Penetration Testing mailing list archives
SAP R/3 password encryption ?
From: Petr.Kazil () eap nl
Date: Thu, 2 Feb 2006 17:15:49 +0100
One of our customers with access to a SAP system found a query that lists password changes. It shows both the old and new passwords in encrypted format. He was wondering if these password hashes might be crackable. I'm no SAP specialist and if you don't have a SAP account it's hard to get any documentation. But to me it looks like a password hash that might be vulnerable to a dictionary attack. But I don't know whether SAP uses something common (like SHA) or a proprietary algorithm. The password dumps look like this: Old value: New value: |D624B6DF0C787DBC||21621AFB43G9726F| (I changed some values.) |0000000000000000||75ADC566FA921A4A| Does anyone have more information about the encrytion algorithm? I tried to get the information from SAP specialists who gave a course to my colleagues, but they didn't know either. Greetings, Petr Kazil ------------------------------------------------------------------------------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 -------------------------------------------------------------------------------
Current thread:
- Black Hat USA CFP opens, Europe early bird reminder, Federal news Jeff Moss (Feb 01)
- SAP R/3 password encryption ? Petr . Kazil (Feb 02)
- Re: SAP R/3 password encryption ? Tim (Feb 05)
- Re: SAP R/3 password encryption ? Petr . Kazil (Feb 05)
- Re: SAP R/3 password encryption ? Tim (Feb 05)
- SAP R/3 password encryption ? Petr . Kazil (Feb 02)