and the Oracle database has been known for a few years, although Nuñez Di Croce recently figured out how to slip a "backdoor" into a program in the database that can then send data to a remote hacker. Since the Oracle database does not conduct an integrity check of the source code, the attack would be difficult to detect.

It would allow an attacker, for example, to forward all information related to a new customer account. It could also let a hacker modify shipping orders or collect the log-in details when employees log on to the SAP system, he said.

"It's amazing to see how many experienced SAP customers don't know about this vulnerability," Nuñez Di Croce said.

SAP responded that what Onapsis found is "not a specific vulnerability."

"We have been made aware of the issue by Onapsis and have reviewed it. We believe that if customers follow our guidelines for security, the risk of illegitimate access through a backdoor can be excluded," SAP said in a statement.

"SAP focuses on preventing illegitimate access to SAP systems, rather than detecting manipulation within the database," the company added. It said it takes security issues "very seriously."

Nuñez Di Croce's company plans later this month to release a tool that will check to ensure applications within the database haven't been tampered with. The tool is called the Onapsis Integrity Analyzer for SAP.

It creates a hash value, or a unique numerical identifier based on the source code for applications. If the tool scans an application later and it has a different hash value, it may have been tampered with, indicating a backdoor, Nuñez Di Croce said.

Nuñez Di Croce's presentation will be in Black Hat's application security track. The conference will have two other tracks, one focusing on the "big picture" security issues and one dedicated to hardware, according to the conference schedule.

In the big picture track, Stephan Chenette, principal security researcher for Websense Security Labs, will give a presentation on a project called Fireshark. The project aims to streamline collecting information on the tens of thousands of Web sites that may contain malicious code and are designed to attack unsuspecting visitors.

Fireshark "is capable of visiting large collections of Web sites at a time, executing, storing and analyzing the content and from it identifying hundreds of malicious ecosystems," Chenette wrote on Black Hat's Web site.

Join the PC World newsletter!

Error: Please check your email address.

Tags securityblack hathacking

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?