ã¿ãªãããããã«ã¡ã¯ãç§ã®ååã¯Vahagn Vardanyanã§ãïŒå€ãã®äººãèããããã«ãã¿ã€ããã¹ã¯ãããŸãã:)ïŒãç§ã¯DSecã§SAPã·ã¹ãã ã®ã»ãã¥ãªãã£ç ç©¶è
ãšããŠåããŠããŸãããã®çãèšäºã§ã¯ãSAPãã®çµæãéèŠãªããžãã¹æ
å ±ã«ã¢ã¯ã»ã¹ã§ããŸãã
SAP NWã®åæ°ããŒãžã§ã³ã§ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã匷åãããŠãããè匱æ§ã«ããã·ã¹ãã ãå®å
šã«äŸµå®³ãããããšã¯ãããŸããã ãã ããããã€ãã®ã»ãã¥ãªãã£åé¡ãäžç·ã«äœ¿çšãããšãæ»æè
ãç®æšãéæã§ããå ŽåããããŸãã 仿¥ã¯ã倿°ã®è匱æ§ã䜿çšããŠSAP NWã䟵害ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
ãã®èšäºã§ã¯ãæåã«ã·ã¹ãã ããæ
å ±ãååŸããå¯èœæ§ã«ã€ããŠãæ
å ±æŒæŽ©ã«åºã¥ãè匱æ§ã®æªçšã«ã€ããŠã次ã«ç¹æš©ã®ææ Œã«ã€ããŠèª¬æããŸãã ãã¹ãŠã®è匱æ§ã¯ãææ°ããŒãžã§ã³ïŒèª¿æ»æç¹ïŒã®SAPïŒSAP NW AS JAVA 7.4ïŒã§çºèŠãããŸããã ãŸããããã¯å§ãŸã£ãã

ã¯ããã«
SAP AS JAVAãµãŒããŒã«ã¯ãCïŒ\ usr \ sap \ïŒ
SIDïŒ
\ J00 \ j2ee \ cluster \ apps \ sap.comãã©ã«ããŒã«æ ŒçŽãããŠããå€ãã®æšæºã¢ããªã±ãŒã·ã§ã³ããããŸããïŒ
SIDïŒ
ã¯SAPã·ã¹ãã ã®SIDã§ãã ãããã£ãŠããã¹ãã·ã¹ãã ã«ã¯SID DM0ããããŸãã
以äžã®ã¹ã¯ãªãŒã³ã·ã§ãããããSAP NWã®æšæºã¢ã»ã³ããªã«ã¯1400ãè¶
ããã³ã³ããŒãã³ãïŒå®å
šãªã¢ã»ã³ããªãã€ã³ã¹ããŒã«ãããš2000ãè¶
ããã³ã³ããŒãã³ããååšããïŒããããããŸããŸãªæš©éãæã€SAPãŠãŒã¶ãŒãåŒã³åºãããšãã§ããããšãããããŸãã

åŒã³åºãããšãã§ããåã³ã³ããŒãã³ãã«ã¯ãweb.xmlããã³portalapp.xmlãã¡ã€ã«ã«èšè¿°ãããŠããç¹å®ã®ã¢ã¯ã»ã¹ã¬ãã«ããããŸãã ã³ã³ããŒãã³ããžã®ã¢ã¯ã»ã¹æš©ã«ã¯4çš®é¡ãããŸãã

åœç¶ãå€éšããã¢ã¯ã»ã¹å¯èœã§ãããæš©éã®ãªããŠãŒã¶ãŒãã¢ã¯ã»ã¹ã§ãããããno_safetyæš©éãæã€ãµãŒãã¬ãããã¢ããªã±ãŒã·ã§ã³ãããã³ã³ã³ããŒãã³ãããŸãã¯äºåå®çŸ©ãããæš©éãæããªãã³ã³ããŒãã³ãã«é¢å¿ããããŸãã
æåã®è匱æ§ã«ç§»ããŸãããã
æ
å ±æŒããã®è匱æ§
æ§æãã¡ã€ã«ãæ€çŽ¢ããåŸãã¢ã¯ã»ã¹æš©ã®èª¬æãå«ãèšè¿°åãã¡ã€ã«
<property name="SafetyLevel" value="no_safety"/>
ãŸãã¯å®å
šã«ååšããŸããã webdynproã³ã³ããŒãã³ãtcãrtcãcoll.appl.rtcãwd_chatãèŠã€ãããŸããã èšå®ãã¡ã€ã«ã¯æ¬¡ã®ãšããã§ãã

次ã®ã¢ãã¬ã¹ã§ãã®ãµãŒãã¹ã«é£çµ¡ã§ããŸãã
httpïŒ/ SAP_IPïŒSAP_PORT / webdynpro / resources / sap.com / tcãrtcãcoll.appl.rtcãwd_chat /ãã£ããïŒ
ããŒãžãéããã¡ãã»ãŒãžãéä¿¡ããããã®æ©èœã確èªããŸãã ãšããããåä¿¡è
ïŒãŠãŒã¶ãŒïŒã远å ããæ©èœããããŸãã

åå è
ã®è¿œå ãšã³ããªãã¯ãªãã¯ãããšãæ¿èªãªãã§ãŠãŒã¶ãŒãæ€çŽ¢ããããã®ãŠã£ã³ããŠã衚瀺ãããŸãã

Jon Snowãšããååã®ãŠãŒã¶ãŒãšãã°ã€ã³J.Snowãæã€ãŠãŒã¶ãŒããªã¹ãã«å«ãŸããŠããããšã¯éåžžã«è峿·±ãããšã§ãã
ããŒã...ãã®è匱æ§ã䜿çšããŠããããã«èŠããŸããSAPãŠãŒã¶ãŒãã°ã€ã³ã®ãªã¹ããååŸã§ããŸãã ãã ããããã¯ã·ã¹ãã ãå±éºã«ãããã®ã«ååã§ã¯ãããŸãããééã£ããã¹ã¯ãŒãã3ã5åå
¥åãããšãã¢ã«ãŠã³ãããããã¯ãããããã§ãã ããã§ã¯ãä»ã®è匱æ§ãæ¢ããŸãããã
SQLã€ã³ãžã§ã¯ã·ã§ã³
è匱æ§ãçºèŠãããæ¬¡ã®å¿åãµãŒãã¹ã¯UDDISecurityServiceã§ãã
SAPãµãŒããŒã§ã¯ããã®ãµãŒãã¹ã¯æ¬¡ã®å Žæã«ãããŸããCïŒ\ usr \ sap \ DM0 \ J00 \ j2ee \ cluster \ apps \ sap.com \ tcãuddi \ servlet_jsp \ UDDISecurityService \
æ§æãã¡ã€ã«ãããããããã«ããµãŒãã¹ã¯å¿åã§ãå©çšã§ããŸãã

servlet-classã¿ã°ã¯ãSOAPèŠæ±ã䜿çšããŠãã®ãµãŒãã¬ãããžã®ã¢ã¯ã»ã¹ãååŸã§ããããšã瀺ããŸãã ããã§ãSOAPèŠæ±ã®æ§é ãèŠã€ããã¿ã¹ã¯ã«çŽé¢ããŠããŸãã èŠæ±ã®æ§é ã¯ããã®ãµãŒãã¹ãèšè¿°ãããŠããwsdlãã¡ã€ã«ãèŠã€ããããšã§èŠã€ããããšãã§ããããšãç¥ãããŠããŸãã UDDISecurityImplBeanãšã³ããªãå«ãwsdlãã¡ã€ã«ãèŠã€ããå¿
èŠãããããšãããããŸããã ããŒã¿ã«ã³ãã³ããŒã䜿çšããŠãæ€çŽ¢ãå®è¡ããŸãã

å¿
èŠãªæ
å ±ãå«ããã¡ã€ã«ããµãŒããŒäžã§èŠã€ãããŸããã wsdlæ§é ãæã£ãŠãããããç¹å¥ãªãŠãŒãã£ãªãã£ã䜿çšããŠSOAPãªã¯ãšã¹ãã«å€æã§ããŸãã ãã®ãã¡ã€ã«ã«ã¯ãapplyPermissionãšdeletePermissionByIdã®2ã€ã®ã¡ãœãããèšè¿°ãããŠããããšãããããŸããã

2çªç®ã®ã¡ãœããïŒdeletePermissionByIdïŒãéžæããSOAPãªã¯ãšã¹ããçæããŠSAPãµãŒããŒã«éä¿¡ããŸãã

çãã¯æ¬¡ã®ãšããã§ãã

çãã¯200çªç®ã®ã³ãŒããè¿ããŸããããéä¿¡ãããããŒã¿ãåŠçããããžãã¯ã¯çè§£ã§ããŸããã ãã®ããã°ã©ã ã®ãã¹ãŠã®æ©èœã«ãæ
£ãããã«ã¯ãSAOPèŠæ±ãåŠçãããµãŒããŒã§JAVAã³ãŒããèŠã€ããå¿
èŠããããŸãã ãããŠããã®ãªã¯ãšã¹ãã®åŠçã®èª¬æãå«ãjarãã¡ã€ã«ãèŠã€ãããµãŒããŒäžã®æ¬¡ã®å Žæã«é
眮ããŸãã
CïŒ\ usr \ sap \ïŒ
SIDïŒ
\ J00 \ j2ee \ cluster \ apps \ sap.com \ tcãuddi \ EJBContainer \ applicationjars \ tcãesiãuddiãserverãejbãejbm.jar
ãã¡ã€ã«ãéã³ã³ãã€ã«ãããšã次ã®ã¯ã©ã¹ã衚瀺ãããŸãã

èŠæ±åŠçèªäœã¯ãUDDISecurityBeanã¯ã©ã¹ã§è¡ãããŸãã

deletePermissionByIdãªã¯ãšã¹ããéä¿¡ãããšã deletePermision颿°ãåŒã³åºãPermissionsDaoïŒïŒã³ã³ã¹ãã©ã¯ã¿ãŒãã©ã®ããã«è¡šç€ºãããããããããŸãã PermissionsDaoã¯ã©ã¹ã«ç§»åããŸãã

SOAPãªã¯ãšã¹ããä»ããŠéä¿¡ãããããŒã¿ã¯ããã£ã«ã¿ãªã³ã°ãªãã§SAPãµãŒããŒããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ããããã«äœ¿çšãããŸãã SQLã€ã³ãžã§ã¯ã·ã§ã³ããããšæ³å®ã§ããŸãã ããã確èªããã«ã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³çšã®ç¹å¥ãªã¯ãšãªãéä¿¡ããSAPãµãŒããŒããŒã¿ããŒã¹ã®ãã°ã確èªããå¿
èŠããããŸãã ããŒã¿ããŒã¹ãã°ãã¡ã€ã«ã¯ãããã©ã«ãã§ãã©ã«ããŒCã«ãããŸãã\ usr \ sap \ïŒ
SIDïŒ
\ J00 \ j2ee \ cluster \ server0 \ log \ system \ããã©ã«ãã§database_NN.N.logãšåŒã°ããŸããNã¯0ã9ã®æ°åã§ããå
æ¬çã«ã
次ã®ãªã¯ãšã¹ããéä¿¡ããŸãã

çãã§ã¯ã200çªç®ã®ã³ãŒããååŸããŸãã

ãã ããããŒã¿ããŒã¹ãã°ã§ã¯æ¬¡ã®ããšãããããŸãã

ããã§ãSAPããŒã¿ããŒã¹ãžã®å¿åSQLã€ã³ãžã§ã¯ã·ã§ã³ããããšæèšã§ããŸãã ãµãŒããŒãããã°ãåé€ããæ¬¡ã®ãªã¯ãšã¹ããéä¿¡ããŸãã ãµãŒããŒã®ãã°ã«ãšã©ãŒããªãå ŽåãSQLã¯ãšãªã®æ§é ã¯æ£ããã§ãã

ãšã©ãŒã¯ãããŸããã

æ°ããã¿ã¹ã¯ã¯ãããšãã°Jon Snowã®ãã¹ã¯ãŒãããã·ã¥ãªã©ãSAPããŒã¿ããŒã¹ããéèŠãªããŒã¿ãååŸããã®ã«åœ¹ç«ã€ã¯ãšãªãèŠã€ããããšã§ãã SAP NW AS JAVAã®ããã¥ã¡ã³ãããããŠãŒã¶ãŒããŒã¿ïŒãŠãŒã¶ãŒåãååããã¹ã¯ãŒãããã·ã¥ïŒãUME_STRINGSããŒãã«ã«æ ŒçŽãããŠããããšãããã£ãŠããŸãã
UME_STRINGSãããã¹ãŠã®ããŒã¿ãååŸããã¯ãšãªã¯æ¬¡ã®ããã«ãªããŸãã


ã芧ã®ãšããããã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã®è匱æ§ã¯ãšã©ãŒããŒã¹ã§ã¯ãªãããã®ãµãŒãã¬ããã§äœ¿çšãããsleepïŒïŒé¢æ°ããµããŒãããªãã¢ããã¿ãŒã§ãã ããŒãã«ä¹ç®æ¹åŒã䜿çšããŠã¯ãšãªåŠçæéãå¢ããããã®è匱æ§ãæéããŒã¹ã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã«å€ããŸãã ãããè¡ãã«ã¯ããã¹ãŠã®SAPãµãŒããŒã«ããŒã¿ãåžžã«å«ãŸããããŒãã«ãèŠã€ããŸãã ãã®ãããªããŒãã«ã¯J2EE_CONFIGã§ ãã³ã³ããŒãã³ãã®æ§ææ
å ±ãä¿åãããŸãã
次ã®ãªã¯ãšã¹ããéä¿¡ããŸãããã

èŠæ±ãåä¿¡ãããµãŒããŒã¯ã以åã«2ã€ã®ããŒãã«ïŒ UME_STRINGSãšJ2EE_CONFIGïŒãä¹ç®ããŠãããŒã¿ããŒã¹ããããŒã¿ãæœåºããããšããŸãã ããŒãã«ã«ã¯å€§éã®ããŒã¿ãå«ãŸããŠããããããµãŒããŒã«äžæçãªè² è·ãããããŸãã

ãããŠã32ç§åŸã«çããåŸãããŸãã ãããŠ-å®äºïŒæéããŒã¹ã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã

管çè
ããã·ã¥ã®ååŸ
åè¿°ã®ããã«ãããã·ã¥ããããã¹ã¯ãŒãã¯ãæ¬¡ã®æ§é ãæã€UME_STRINGSããŒãã«ã«ä¿åãããŸãã

UME_STRINGS.PIDããŒãã«ã«ã¯ããŠãŒã¶ãŒåãæ ŒçŽãããŸãã
UME_STRINGS.ATTR = 'j_password'ã¯ããŠãŒã¶ãŒãäœæãããSAP AS JAVAã¹ã¿ãã¯ã«ååšããããšã瀺ããŸãã
UME_STRINGS.VALã¯ããã°ã€ã³ãUME_STRINGS.PIDã«èšé²ãããŠãããŠãŒã¶ãŒããã®ãã¹ã¯ãŒãããã·ã¥ãä¿åããŸãã
ãã£ãŒã«ãUME_STRINGS.VALã«å«ãŸããããŒã¿ãéžæããå¿
èŠãããããšãããããŸããã ã€ã³ãžã§ã¯ã·ã§ã³ã®åºæ¬çãªSQLã¯ãšãªã¯æ¬¡ã®ããã«ãªããŸãã
SELECT COUNT(*) FROM J2EE_CONFIG, UME_STRINGS WHERE UME_STRINGS.ATTR='j_password' AND UME_STRINGS.PID LIKE '%J.Snow%' AND UME_STRINGS.VAL LIKE '%'
ãã¹ã¯ãŒãã¯ããã·ã¥ããã圢åŒã§SAPããŒã¿ããŒã¹ã«ä¿åãããããšãããã£ãŠããŸããããã·ã¥ã¢ã«ãŽãªãºã ã¯æ¬¡ã®ããã«ãªããŸãã
ãµãã·ã£
SSHA
SHA
SHA-512
ã€ãŸã ãã¹ã¯ãŒãããã·ã¥ã«ã¯ã次ã®ãããªæåãå«ãŸããå ŽåããããŸãã
1234567890QWERTYUIOPASDFGHJKLZXCVBNM*.,{}
ããããç¹°ãè¿ãåŠçããéžæããæåããã¹ã¯ãŒãã®ããã·ã¥æåãšäžèŽããå Žåããªã¯ãšã¹ãã®é
å»¶ãçºçããŸãã

å¿çã¯1ç§éé
å»¶ããŸãã

ãã®ããã»ã¹ãèªååããããšã«ããããŠãŒã¶ãŒJon Snowããããã·ã¥ãååŸããŸãã
{SHA-512, 10000, 24}YXNkUVdFMTIzzbAIcuqnw5RzpmdgZ38PWjhBeaGzHkV6XINN7ZDqxqgr0nYxfCaE5ncdK7kzzkzryJAn42qv9YlY034Llr4b8Rv1534chnIf1i8jZE6ylzTV5XuzvUlaXQ==

ã芧ã®ãšããããã¹ã¯ãŒãã¯SHA-512ã¢ã«ãŽãªãºã ã«ãã£ãŠããã·ã¥ãããŠããŸãã 3çªç®ã®è匱æ§ããªããã°ãç ç©¶ã¯ããã§çµäºããã§ãããã
æå·ãšã©ãŒãç¹æš©ã®ãšã¹ã«ã¬ãŒã·ã§ã³
ãã®è匱æ§ã¯å¶ç¶çºèŠãããŸãã:-)
SQLã€ã³ãžã§ã¯ã·ã§ã³ã䜿çšããŠããŠãŒã¶ãŒJon Snowã®ãã¹ã¯ãŒãããã·ã¥ãååŸããŸããã
{SHA-512, 10000, 24}YXNkUVdFMTIzzbAIcuqnw5RzpmdgZ38PWjhBeaGzHkV6XINN7ZDqxqgr0nYxfCaE5ncdK7kzzkzryJAn42qv9YlY034Llr4b8Rv1534chnIf1i8jZE6ylzTV5XuzvUlaXQ==
ããŒãã ã芧ã®ãšãããããã·ã¥ã®æåŸã«==æåããããŸãã ãããŠãbase64decodeãå®è¡ãããšã©ããªããŸããïŒ


ãªã«ïŒ ã©ããã£ãŠïŒ ãã¹ã¯ãŒã ãããæ¬åœã«Jonã®ãã¹ã¯ãŒãã§ãããã©ããã確èªããæ¹æ³ã¯1ã€ãããããŸãããJ.Snowãã°ã€ã³ãšasdQWE123ãã¹ã¯ãŒãã䜿çšããŠããŒã¿ã«ã«ãã°ã€ã³ããŸãã

ãã£ãïŒ ç§ã¯ç®¡çè
ã§ãïŒ ããããã©ã®ããã«ïŒ ãã¹ã¯ãŒããããŒã¿ããŒã¹å
ã§base64圢åŒã§ãããšããäºå®ã«é¢é£ãããã®ãçè§£ããå¿
èŠããããŸãã
æ€çŽ¢ã®çµæã次ã®ãã©ã«ããŒã«ãããã¡ã€ã«sap.comãtcãsecãumeãcoreãimpl.jarãèŠã€ãããŸããïŒ CïŒ\ usr \ sap \ DM0 \ J00 \ j2ee \ cluster \ bin \ ext \ com.sap .security.core.sda \ lib \ private ã ãŠãŒã¶ãŒã®ãã¹ã¯ãŒãã®ããã·ã¥ãæå¹æ§ã®ç¢ºèªããŠãŒã¶ãŒã®ãããã¯ãªã©ãæ
åœãã颿°ãå«ãŸããŠããŸãã äž»ãªã¯ã©ã¹ã®1ã€ã¯PasswordHashã§ãã ãã®ã¯ã©ã¹ãããã«è©³ããèããŠã¿ãŸãããã

2ã€ã®ã³ã³ã¹ãã©ã¯ã¿ãŒãããããã®ãã¡ã®1ã€
public PasswordHash(String user, String password) { this._user = user; this._password = password; this._extra = null; }
ã芧ã®ãšãããå
éšå€æ°userããã³passwordãåæåããŸã ã
ãã¹ã¯ãŒãããããã·ã¥ãååŸããã«ã¯ã PasswordHashã¯ã©ã¹ã®å¥ã®getHash颿°ã䜿çšãããŸãã

114è¡ç®ãããããããã«ããã®é¢æ°ã¯createHashWithIterations颿°ãåŒã³åºããŸãããã®é¢æ°ã¯ãããã·ã¥ãçæããããã®å
¥åãšããŠã©ã³ãã ãªå€ãåããŸãã createHashWithIterationsïŒsaltïŒé¢æ°ã«è¡ããŸããã

184è¡ç®ã§ã åºå倿°ãåæåãããå
¥åããããŠãŒã¶ãŒãã¹ã¯ãŒãã®ãã€ããæ ŒçŽãããŸãã
185è¡ç®ã¯ããã¹ã¯ãŒããã€ããš112è¡ç®ã§çæãããã©ã³ãã ãœã«ãã§æ§æãããæ°ãã倿°pass_n_saltãäœæããŸãã
次ã«ãè¡191ã§hashWithIterations颿°ãåŒã³åºãããŸã ããã®é¢æ°ã¯inputãšpass_n_saltã® 2ã€ã®ãã©ã¡ãŒã¿ãŒãåããŸãã ãã€ãåäœã®asdQWE123ãã¹ã¯ãŒããoutputã«æ ŒçŽãããŠããããšã«æ³šæããŠãã ããã

ãšãŠãè峿·±ãã åè¡ãåå¥ã«æ€èšããŸãã
238è¡ç®ã¯å€æ°outputãåæåãã ããŒã¿å€æ°ããã®ããŒã¿ãæžã蟌ãŸããŸãïŒ ããŒã¿å€æ°ã®æåã®ãã€ãã¯ãã¹ã¯ãŒãasdQWE123ã§ãïŒã
241è¡ç®ã¯ãããŒã¿ã®ããã·ã¥åŠçãè¡ãMessageDigestã¯ã©ã¹ã®md倿°ã«åæåãããŸãã
243è¡ç®ã¯ãããã·ã¥ã«ãŒã_iterations = 10000ãéå§ããŸãã
244-245è¡ç®ã§ã¯ã SHA-512ã¢ã«ãŽãªãºã ã䜿çšããŠããŒã¿ãããã·ã¥ãã ããŒã¿å€æ°ã«æžã蟌ã¿ãŸãã
è¡246ã åºå倿°ã¯ç¡å¹åãããŸãã
è¡247ã倿°ãã¹ ïŒasdQWE123ïŒããã®ããŒã¿ãåºå倿°ã«æžã蟌ãŸããŸãã
248è¡ç®ã§ã¯ãããŒã¿ããã®ããŒã¿ã åºå倿°ã®æåŸã«æžã蟌ãŸããŸãã
åºå倿°ã®æ§é ã¯æ¬¡ã®ãšããã§ãã

ãã®ããžãã¯ã¯ãã¹ãŠ10,000åå®è¡ããããµã€ã¯ã«ã®æåŸã®ã¹ãããã§ããã¹ã¯ãŒããåºå倿°ã®å
é ã«è¿œå ããããã¹ã¯ãŒããããŒã¿ãä¿åããåŸã§ãã ãããã£ãŠãåºå倿°ã®æåã®ãã€ãã¯ããã£ãã·ã¥ãããŠããªããã¹ã¯ãŒãã§æ§æãããŸãã
è匱ãªã³ãŒãã»ã¯ã·ã§ã³ã®ãããã¯å³ïŒ
pass = plain_pass
åºå= [ãã¬ãŒã³ãã¹] + [ã©ã³ãã ãã€ã]
i = 0
ããŒã¿= sha_512ïŒåºåïŒ
åºå= [NULL]
åºå= [ãã¬ãŒã³ãã¹] + [ããŒã¿]
ïŒiïŒi = i + 1
i == 10000ã®å Žå
exit_from_loop
åºå== "asdQWE123blablabla"
ããã°ã©ããŒã®ééãã¯ãforã«ãŒãã®æåŸã®ã¹ãããã§ããŒã¿ãããã·ã¥ããªãã£ãããšã§ãã ãã®è匱æ§ã¯ãã§ã«è§£æ±ºãããŠãããä¿®æ£ã¯æ¬¡ã®ããã«ãªããŸãã
pass = plain_pass
åºå= [ãã¬ãŒã³ãã¹] + [ã©ã³ãã ãã€ã]
i = 0
åºå= [ãã¬ãŒã³ãã¹] + [ããŒã¿]
ããŒã¿= sha_512ïŒåºåïŒ
ïŒiïŒi = i + 1
i == 10000ã®å Žå
exit_from_loop

ã芧ã®ãšãããSAPã¯ã¹ãããã®é åºã倿ŽããŠããã åºå倿°ãæåã«åæåãããæ¬¡ã«å€æ°ããŒã¿ããã·ã¥ãåæåãããŸã ã
ãããã«
ããã§ããããã®è匱æ§ãä¿®æ£ããããã«SAPããªãªãŒã¹ããã»ãã¥ãªãã£ããŒããèŠãŠã¿ãŸãããã
ãŠãŒã¶ãŒã®é瀺ããã°ã€ã³-SAP nota 2255990 ãè匱æ§ã¯2016幎5æ8æ¥ã«ä¿®æ£ãããŸããã ãã§ã«CVE-shack CVE-2016-3973ïŒCVSS v3 7.5ïŒããããŸãã
SAPã®è匱ãªããŒãžã§ã³ã®ãªã¹ãïŒ

SQLã€ã³ãžã§ã¯ã·ã§ã³ãä¿®æ£ããããã«ãSAPã»ãã¥ãªãã£ããŒã2101079ããªãªãŒã¹ããã2016幎2æ9æ¥ã«CVE-2016-2386ïŒCVSS v3 9.1ïŒã§ä¿®æ£ãããŸããã
SAPã®è匱ãªããŒãžã§ã³ã®ãªã¹ãïŒ

ãã¹ã¯ãŒãããã·ã¥ã®èª€ã£ãå®è£
ã«ããè匱æ§ã¯ãããŒã2191290ã§æ±ãããŸãã ãã®ããŒãã¯2016幎1æ12æ¥ãCVE-2016-1910ïŒCVSS v3 5.3ïŒã«ãªãªãŒã¹ãããŸããã
SAPã®è匱ãªããŒãžã§ã³ã®ãªã¹ãïŒ

ãã¡ããããã人ã¯ããçš®ã®ãæ²ãã£ããµãŒããŒããã€ã³ã¹ããŒã«ããŠãã°ãèŠã€ãããšèšããããããŸãããããã®ããã«SAP-aãŠãŒã¶ãŒã®ãªã¹ãã®é瀺ã«é¢ããçµ±èšãããããŸããã ã¹ãã£ã³ã¯ãã€ã³ã¿ãŒãããçµç±ã§ã¢ã¯ã»ã¹å¯èœãª7348 SAPãµãŒããŒã§å®è¡ãããŸããã

åããŒãã®çµ±èš

åèšã§ãçŽ1013å°ã®ãµãŒããŒïŒçŽ14ïŒ
ïŒãæ
å ±é瀺ã®è匱æ§ã«å¯ŸããŠè匱ã§ããããšã倿ããŸãã

ããŠãSQLã€ã³ãžã§ã¯ã·ã§ã³ã®è匱æ§ãååšããå¯èœæ§ã®ãããµãŒãã¬ããã®ã¢ã¯ã»ã·ããªãã£ã®çµ±èšã«é¢ãããã1ã€ã®ãã¬ãŒãïŒãããããŸã ã€ã³ã¹ããŒã«ãããŠããªãå ŽåïŒ

åèš-2174ãµãŒããŒãçŽ30ïŒ
ããã§ã¯ãäœãããå¿
èŠããããŸããïŒ
ããããé©çšããå¿
èŠããããŸãã管çè
仲éã
ã¯ãããããŠæåŸã«ïŒããããªããç§ãã¡ãšäžç·ã«åããããã«ãã£ãšãã°ããããã°ãèŠã€ããããªãã ããã«å±¥æŽæžãéã£ãŠãã ãã