Question: Hello all
I'm trying to propose that we lock SAP* in ALL clients and ALL systems (DEV, QA, PRD). Currently it's just locked in the customer client in all systems.
I want to prove that even if we go through the arduous task of building roles for DEV and QA, if we leave SAP* or DDIC's password unchanged in 001, anyone could do some damage.
Now, I know that I could do some system damage with DDIC or SAP* in r 001, but is there any way I could prove that I could say, assign myself SAP_ALL in the customer client by logging into 001 with SAP* and NOT using an RFC connection and function module? Thus..what's the point of building specialized roles in customer client if DDIC's or SAP*'s passwords are know in client 001.
Thanks.
Answer:
SAP*, DDIC, SAPCPIC, EARLYWATCH ARe among the IDs that could be used to access ANY client in ANY system From any system to any system ( yes it does require RFC or its equivalent, but the point is it is a backdoor, how you accomplish the damage is irrelevent, it is that you can).
In the logged on system you can use function module RFC_ABAP_INSTALL_AND_RUN to write code to add access to yourself in any client on the machine. You can do this temporarily, up to 1.5 hours, by manipulating table USRBF2 and semi perminantly by manipulating USRBF2 and UST04 or manipulation USREFUS table. This is provided you have AUTH/NEW_BUFFERING set above 0. This added access is almost un-noticed in SUIM and SU01.
In any system in any client you can alway use ABAP to do the changes in any client. You do not need a developers key, only DEBUG with replace, which SAP* has. TO get to other systems you do need RFC or communication to the other systems but to accomplish this you only need to know the default password of EARLYWATCH, DDIC, SAP*, SAPCPIC, all of which are known.
Answer:
Thanks John,
So, in short, SAP*'s password should be changed and locked in ALL systems and ALL clients?
EARLYWATCH, SAPCPIC and DDIC'S paswords should be changed in ALL systems and ALL clients?
Thanks.
Answer:
Yes.
Yes and locked.
Answer:
For what my penny is worth, you should remove all access from SAP*, then logon as SAP*, log-off and then lock the user ID.
Occationally keep an eye on the buffer, and SM20 and obscure messages in SM21.
How to Earn Rs.25000 every month in internet without Investment?
Locking SAP* in all clients in all systems.
Labels:
Sap Basis Faqs
Subscribe to:
Post Comments (Atom)
topics
-
▼
2007
(1406)
-
▼
November
(1359)
- Free Download SAP FI Certification study pdf books
- Implementing SAP R/3 on OS/400
- Update SAP Kernel in UNIX based
- Security Audit Log (BC-SEC).pdf
- Security Audit Log.pdf
- Securities,pdf
- Secure Store & Forward / Digital Signatures (BC-SE...
- Secure Network Communications (BC-SEC-SNC)
- Free download use ful T-codes
- I did not find any OSS notes appropriate for my pr...
- How to apply OSS notes number?
- What is OSS Notes number?
- Where can i access SAP OSS?
- WHAT IS OSS
- Disaster Recovery Plan to Restore Production System
- Steps to Install SAP Note in sap
- Difference Between SAP Notes and Support Package
- Question : Subject : Support packages testing
- Five Different "User Type"
- How to solve the Time Zone Definition Problems?
- Setting the User Decimals Format
- Schedule Manager
- Various Important SAP Basis T-Code
- Trace Functions in sap
- System Trace: Error Analysis in sap
- System Trace(ST01) in sap
- Roles and Authorizations Used in Background Proces...
- Deleting Multiple Spool Requests Simultaneously in...
- Logging and Tracing in spool
- Print and Output Management in spool
- Background Job Monitoring Monitor in CCMS
- Monitoring the Database Using the Alert Monitor
- Monitoring the Operating System Using the Alert Mo...
- Monitoring Memory Management Using the Alert Monitor
- Method Dispatching Monitor in CCMS
- Remote Application Server Status Monitor in CCMS
- GRMG Self-Monitoring Monitor in CCMS
- CCMS Selfmonitoring Monitor for System-Wide Data i...
- Logfile Monitoring Monitor in CCMS
- Logon Load Balancing Monitor in CCMS
- Transaction-Specific Dialog Monitor in CCMS
- Workload Collector Monitor in CCMS
- System Errors Monitor in CCMS
- System Configuration Monitor in CCMS
- Syslog Monitor in CCMS
- Spool System Monitor in CCMS
- Security Monitor in CCMS
- Performance Overview Monitor in CCMS
- Operating System Monitor in CCMS
- Filesystems Monitor in CCMS
- Entire System Monitor in CCMS
- Monitoring the Enqueue Service in CCMS
- Dialog per Application Server Monitor in CCMS
- Dialog Overview Monitor in CCMS
- Database Monitor in CCMS
- Transactional RFC and Queued RFC Monitor in CCMS
- Communications Monitor in CCMS
- Buffers Monitor in CCMS
- Background Job Monitoring Monitor(CCMS)
- Background Processing Monitor(CCMS)
- Availability and Performance Overview Monitor (CCMS)
- SAP CCMS Monitor Templates Monitor Set
- Creating and Changing a Monitoring Pause(CCMS)
- Creating and Changing Monitoring Rules(CCMS)
- Configuring Availability Monitoring(CCMS)
- Update Repositories(CCMS)
- Displaying Central Performance History Reports(CCMS)
- Displaying Report Properties
- Scheduling and Executing a Report
- Variables in Group Names
- Creating a Report Definition(CCMS)
- Maintaining Collection and Reorganization Schemata...
- Maintaining Collection and Reorganization Schemata...
- Creating and Editing a Calendar Schema(CCMS)
- Creating and Editing a Day Schema
- Customizing the Alert Monitor(CCMS)
- Resetting MTEs and Alerts(CCMS)
- Reorganizing Completed Alerts(CCMS)
- Display Completed Alerts(CCMS)
- Automatically Complete Alerts(CCMS)
- Completing Alerts(CCMS)
- Starting Methods (CCMS)
- Processing Alerts(CCMS_
- Displaying the Technical View: Central Performance...
- Displaying the Technical View: Threshold Values(CCMS)
- Displaying the Technical View: Status Autoreaction...
- Displaying the Technical View: Status Data Collector
- Displaying the Technical View: Method Allocation
- Displaying the Technical View: Info on MTE
- Display Types and Views of the Alert Monitor(CCMS)
- Properties of Status Attributes (CCMS)
- Properties of Performance Attributes(CCMS)
- Properties of Log Attributes (CCMS)
- General Properties of Monitoring Tree Elements(CCMS)
- Properties of Monitoring Objects and Attributes
- Elements of the Alert Monitoring Tree
- Alert Monitoring Tree(CCMS)
- Monitors(CCMS)
- Monitor Sets (CCMS)
- Elements of the Alert Monitor (CCMS)
-
▼
November
(1359)
No comments:
Post a Comment