Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SAPMS+SAPRFC contribution from @gelim @_chipik #31

Merged
merged 1 commit into from
Apr 30, 2019

Conversation

gelim
Copy link
Contributor

@gelim gelim commented Apr 30, 2019

Hey,
this is the contribution used for our research on Gateway+Message Server "be trusted" attack presented at OPCDE2019 Dubai.

slides and videos

Main takeaways are:

  • added the DPInfo[1-3] packets in SAPMS.py for handling specific MS ADM packets relaying Dispatcher/WP info : [1-3] because of tight SAP kernel version dependency.
  • enhanced SAPRFC.py with mainly SAPCPIC* and SAPRFXPG* new packets

Those enhancements are used by PoC code like this and this

@martingalloar
Copy link
Collaborator

This is really good work, thank you very much for contributing it back to upstream @gelim and @chipik! I'll add some documentation and references to your work and the exploits repositories after the merge.

@martingalloar martingalloar merged commit 03bdc11 into OWASP:master Apr 30, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants