back to article Some old SAP systems have default kernel user accounts. Guess what happened next?

Security researchers were able to access default SAP accounts on enterprise systems worldwide by using default passwords. The security snafu meant that SAP systems worldwide were potentially vulnerable to data theft, business process disruption and fraud, specialist security outfit ERP-SEC warned. Joris van de Vis, researcher …

  1. Pascal Monett Silver badge
    Facepalm

    "SAP said it had fixed the problem"

    Oh good. Now can someone please explain why SAP thought hardcoded kernel users was a good idea in the first place ?

    Because that is something I'd really like to know. Hey guys, we're making this really complex and hard-to-configure enterprise software application that will be available over LAN, WAN and wireless. Why don't we include a hardcoded kernel user to make sure we can always debug a client installation ? After all, what could possibly go wrong ?

    1. Anonymous Coward
      Anonymous Coward

      Re: "SAP said it had fixed the problem"

      Well, I'll give you that it's not good practice and I'd add that it's been a while since I've seen anyone do this (except for system accounts hmmmm).

      I'm also not sure how long ago SAP stopped doing this.

      On the other hand is there a requirement to leave ssh access open to the world on the machine with the hard coded login? I would expect any administrator worth their salt to at the very least make external accesses go via another machine first..... which makes this attack vector a lot less useful.

      Perhaps there's something in this part of SAP which means you have to allow access to the machine for world+dog...... I don't know.

    2. eaddict

      Re: "SAP said it had fixed the problem"

      Sadly SAP isn't the only culprit. If it wasn't for our required yearly audit we would have really no pressure to make vendors we interact with NOT have well known passwords. Heck, why even have them?

    3. herman

      Re: "SAP said it had fixed the problem"

      Oh, I dunno, how about the hard coded kernel user called 'root'?

  2. I. Aproveofitspendingonspecificprojects

    I'm going to have to change my name

    Soldyer of Freedom how does that sound?

    And for my Thumbdowners, here is some white noise: https://www.biblegateway.com/passage/?search=Revelation+19%3A11-21&version=ESV

    1. Afernie

      Re: I'm going to have to change my name

      I assume that sentence, and biblical reference made somehow sense inside your own head.

    2. redpawn

      Re: I'm going to have to change my name

      Worried you call it "white noise" and KJV would give you more cred.

    3. allthecoolshortnamesweretaken

      Re: I'm going to have to change my name

      "Oh, come on. Revelation was a mushroom dream that belonged in the Apocrypha. The New Testament is basically about what happened when God got religion." -- Terry Pratchett

  3. jamesb2147

    Humor and click-bait

    Get better at it. It's still annoying, Ed.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like