Fortunately more and more SAP customers start securing their business critical SAP infrastructure after many SAP security presentations on conferences and others ways of raising awareness. Securing SAP systems is never an easy task, taking into account the complexity and wide variety of possible deployment scenarios for SAP systems.
However, you can secure the low hanging fruit and prevent the most easy compromises by focusing on just a couple of vulnerabilities. One of the most obvious and simple precautions is to get rid of DEFAULT accounts. This is a simple task as the list of default users and passwords was limited to only 5 accounts for a long time, but that has changed. Welcome to SAP default account number 6; the SMDAGENT user....
A total compromise of a SAP system will be demonstrated in this presentation. Combined with two other vulnerabilities found by our research, this default account is all it takes to get easy access to your multi-million dollar SAP systems.