← All talks

SAP Security: Reverse Engineering Protocols & Network Fun! #shorts

BSides Frankfurt · 20260:5281 viewsPublished 2026-03Watch on YouTube ↗
Tags
CategoryTechnical
About this talk
SAP's proprietary protocols create a firewall headache. Opening 100 ports for GUI access? Audits reveal chaos. Network admins face a black box, leading to widespread vulnerabilities. #SAP #Cybersecurity #NetworkSecurity #Firewall #IT
Show transcript [en]

Maybe to add that PySAP, just to have an idea, it sounds super fancy, that's really a reverse engineering of all those proprietary protocols. So, SAP has my gosh, I don't know how many different services you can technically expose, uh which is super crazy on SAP though, especially for firewall and network administrators, you have a lot of fun because someone tells you, "Hey, I need GUI access." And you can say, "Well, that's potential port range of 100 ports. Which should I open?" And guess what happens? Yes, 90% which we see on audits is 100 ports are open. Congratulations. And not only sometimes to internal communication, also to the public. Because to be honest, for for someone

who just do network stuff, SAP is really a black box. You have no understanding of the service and how should you? That's a whole business world.