← All talks

SAP System Security: Dodging Demo Credential Pitfalls #shorts

BSides Frankfurt0:42888 viewsPublished 2026-03Watch on YouTube ↗
About this talk
Beware of exposed demo system details! Free text fields can reveal production system warnings. Never leave login info on public pages—especially on Fridays. Protect your data. #CyberSecurity #InfoSec #SystemAdmin #TechTips
Show transcript [en]

But that's what we did here. Some other stuff we found is, for example, we get those system names. Um I extended it a bit. You will see it in the demo. You can put on the SAP fat client, you have there a common field where you can put in like free text. System information, hey that's a production system, be careful what you click on. Don't push stuff on Friday, blah blah blah. Some people really put their demo systems out. For example, consulting companies or maybe sometimes even SAP themselves. Where would you place your demo credentials that no one really forget them? Right on the login page. So, you sometimes find their login information.