SlideShare uma empresa Scribd logo
NewyorkSys
Introduction
 Entire companies have been built up around highly
  guarded intellectual property and process secrets ... and
  could easily fall if this was breached. Therefore, keeping
  the security of the organization intact is one of the vital
  aspects of any SAP implementation.
 SAP BASIS addresses all security issues by incorporating an
  authorization      module. With increased potential for
  security breaches in the computer systems around the
  world, BASIS consultants face a tough task of maintaining
  the integrity and administering the security of SAP
  systems. Interoperability features of a SAP system makes
  this task a bit more difficult.
  Call     : +1-718-305-1757, +1-718-313-0499
  E – Mail : training@newyorksys.com www.newyorksys.com
SAP Security in Open Environment




  Call     : +1-718-305-1757, +1-718-313-0499
  E – Mail : training@newyorksys.com www.newyorksys.com
SAP Security Components




Call     : +1-718-305-1757, +1-718-313-0499
E – Mail : training@newyorksys.com www.newyorksys.com
Network Security
 Encryption
 • Password sniffing
 • No traffic encryption by default
 Potocol vulnerabilities
 • RFC protocol vulnerabilities
 • Getting information
 • Executing remote commands
 • Registering External server
 Improper components implementation
 • Improper SAP firewall rules implementation (allow all)
 • Network segmentation between users, administrators &
 servers
 Call     : +1-718-305-1757, +1-718-313-0499
 E – Mail : training@newyorksys.com www.newyorksys.com
OS Security
  OS and application vulnerabilities
 Any critical vulnerability in OS or applications installed on SAP
  server can be used to get access to OS and business DATA.
  Examples of OS vulnerabilities are everywhere
  (securityfocus, milw0rm,exploit-db)
  OS specific security options NFS access. SAP data and binaries
  can be accessed by an anonymous user with NFS OS access
  rights.
 Critical SAP files and Oracle data files may have insecure
  rights such as 755 or even 777 Insecure rhosts. Remote access
  can be managed by rlogin from trusted servers thus getting
  access to one of SAP servers an attacker can access to
  others
  Call     : +1-718-305-1757, +1-718-313-0499
  E – Mail : training@newyorksys.com www.newyorksys.com
Database Security
 • Database vulnerabilities
 • Many default passwords + Default SAP passwords

 • Password policies such as password length and
 locking are not installed by default
 • Security properties such as
 REMOTE_OS_AUTHENT
 • Listener security (for example latest buffer overflows
 that give remote access to OS)
 • Many many others
Application Security
 • There are many different Web servers installed in SAP
 landscape such as: WEB AS, ITS, IGS
 • SAP usually installs with many different web
 applications that use different technologies:
  JSP servlets, Web services, Webdynpro, EJB, Portal
 iviews, BSP
 • All SAP implementations have internally developed
 stuff so every company may have their own
 vulnerabilities
Internal Security
 The most known area of SAP security
 It is about roles, privileges and segregation of duties
 Every SAP security consultant or administrator knows
  this aria (maybe :)
 Unfortunately, it is ALL that they know about SAP
  security
ABOUT NEWYORKSYS – IT SOLUTIONS
 NewyorkSys is one of the leading top IT Training and
  Consulting Company in US, with a good placement track
  record. We have certified trainers. We will provide Online
  Training, Fast Track online training, with job assistance
 We are providing excellent Training in all courses. Faculty
  from top MNC’s with highly skilled domain expertsaise will
  train & guide you with real time examples , project
  explanation . We also help you in resume preparation and
  provide job assistance till you get job.

            For more details visit our website :
                www.newyorksys.com


 Call     : +1-718-305-1757, +1-718-313-0499
 E – Mail : training@newyorksys.com www.newyorksys.com
NEWYORKSYS OFFER ONLINE COURSES
  SAP ERP TECHNOLOGIES : SAP Basis, SAP ABAP, SAP
   Security, SAP Net Weaver, SAP XI, SAP FICO, SAP MM, SAP PP,
   SAP WM, SAP SRM, SAP BPC, SAP EP ADMIN, SAP SCM, SAP
   SD, SAP CRM, SAP HR, SAP MDM, SAP Is Retail, SAP ABAP HR.

  SAP ADVANCED TECHNOLOGIES :SAP HANA, SAP BPC,
   SAP ABAP Workflow, SAP Business Object, SAP APO, SAP PLM,
   SAP SEM.

                FOR MORE DETAILS VISIT :
              http://www.Newyorksys.com
CONTACT US
For Additional Assistance , Course Details, Batch
Scheduling Information , you may contact to below
address
NewyorkSys Inc.,
15 Roaring Brook Rd,
Chappaqua,
NY 10514.
USA : +1-718-313-0499
USA : +1-178-305-1757
E-Mail ID : training@NewyorkSys.com
Visit : www.NewyorkSys.com

Mais conteúdo relacionado

Destaque (15)

บทที่7 ใหม่1
บทที่7 ใหม่1บทที่7 ใหม่1
บทที่7 ใหม่1
 
IniciadorKids-CREA
IniciadorKids-CREAIniciadorKids-CREA
IniciadorKids-CREA
 
Foreclosure
ForeclosureForeclosure
Foreclosure
 
Naruto 245
Naruto 245Naruto 245
Naruto 245
 
二Mt三a 7號柯婷儀[1]
二Mt三a 7號柯婷儀[1]二Mt三a 7號柯婷儀[1]
二Mt三a 7號柯婷儀[1]
 
13余思玨
13余思玨13余思玨
13余思玨
 
給予討論
給予討論給予討論
給予討論
 
Busqueda en google
Busqueda en googleBusqueda en google
Busqueda en google
 
Qısa müddətdə yeni mediada trend (virus) necə yaratmalı,Ülvi Həsənli Mehman H...
Qısa müddətdə yeni mediada trend (virus) necə yaratmalı,Ülvi Həsənli Mehman H...Qısa müddətdə yeni mediada trend (virus) necə yaratmalı,Ülvi Həsənli Mehman H...
Qısa müddətdə yeni mediada trend (virus) necə yaratmalı,Ülvi Həsənli Mehman H...
 
結婚.壓力.離婚
結婚.壓力.離婚結婚.壓力.離婚
結婚.壓力.離婚
 
MLA Documentation
MLA DocumentationMLA Documentation
MLA Documentation
 
Slideshare
Slideshare Slideshare
Slideshare
 
Sourajit Aiyer - Dhaka Tribune - Microfinance - A catalyst to boost rural demand
Sourajit Aiyer - Dhaka Tribune - Microfinance - A catalyst to boost rural demandSourajit Aiyer - Dhaka Tribune - Microfinance - A catalyst to boost rural demand
Sourajit Aiyer - Dhaka Tribune - Microfinance - A catalyst to boost rural demand
 
Learning styles
Learning stylesLearning styles
Learning styles
 
01廖麗萍
01廖麗萍01廖麗萍
01廖麗萍
 

Mais de Newyorksys.com

Sap abap hr online training course
Sap abap hr online training courseSap abap hr online training course
Sap abap hr online training course
Newyorksys.com
 
Sap abap online training course
Sap abap online training courseSap abap online training course
Sap abap online training course
Newyorksys.com
 

Mais de Newyorksys.com (6)

ORACLE PL/SQL TUTORIALS - OVERVIEW - SQL COMMANDS
ORACLE PL/SQL TUTORIALS - OVERVIEW - SQL COMMANDSORACLE PL/SQL TUTORIALS - OVERVIEW - SQL COMMANDS
ORACLE PL/SQL TUTORIALS - OVERVIEW - SQL COMMANDS
 
Datastage ppt
Datastage pptDatastage ppt
Datastage ppt
 
Sap bodi bods online training course
Sap bodi bods online training courseSap bodi bods online training course
Sap bodi bods online training course
 
Sap basis online training course
Sap basis online training courseSap basis online training course
Sap basis online training course
 
Sap abap hr online training course
Sap abap hr online training courseSap abap hr online training course
Sap abap hr online training course
 
Sap abap online training course
Sap abap online training courseSap abap online training course
Sap abap online training course
 

Último

The basics of sentences session 4pptx.pptx
The basics of sentences session 4pptx.pptxThe basics of sentences session 4pptx.pptx
The basics of sentences session 4pptx.pptx
heathfieldcps1
 
Industrial Training Report- AKTU Industrial Training Report
Industrial Training Report- AKTU Industrial Training ReportIndustrial Training Report- AKTU Industrial Training Report
Industrial Training Report- AKTU Industrial Training Report
Avinash Rai
 
Neurulation and the formation of the neural tube
Neurulation and the formation of the neural tubeNeurulation and the formation of the neural tube
Neurulation and the formation of the neural tube
SaadHumayun7
 

Último (20)

The Art Pastor's Guide to Sabbath | Steve Thomason
The Art Pastor's Guide to Sabbath | Steve ThomasonThe Art Pastor's Guide to Sabbath | Steve Thomason
The Art Pastor's Guide to Sabbath | Steve Thomason
 
Danh sách HSG Bộ môn cấp trường - Cấp THPT.pdf
Danh sách HSG Bộ môn cấp trường - Cấp THPT.pdfDanh sách HSG Bộ môn cấp trường - Cấp THPT.pdf
Danh sách HSG Bộ môn cấp trường - Cấp THPT.pdf
 
Pragya Champions Chalice 2024 Prelims & Finals Q/A set, General Quiz
Pragya Champions Chalice 2024 Prelims & Finals Q/A set, General QuizPragya Champions Chalice 2024 Prelims & Finals Q/A set, General Quiz
Pragya Champions Chalice 2024 Prelims & Finals Q/A set, General Quiz
 
Advances in production technology of Grapes.pdf
Advances in production technology of Grapes.pdfAdvances in production technology of Grapes.pdf
Advances in production technology of Grapes.pdf
 
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...
UNIT – IV_PCI Complaints: Complaints and evaluation of complaints, Handling o...
 
Students, digital devices and success - Andreas Schleicher - 27 May 2024..pptx
Students, digital devices and success - Andreas Schleicher - 27 May 2024..pptxStudents, digital devices and success - Andreas Schleicher - 27 May 2024..pptx
Students, digital devices and success - Andreas Schleicher - 27 May 2024..pptx
 
Dementia (Alzheimer & vasular dementia).
Dementia (Alzheimer & vasular dementia).Dementia (Alzheimer & vasular dementia).
Dementia (Alzheimer & vasular dementia).
 
How to Break the cycle of negative Thoughts
How to Break the cycle of negative ThoughtsHow to Break the cycle of negative Thoughts
How to Break the cycle of negative Thoughts
 
Operations Management - Book1.p - Dr. Abdulfatah A. Salem
Operations Management - Book1.p  - Dr. Abdulfatah A. SalemOperations Management - Book1.p  - Dr. Abdulfatah A. Salem
Operations Management - Book1.p - Dr. Abdulfatah A. Salem
 
[GDSC YCCE] Build with AI Online Presentation
[GDSC YCCE] Build with AI Online Presentation[GDSC YCCE] Build with AI Online Presentation
[GDSC YCCE] Build with AI Online Presentation
 
Benefits and Challenges of Using Open Educational Resources
Benefits and Challenges of Using Open Educational ResourcesBenefits and Challenges of Using Open Educational Resources
Benefits and Challenges of Using Open Educational Resources
 
The Last Leaf, a short story by O. Henry
The Last Leaf, a short story by O. HenryThe Last Leaf, a short story by O. Henry
The Last Leaf, a short story by O. Henry
 
Basic_QTL_Marker-assisted_Selection_Sourabh.ppt
Basic_QTL_Marker-assisted_Selection_Sourabh.pptBasic_QTL_Marker-assisted_Selection_Sourabh.ppt
Basic_QTL_Marker-assisted_Selection_Sourabh.ppt
 
Salient features of Environment protection Act 1986.pptx
Salient features of Environment protection Act 1986.pptxSalient features of Environment protection Act 1986.pptx
Salient features of Environment protection Act 1986.pptx
 
Open Educational Resources Primer PowerPoint
Open Educational Resources Primer PowerPointOpen Educational Resources Primer PowerPoint
Open Educational Resources Primer PowerPoint
 
Matatag-Curriculum and the 21st Century Skills Presentation.pptx
Matatag-Curriculum and the 21st Century Skills Presentation.pptxMatatag-Curriculum and the 21st Century Skills Presentation.pptx
Matatag-Curriculum and the 21st Century Skills Presentation.pptx
 
The basics of sentences session 4pptx.pptx
The basics of sentences session 4pptx.pptxThe basics of sentences session 4pptx.pptx
The basics of sentences session 4pptx.pptx
 
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17
 
Industrial Training Report- AKTU Industrial Training Report
Industrial Training Report- AKTU Industrial Training ReportIndustrial Training Report- AKTU Industrial Training Report
Industrial Training Report- AKTU Industrial Training Report
 
Neurulation and the formation of the neural tube
Neurulation and the formation of the neural tubeNeurulation and the formation of the neural tube
Neurulation and the formation of the neural tube
 

SAP Security Online Training by Newyorksys.com

  • 2. Introduction  Entire companies have been built up around highly guarded intellectual property and process secrets ... and could easily fall if this was breached. Therefore, keeping the security of the organization intact is one of the vital aspects of any SAP implementation.  SAP BASIS addresses all security issues by incorporating an authorization module. With increased potential for security breaches in the computer systems around the world, BASIS consultants face a tough task of maintaining the integrity and administering the security of SAP systems. Interoperability features of a SAP system makes this task a bit more difficult. Call : +1-718-305-1757, +1-718-313-0499 E – Mail : training@newyorksys.com www.newyorksys.com
  • 3. SAP Security in Open Environment Call : +1-718-305-1757, +1-718-313-0499 E – Mail : training@newyorksys.com www.newyorksys.com
  • 4. SAP Security Components Call : +1-718-305-1757, +1-718-313-0499 E – Mail : training@newyorksys.com www.newyorksys.com
  • 5. Network Security Encryption • Password sniffing • No traffic encryption by default Potocol vulnerabilities • RFC protocol vulnerabilities • Getting information • Executing remote commands • Registering External server Improper components implementation • Improper SAP firewall rules implementation (allow all) • Network segmentation between users, administrators & servers Call : +1-718-305-1757, +1-718-313-0499 E – Mail : training@newyorksys.com www.newyorksys.com
  • 6. OS Security OS and application vulnerabilities  Any critical vulnerability in OS or applications installed on SAP server can be used to get access to OS and business DATA. Examples of OS vulnerabilities are everywhere (securityfocus, milw0rm,exploit-db) OS specific security options NFS access. SAP data and binaries can be accessed by an anonymous user with NFS OS access rights.  Critical SAP files and Oracle data files may have insecure rights such as 755 or even 777 Insecure rhosts. Remote access can be managed by rlogin from trusted servers thus getting access to one of SAP servers an attacker can access to others Call : +1-718-305-1757, +1-718-313-0499 E – Mail : training@newyorksys.com www.newyorksys.com
  • 7. Database Security • Database vulnerabilities • Many default passwords + Default SAP passwords • Password policies such as password length and locking are not installed by default • Security properties such as REMOTE_OS_AUTHENT • Listener security (for example latest buffer overflows that give remote access to OS) • Many many others
  • 8. Application Security • There are many different Web servers installed in SAP landscape such as: WEB AS, ITS, IGS • SAP usually installs with many different web applications that use different technologies: JSP servlets, Web services, Webdynpro, EJB, Portal iviews, BSP • All SAP implementations have internally developed stuff so every company may have their own vulnerabilities
  • 9. Internal Security  The most known area of SAP security  It is about roles, privileges and segregation of duties  Every SAP security consultant or administrator knows this aria (maybe :)  Unfortunately, it is ALL that they know about SAP security
  • 10. ABOUT NEWYORKSYS – IT SOLUTIONS  NewyorkSys is one of the leading top IT Training and Consulting Company in US, with a good placement track record. We have certified trainers. We will provide Online Training, Fast Track online training, with job assistance  We are providing excellent Training in all courses. Faculty from top MNC’s with highly skilled domain expertsaise will train & guide you with real time examples , project explanation . We also help you in resume preparation and provide job assistance till you get job. For more details visit our website : www.newyorksys.com Call : +1-718-305-1757, +1-718-313-0499 E – Mail : training@newyorksys.com www.newyorksys.com
  • 11. NEWYORKSYS OFFER ONLINE COURSES  SAP ERP TECHNOLOGIES : SAP Basis, SAP ABAP, SAP Security, SAP Net Weaver, SAP XI, SAP FICO, SAP MM, SAP PP, SAP WM, SAP SRM, SAP BPC, SAP EP ADMIN, SAP SCM, SAP SD, SAP CRM, SAP HR, SAP MDM, SAP Is Retail, SAP ABAP HR.  SAP ADVANCED TECHNOLOGIES :SAP HANA, SAP BPC, SAP ABAP Workflow, SAP Business Object, SAP APO, SAP PLM, SAP SEM. FOR MORE DETAILS VISIT : http://www.Newyorksys.com
  • 12. CONTACT US For Additional Assistance , Course Details, Batch Scheduling Information , you may contact to below address NewyorkSys Inc., 15 Roaring Brook Rd, Chappaqua, NY 10514. USA : +1-718-313-0499 USA : +1-178-305-1757 E-Mail ID : training@NewyorkSys.com Visit : www.NewyorkSys.com