Penetration Testing mailing list archives

SAP R/3 password encryption ?


From: Petr.Kazil () eap nl
Date: Thu, 2 Feb 2006 17:15:49 +0100

One of our customers with access to a SAP system found a query that lists 
password changes.
It shows both the old and new passwords in encrypted format. He was 
wondering if these password hashes might be crackable. I'm no SAP 
specialist and if you don't have a SAP account it's hard to get any 
documentation.

But to me it looks like a password hash that might be vulnerable to a 
dictionary attack. But I don't know whether SAP uses something common 
(like SHA) or a proprietary algorithm. The password dumps look like this:

Old value:         New value:
|D624B6DF0C787DBC||21621AFB43G9726F| (I changed some values.)
|0000000000000000||75ADC566FA921A4A|

Does anyone have more information about the encrytion algorithm? I tried 
to get the information from SAP specialists who gave a course to my 
colleagues, but they didn't know either.

Greetings, Petr Kazil

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: