<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; sap security</title>
	<atom:link href="http://www.darknet.org.uk/tag/sap-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Onapsis Bizploit &#8211; ERP Penetration Testing Framework</title>
		<link>http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/</link>
		<comments>http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 10:33:30 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[bizploit]]></category>
		<category><![CDATA[bizsploit]]></category>
		<category><![CDATA[discovery]]></category>
		<category><![CDATA[erp penetration testing]]></category>
		<category><![CDATA[erp security]]></category>
		<category><![CDATA[erp security scanner]]></category>
		<category><![CDATA[erp vulnerability assessment]]></category>
		<category><![CDATA[exploration]]></category>
		<category><![CDATA[onapsis]]></category>
		<category><![CDATA[onapsis research labs]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[sap scanner]]></category>
		<category><![CDATA[sap security]]></category>
		<category><![CDATA[sap security scanner]]></category>
		<category><![CDATA[vulnerability-assessment]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2708</guid>
		<description><![CDATA[Bizploit is the first Opensource ERP Penetration Testing framework. Developed by the Onapsis Research Labs, Bizploit assists security professionals in the discovery, exploration, vulnerability assessment and exploitation phases of specialized ERP Penetration Tests. Bizploit is expected to provide the security community with a basic framework to support the discovery, exploration, vulnerability assessment and exploitation of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Bizploit is the first Opensource ERP Penetration Testing framework. Developed by the Onapsis Research Labs, Bizploit assists security professionals in the discovery, exploration, vulnerability assessment and exploitation phases of specialized ERP Penetration Tests.</p>
<p>Bizploit is expected to provide the security community with a basic framework to support the discovery, exploration, vulnerability assessment and exploitation of ERP systems.</p>
<p>The term &#8220;ERP Security&#8221; has been so far understood by most of the IT Security and Auditing industries as a synonym of “Segregation of Duties”. While this aspect is absolutely important for the overall security of the Organization&#8217;s core business platforms, there are many other threats that are still overlooked and imply much higher levels of risk. Onapsis Bizploit is designed as an academic proof-of-concept that will help the general community to illustrate and understand this kind of risks.</p>
<p>Currently Onapsis Bizploit provides all the features available in the <a href="http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/">sapyto</a> GPL project, plus several new plugins and connectors focused in the security of SAP business platforms. Updates for other popular ERPs are to be released in the short term.</p>
<p>You can download Bizploit here:</p>
<p><a href="http://www.onapsis.com/resources/get.php?resid=bizploit-win32">Bizploit v1.00-rc1 for Windows</a><br />
<a href="http://www.onapsis.com/resources/get.php?resid=bizploit-linux">Bizploit v1.00-rc1 for Linux</a></p>
<p></p>
<p>Or read more <a href="http://www.onapsis.com/research.html#bizploit">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Onapsis+Bizploit+%E2%80%93+ERP+Penetration+Testing+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2708+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/&amp;t=Onapsis+Bizploit+%E2%80%93+ERP+Penetration+Testing+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/&amp;title=Onapsis+Bizploit+%E2%80%93+ERP+Penetration+Testing+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/&amp;title=Onapsis+Bizploit+%E2%80%93+ERP+Penetration+Testing+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/&amp;title=Onapsis+Bizploit+%E2%80%93+ERP+Penetration+Testing+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/&amp;title=Onapsis+Bizploit+%E2%80%93+ERP+Penetration+Testing+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F06%2Fonapsis-bizploit-erp-penetration-testing-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/06/onapsis-bizploit-erp-penetration-testing-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sapyto v0.98 Released &#8211; SAP Penetration Testing Framework Tool</title>
		<link>http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/</link>
		<comments>http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 04:57:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[hacking sap]]></category>
		<category><![CDATA[sap]]></category>
		<category><![CDATA[sap auditing]]></category>
		<category><![CDATA[sap penetration testing]]></category>
		<category><![CDATA[sap security]]></category>
		<category><![CDATA[sap testing framework]]></category>
		<category><![CDATA[sapyto]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1310</guid>
		<description><![CDATA[sapyto is the first SAP Penetration Testing Framework, sapyto provides support to information security professionals in SAP platform discovery, investigation and exploitation activities. sapyto is periodically updated with the outcome of the deep research on the various security aspects in SAP systems. Although sapyto is a versatile and powerful tool, it is of major importance [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>sapyto is the first SAP Penetration Testing Framework, sapyto provides support to information security professionals in SAP platform discovery, investigation and exploitation activities.</p>
<p>sapyto is periodically updated with the outcome of the deep research on the various security aspects in SAP systems.</p>
<p>Although sapyto is a versatile and powerful tool, it is of major importance for it to be used by consultants who are highly skilled and specialized in its usage, preventing any interference with your organization’s usual SAP operation.</p>
<p><strong>New in This Version</strong></p>
<p>This version is mainly a complete re-design of sapyto&#8217;s core and architecture to support future releases. Some of the new features now available are:</p>
<ul>
<li>Target configuration is now based on &#8220;connectors&#8221;, which represent different ways to communicate with SAP services and components. This makes the<br />
framework extensible to handle new types of connections to SAP platforms.</li>
<li>Plugins are now divided in three categories: Discovery, Audit &#038; Exploit.</li>
<li>Exploit plugins now generate shells and/or sapytoAgent objects.</li>
<li>New plugins!: User account bruteforcing, client enumeration, SAProuter assessment, and more&#8230;</li>
<li>Plugin-developer interface drastically simplified and improved.</li>
<li>New command switches to allow the configuration of targets/scripts/output independently.</li>
<li>Installation process and general documentation improved.</li>
</ul>
<p>You can download sapyto v0.98 here (you may have to fill in a form):</p>
<p><a href="http://www.cybsec.com/otd/otd_form.php?lang=en&#038;form=sapyto">sapyto Public Edition (v0.98)</a></p>
<p></p>
<p>Or read more <a href="http://www.cybsec.com/EN/research/sapyto.php">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sapyto+v0.98+Released+%E2%80%93+SAP+Penetration+Testing+Framework+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1310+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/&amp;t=sapyto+v0.98+Released+%E2%80%93+SAP+Penetration+Testing+Framework+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/&amp;title=sapyto+v0.98+Released+%E2%80%93+SAP+Penetration+Testing+Framework+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/&amp;title=sapyto+v0.98+Released+%E2%80%93+SAP+Penetration+Testing+Framework+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/&amp;title=sapyto+v0.98+Released+%E2%80%93+SAP+Penetration+Testing+Framework+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/&amp;title=sapyto+v0.98+Released+%E2%80%93+SAP+Penetration+Testing+Framework+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fsapyto-v098-released-sap-penetration-testing-framework-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/sapyto-v098-released-sap-penetration-testing-framework-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

