3299-pentesting-saprouter.md (7868B)
1 --- 2 title: "3299/tcp - Pentesting SAProuter" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/3299-pentesting-saprouter.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3299-pentesting-saprouter.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 3299/tcp - Pentesting SAProuter 14 15 ```text 16 PORT STATE SERVICE VERSION 17 3299/tcp open saprouter? 18 ``` 19 20 The Metasploit workflow below is based on Rapid7's SAProuter research.<sup>[[1]](#references)</sup> 21 22 ## Understanding SAProuter Penetration with Metasploit 23 24 SAProuter is an application-level gateway for SAP network traffic. It uses a route permission table (`saprouttab`) to decide which source may reach which host and service, and its default listener is TCP/3299. It complements rather than replaces a firewall.<sup>[[3]](#references)</sup> 25 26 **Scanning and Information Gathering** 27 28 First, use the **sap_service_discovery** module to identify SAP services and confirm whether SAProuter is present. 29 30 ```text 31 msf> use auxiliary/scanner/sap/sap_service_discovery 32 msf auxiliary(sap_service_discovery) > set RHOSTS 1.2.3.101 33 msf auxiliary(sap_service_discovery) > run 34 ``` 35 36 Following the discovery, further investigation into the SAP router's configuration is carried out with the **sap_router_info_request** module to potentially reveal internal network details. 37 38 ```text 39 msf auxiliary(sap_router_info_request) > use auxiliary/scanner/sap/sap_router_info_request 40 msf auxiliary(sap_router_info_request) > set RHOSTS 1.2.3.101 41 msf auxiliary(sap_router_info_request) > run 42 ``` 43 44 **Enumerating Internal Services** 45 46 With obtained internal network insights, the **sap_router_portscanner** module is used to probe internal hosts and services through the SAProuter, allowing a deeper understanding of internal networks and service configurations. 47 48 ```text 49 msf auxiliary(sap_router_portscanner) > set INSTANCES 00-50 50 msf auxiliary(sap_router_portscanner) > set PORTS 32NN 51 ``` 52 53 This module's flexibility in targeting specific SAP instances and ports makes it an effective tool for detailed internal network exploration. 54 55 **Advanced Enumeration and ACL Mapping** 56 57 Further scanning can reveal how Access Control Lists (ACLs) are configured on the SAProuter, detailing which connections are allowed or blocked. This information is pivotal in understanding security policies and potential vulnerabilities. 58 59 ```text 60 msf auxiliary(sap_router_portscanner) > set MODE TCP 61 msf auxiliary(sap_router_portscanner) > set PORTS 80,32NN 62 ``` 63 64 **Blind Enumeration of Internal Hosts** 65 66 In scenarios where direct information from the SAProuter is limited, techniques like blind enumeration can be applied. This approach attempts to guess and verify the existence of internal hostnames, revealing potential targets without direct IP addresses. 67 68 **Leveraging Information for Penetration Testing** 69 70 Having mapped the network and identified accessible services, penetration testers can utilize Metasploit's proxy capabilities to pivot through the SAProuter for further exploration and exploitation of internal SAP services. 71 72 ```text 73 msf auxiliary(sap_hostctrl_getcomputersystem) > set Proxies sapni:1.2.3.101:3299 74 msf auxiliary(sap_hostctrl_getcomputersystem) > set RHOSTS 192.168.1.18 75 msf auxiliary(sap_hostctrl_getcomputersystem) > run 76 ``` 77 78 **Conclusion** 79 80 This approach underscores the importance of secure SAProuter configurations and highlights the potential for accessing internal networks through targeted penetration testing. Properly securing SAP routers and understanding their role in network security architecture is crucial for protecting against unauthorized access. 81 82 For more detailed information on Metasploit modules and their usage, visit [Rapid7's database](http://www.rapid7.com/db). 83 84 --- 85 86 ## CVE-2022-27668 – Improper Access Control ➜ Remote Administrative Command Execution 87 88 In June 2022, SAP released Security Note **3158375** for a critical improper-access-control flaw in the SAProuter versions listed below. When `saprouttab` permits the necessary route, an unauthenticated remote attacker can tunnel administrative packets such as *shutdown*, *trace-level*, and *connection-kill* to the router even when it was started without the `-X` remote-administration option.<sup>[[2]](#references)</sup> 89 90 The issue results from the possibility to build a tunnel to the router’s own loopback interface by targeting the unspecified address **0.0.0.0**. Once the tunnel is established, the attacker gains local-host privileges and can run any admin command.<sup>[[2]](#references)</sup> 91 92 Practical exploitation can be reproduced with the **pysap** framework: 93 94 ```bash 95 # 1. Build a loopback tunnel through the vulnerable SAProuter 96 python router_portfw.py -d <ROUTER_IP> -p 3299 \ 97 -t 0.0.0.0 -r 3299 \ 98 -a 127.0.0.1 -l 3299 -v 99 100 # 2. Send an admin packet (here: stop the remote router) 101 python router_admin.py -s -d 127.0.0.1 -p 3299 102 ``` 103 104 **Affected versions** 105 106 * Stand-alone SAProuter 7.22 / 7.53 107 * Kernel 7.49, 7.77, 7.81, 7.85–7.88 (incl. KRNL64NUC/UC) 108 109 **Fix / Mitigation** 110 111 1. Apply the patch delivered with SAP Note **3158375**. 112 2. Remove wildcard (`*`) targets from `P` and `S` lines in `saprouttab`. 113 3. Make sure the router is started **without** the `-X` option and is **not** directly exposed to the Internet. 114 115 --- 116 117 ## Updated Tooling & Tricks 118 119 * **pysap** provides `router_portfw.py`, `router_admin.py`, and `router_trace.py` for crafting NI/Router packets, testing ACLs, and reproducing CVE-2022-27668 in an authorized lab.<sup>[[4]](#references)</sup> 120 * **Nmap** – extend service detection by adding the custom SAProuter probe: 121 122 ```text 123 Probe TCP SAProuter q|\x00\x00\x00\x00| 124 ports 3299 125 match saprouter m|SAProuter ([\d.]+)| p/SAProuter/ v/$1/ 126 ``` 127 128 Combine with NSE scripts or `--script=banner` to quickly fingerprint versions that leak the banner string (`SAProuter <ver> on '<host>'`). 129 * **Metasploit** – the auxiliary modules shown above still work through a SOCKS or NI proxy created with pysap, enabling full framework integration even when the router blocks direct access. 130 131 --- 132 133 ## Hardening & Detection Checklist 134 135 * Filter port **3299/TCP** on the perimeter firewall – allow traffic only from trusted SAP support networks. 136 * Keep SAProuter **fully patched**; verify with `saprouter -v` and compare against the latest kernel patch level. 137 * Use **strict, host-specific** entries in `saprouttab`; avoid `*` wildcards and deny `P`/`S` rules that target arbitrary hosts or ports. 138 * Configure an SNC environment, start each SAProuter with **`-K <snc-name>`**, and use `KT` plus `KP`/`KD`/`KS` route-table entries where adjacent SAProuters must authenticate and encrypt traffic.<sup>[[3]](#references)</sup> 139 * Disable remote administration (`-X`) and use **`-H <hostname-or-address>`** to bind only the required interface instead of listening on every local address.<sup>[[3]](#references)</sup> 140 * Monitor the **dev_rout** log for suspicious `ROUTER_ADM` packets or unexpected `NI_ROUTE` requests to `0.0.0.0`. 141 142 --- 143 144 ## Shodan 145 146 - `port:3299 !HTTP Network packet too big` 147 148 ## References 149 150 - [1] [Piercing SAProuter with Metasploit](https://www.rapid7.com/blog/post/2014/01/09/piercing-saprouter-with-metasploit/) 151 - [2] [Improper Access Control in SAP® SAProuter (CVE-2022-27668)](https://sec-consult.com/vulnerability-lab/advisory/improper-access-control-in-sap-saprouter/) 152 - [3] [SAP Help - Introduction to SAProuter and route permission tables](https://help.sap.com/docs/SAP_NETWEAVER_701/ba627ada0df549ab97b2d7a2c1a79b68/48ce58b318d3424be10000000a421937.html) 153 - [4] [pysap documentation](https://pysap.readthedocs.io/en/latest/)