sapyto is the first SAP Penetration Testing Framework, sapyto provides support to information security professionals in SAP platform discovery, investigation and exploitation activities.
sapyto is periodically updated with the outcome of the deep research on the various security aspects in SAP systems.
Although sapyto is a versatile and powerful tool, it is of major importance for it to be used by consultants who are highly skilled and specialized in its usage, preventing any interference with your organization’s usual SAP operation.
New in This Version
This version is mainly a complete re-design of sapyto’s core and architecture to support future releases. Some of the new features now available are:
- Target configuration is now based on “connectors”, which represent different ways to communicate with SAP services and components. This makes the
framework extensible to handle new types of connections to SAP platforms.
- Plugins are now divided in three categories: Discovery, Audit & Exploit.
- Exploit plugins now generate shells and/or sapytoAgent objects.
- New plugins!: User account bruteforcing, client enumeration, SAProuter assessment, and more…
- Plugin-developer interface drastically simplified and improved.
- New command switches to allow the configuration of targets/scripts/output independently.
- Installation process and general documentation improved.
You can download sapyto v0.98 here (you may have to fill in a form):
Or read more here.