<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Alexander</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Alexander"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Alexander"/>
		<updated>2026-05-27T07:59:14Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Enterprise_Application_Security_Project&amp;diff=235844</id>
		<title>Projects/OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Enterprise_Application_Security_Project&amp;diff=235844"/>
				<updated>2017-11-29T08:49:00Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Project About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Enterprise Application Security Project&lt;br /&gt;
| project_home_page = OWASP Enterprise Application Security Project&lt;br /&gt;
&lt;br /&gt;
| project_description =&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications controls money and resources and every security violation can result a significant money loss. Purpose of this project is to aware people about enterprise application security problems and create a guideline for EA security assessment. &lt;br /&gt;
&lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ '''Creative Commons Attribution Share Alike 3.0'''] &lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Alexander Polyakov&lt;br /&gt;
| leader_email1 = a.polyakov@erpscan.com&lt;br /&gt;
| leader_username1 = Alexander&lt;br /&gt;
 &lt;br /&gt;
| contributor_name2 = Dmitriy Chastuhin  &lt;br /&gt;
| contributor_email2 =  chipik2@gmail.com &lt;br /&gt;
| contributor_username2 =&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
&lt;br /&gt;
| presentation_link = &lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-eas&lt;br /&gt;
&lt;br /&gt;
| project_road_map = http://www.owasp.org/index.php/OWASP_Enterprise_Application_Security_Project/Roadmp&lt;br /&gt;
&lt;br /&gt;
| links_url1 = http://erpscan.com/&lt;br /&gt;
| links_name1 = ERPSCAN Enterprise Security Software and Services &lt;br /&gt;
&lt;br /&gt;
| links_url2 = http://eas-sec.org/&lt;br /&gt;
| links_name2 = EAS-SEC&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| release_4 =&lt;br /&gt;
&amp;lt;!--- The line below is for GPC usage only. Please do not edit it ---&amp;gt;&lt;br /&gt;
| project_about_page = Projects/OWASP Enterprise Application Security Project&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Application_Vulnerability_Statistics&amp;diff=235843</id>
		<title>Enterprise Application Vulnerability Statistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Application_Vulnerability_Statistics&amp;diff=235843"/>
				<updated>2017-11-29T08:41:16Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: /* Authors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show a result of statistical research in the business application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what kind of tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still don’t pay much attention to enterprise business application area, as we see during our and our collegues' researches and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. The purpose of those surveys is to increase awareness about business application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com/wp-content/uploads/2014/02/SAP-Security-in-Figures-A-Global-Survey-2013.pdf SAP Security In Figures – A Global Survey 2013]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Dmitry Chastukhin&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alexander&amp;diff=235842</id>
		<title>User:Alexander</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alexander&amp;diff=235842"/>
				<updated>2017-11-29T08:39:39Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A Founder of  ERPScan. His expertise covers security of enterprise business-critical software like ERP, CRM, SRM, banking and processing software. He is the manager of OWASP-EAS (OWASP subproject), a well-known security expert of the enterprise applications of such vendors as SAP and Oracle, who published a significant number of the vulnerabilities found in the applications of these vendors with acknowledgements from SAP. He is the writer of multiple whitepapers and surveys devoted to information security research in SAP like &amp;quot;SAP Security in figures&amp;quot;. Alexander were invited to speak and train at international conferences such as BlackHat, RSA, HITB and 30 others around globe  as well as in internal workshops for SAP and fortune 500 companies.&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=235841</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=235841"/>
				<updated>2017-11-29T08:38:04Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:100px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[Image:OWASP Inactive Banner.jpg|800px| link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Inactive_Projects]] &amp;lt;/div&amp;gt;&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation, or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
The latest project information can be found here &amp;lt;nowiki&amp;gt;http://eas-sec.org&amp;lt;/nowiki&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin the assessment of enterprise applications &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Application Security Vulnerability Assessment]] &lt;br /&gt;
&lt;br /&gt;
3 Help companies to securely develop and customize business applications&lt;br /&gt;
&lt;br /&gt;
[[Enterprise Application Security Development Issues]] &lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Enterprise Application Security Project]] &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Application_Vulnerability_Statistics&amp;diff=172607</id>
		<title>Enterprise Application Vulnerability Statistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Application_Vulnerability_Statistics&amp;diff=172607"/>
				<updated>2014-04-13T23:14:01Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show a result of statistical research in the business application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what kind of tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still don’t pay much attention to enterprise business application area, as we see during our and our collegues' researches and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. The purpose of those surveys is to increase awareness about business application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com/wp-content/uploads/2014/02/SAP-Security-in-Figures-A-Global-Survey-2013.pdf SAP Security In Figures – A Global Survey 2013]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Nikolay Mescherin, Kirill Nikitenkov, Dmitry Chastukhin, Dmitry Evdokimov&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Application_Vulnerability_Statistics&amp;diff=172606</id>
		<title>Enterprise Application Vulnerability Statistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Application_Vulnerability_Statistics&amp;diff=172606"/>
				<updated>2014-04-13T23:12:23Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show a result of statistical research in the business application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what kind of tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still don’t pay much attention to enterprise business application area, as we see during our and our collegues' researches and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: &lt;br /&gt;
&lt;br /&gt;
• Network architecture security &lt;br /&gt;
&lt;br /&gt;
• OS security &lt;br /&gt;
&lt;br /&gt;
• Database security &lt;br /&gt;
&lt;br /&gt;
• Application security &lt;br /&gt;
&lt;br /&gt;
• Front-end security &lt;br /&gt;
&lt;br /&gt;
Each of the described layers may have their own vulnerabilities that can give an attacker full access to business data, even if other layers are fully secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness about business application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com/wp-content/uploads/2014/02/SAP-Security-in-Figures-A-Global-Survey-2013.pdf SAP Security In Figures – A Global Survey 2013]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Nikolay Mescherin, Kirill Nikitenkov, Dmitry Chastukhin, Dmitry Evdokimov&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Application_Security_Development_Issues&amp;diff=172605</id>
		<title>Enterprise Application Security Development Issues</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Application_Security_Development_Issues&amp;diff=172605"/>
				<updated>2014-04-13T23:10:17Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: Created page with &amp;quot; === Development Issues  ===  == Objective  ==  This document will describe different areas of program vulnerabilities that can be found in the source code of Enterprise Busin...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
=== Development Issues  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in the source code of Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write custom code such as ABAP for SAP, PeopleCode for PeopleSoft, X++ for Microsoft Dynamics, PL/SQL for Oracle EBS, LotusScript for Lotus and much, much more. Here, we will try to categorize them into 9 main areas filtered by criticality. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE, SANS, OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
== 9 most critical types of issues in source code [EASSEC-ASDI-9-2013] ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 Injections (code, SQL, OS)&lt;br /&gt;
&amp;lt;br&amp;gt;2 Critical calls (to DB, to OS)&lt;br /&gt;
&amp;lt;br&amp;gt;3 Missing or bad access control checks (missing auth checks)&lt;br /&gt;
&amp;lt;br&amp;gt;4 Directory / path traversal (write, read, SMBRelay)&lt;br /&gt;
&amp;lt;br&amp;gt;5 Modification of displayed content (XSS stored, XSS linked, JS/HTML injections)&lt;br /&gt;
&amp;lt;br&amp;gt;6 Backdoors (hardcoded credentials)&lt;br /&gt;
&amp;lt;br&amp;gt;7 Covert channels (sockets, HTTP calls, SSRFs)&lt;br /&gt;
&amp;lt;br&amp;gt;8 Information  disclosure (hardcoded users, passwords, debug information) &lt;br /&gt;
&amp;lt;br&amp;gt;9 Obsolete statements (READ TABLE, kernel methods)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
&lt;br /&gt;
Alexander Minozhenko&lt;br /&gt;
&lt;br /&gt;
Pavel Kuzmin&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Application_Security_Vulnerability_Assessment&amp;diff=172604</id>
		<title>Enterprise Application Security Vulnerability Assessment</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Application_Security_Vulnerability_Assessment&amp;diff=172604"/>
				<updated>2014-04-13T23:05:06Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start self-assessment of their systems to find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give an attacker full access to business data, even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All of the data was collected and categorized during our extensive experience of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
In this document, we will describe top 10 violations for every layer of Enterprise Business Applications that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues - 2010  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and corporate network&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lacking or vulnerable encryption between corporate network and EA network&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod systems&amp;lt;&amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of encryption inside EA network&amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure trust relations between components&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecurely configured Internet-facing applications &amp;lt;br&amp;gt;&lt;br /&gt;
7 Vulnerable or default configuration of routers&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of frontend access filtration&amp;lt;br&amp;gt;&lt;br /&gt;
9 Lacking or misconfigured IDS/IPS&amp;lt;br&amp;gt;&lt;br /&gt;
10 Insecure or inappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&amp;lt;br&amp;gt;&lt;br /&gt;
2 Missing 3rd party software patches&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
4 Universal OS passwords&amp;lt;br&amp;gt;&lt;br /&gt;
5 Missing OS patches&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Lacking or misconfigured monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
8 Insecure internal acces control &amp;lt;br&amp;gt;&lt;br /&gt;
9 Unencrypted remote access &amp;lt;br&amp;gt;&lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of DB patch management&amp;lt;br&amp;gt;&lt;br /&gt;
3 Unnecessary enabled DB features &amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Extensive user and group privileges&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lacking or misconfigured audit&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of server trust check&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of encryption&amp;lt;br&amp;gt;&lt;br /&gt;
4 Autocomplete enabled in the browser &amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure browser scripting options&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecure configuration &amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure sortware distribution service&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of AV software&amp;lt;br&amp;gt;&lt;br /&gt;
9 Password stored in configuration file&amp;lt;br&amp;gt;&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Top 9 Application issues - 2014 ==&lt;br /&gt;
&lt;br /&gt;
1. Lack of patch management&amp;lt;br&amp;gt;&lt;br /&gt;
2. Default passwords for application access&amp;lt;br&amp;gt;&lt;br /&gt;
3. Unnecessary enabled functionality&amp;lt;br&amp;gt;&lt;br /&gt;
4. Open remote management interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
5. Insecure configuration&amp;lt;br&amp;gt;&lt;br /&gt;
6. Unencrypted communication&amp;lt;br&amp;gt;&lt;br /&gt;
7. Access control and SoD&amp;lt;br&amp;gt;&lt;br /&gt;
8. Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
9. Logging and monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[EASSEC-PVAG-ABAP] THE SAP NETWEAVER ABAP PLATFORM VULNERABILITY ASSESSMENT GUIDE 2014&lt;br /&gt;
&lt;br /&gt;
http://erpscan.com/publications/the-sap-netweaver-abap-platform-vulnerability-assessment-guide/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Nikolay Mesherin&lt;br /&gt;
Kirill Nikitenkov&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Application_Security_Vulnerability_Assessment&amp;diff=172603</id>
		<title>Enterprise Application Security Vulnerability Assessment</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Application_Security_Vulnerability_Assessment&amp;diff=172603"/>
				<updated>2014-04-13T23:04:19Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: Created page with &amp;quot;=== Implementation guides  ===  == Objective  ==  This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Her...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start self-assessment of their systems to find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give an attacker full access to business data, even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All of the data was collected and categorized during our extensive experience of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
In this document, we will describe top 10 violations for every layer of Enterprise Business Applications that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues - 2010  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and corporate network&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lacking or vulnerable encryption between corporate network and EA network&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod systems&amp;lt;&amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of encryption inside EA network&amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure trust relations between components&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecurely configured Internet-facing applications &amp;lt;br&amp;gt;&lt;br /&gt;
7 Vulnerable or default configuration of routers&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of frontend access filtration&amp;lt;br&amp;gt;&lt;br /&gt;
9 Lacking or misconfigured IDS/IPS&amp;lt;br&amp;gt;&lt;br /&gt;
10 Insecure or inappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&amp;lt;br&amp;gt;&lt;br /&gt;
2 Missing 3rd party software patches&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
4 Universal OS passwords&amp;lt;br&amp;gt;&lt;br /&gt;
5 Missing OS patches&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Lacking or misconfigured monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
8 Insecure internal acces control &amp;lt;br&amp;gt;&lt;br /&gt;
9 Unencrypted remote access &amp;lt;br&amp;gt;&lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of DB patch management&amp;lt;br&amp;gt;&lt;br /&gt;
3 Unnecessary enabled DB features &amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Extensive user and group privileges&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lacking or misconfigured audit&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of server trust check&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of encryption&amp;lt;br&amp;gt;&lt;br /&gt;
4 Autocomplete enabled in the browser &amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure browser scripting options&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecure configuration &amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure sortware distribution service&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of AV software&amp;lt;br&amp;gt;&lt;br /&gt;
9 Password stored in configuration file&amp;lt;br&amp;gt;&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Top 9 Application issues - 2014 ==&lt;br /&gt;
&lt;br /&gt;
1. Lack of patch management&amp;lt;br&amp;gt;&lt;br /&gt;
2. Default passwords for application access&amp;lt;br&amp;gt;&lt;br /&gt;
3. Unnecessary enabled functionality&amp;lt;br&amp;gt;&lt;br /&gt;
4. Open remote management interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
5. Insecure configuration&amp;lt;br&amp;gt;&lt;br /&gt;
6. Unencrypted communication&amp;lt;br&amp;gt;&lt;br /&gt;
7. Access control and SoD&amp;lt;br&amp;gt;&lt;br /&gt;
8. Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
9. Logging and monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[EASSEC-PVAG-ABAP] THE SAP NETWEAVER ABAP PLATFORM VULNERABILITY ASSESSMENT GUIDE 2014&lt;br /&gt;
http://erpscan.com/publications/the-sap-netweaver-abap-platform-vulnerability-assessment-guide/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Nikolay Mesherin&lt;br /&gt;
Kirill Nikitenkov&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Application_Vulnerability_Statistics&amp;diff=172602</id>
		<title>Enterprise Application Vulnerability Statistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Application_Vulnerability_Statistics&amp;diff=172602"/>
				<updated>2014-04-13T23:00:56Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: Created page with &amp;quot;==== Statistics  ====  == Objective  ==  This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Ap...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show a result of statistical research in the business application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what kind of tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still don’t pay much attention to enterprise business application area, as we see during our and our collegues' researches and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: &lt;br /&gt;
&lt;br /&gt;
• Network architecture security &lt;br /&gt;
&lt;br /&gt;
• OS security &lt;br /&gt;
&lt;br /&gt;
• Database security &lt;br /&gt;
&lt;br /&gt;
• Application security &lt;br /&gt;
&lt;br /&gt;
• Front-end security &lt;br /&gt;
&lt;br /&gt;
Each of the described layers may have their own vulnerabilities that can give an attacker full access to business data, even if other layers are fully secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness about business application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Nikolay Mescherin, Kirill Nikitenkov, Dmitry Chastukhin, Dmitry Evdokimov&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=172601</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=172601"/>
				<updated>2014-04-13T22:58:59Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation, or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin the assessment of enterprise applications &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Application Security Vulnerability Assessment]] &lt;br /&gt;
&lt;br /&gt;
3 Help companies to securely develop and customize business applications&lt;br /&gt;
&lt;br /&gt;
[[Enterprise Application Security Development Issues]] &lt;br /&gt;
&lt;br /&gt;
4 Develop free tools for enterprise business applications assessment &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Software&amp;diff=158523</id>
		<title>Enterprise Business Application Security Software</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Software&amp;diff=158523"/>
				<updated>2013-09-16T17:15:07Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Software  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
Here, information on tools and services that can be used for assessment of business applications will be available. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this area is to provide free tools that can help companies to assess the security of their business applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;[http://online.erpscan.com test SAPGUI Security Online]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com/products/erpscan-pentesting-tool/ SAP Pentesting Tool by ERPScan]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com/products/erpscan-webxml-checker/ ERPScan's web.xml checker]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://www.metasploit.com/modules/auxiliary/scanner/sap Metasploit modules for SAP Pentesting]&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158522</id>
		<title>Enterprise Business Application Security Development Issues</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158522"/>
				<updated>2013-09-16T17:13:59Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
=== Development Issues  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in the source code of Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write custom code such as ABAP for SAP, PeopleCode for PeopleSoft, X++ for Microsoft Dynamics, PL/SQL for Oracle EBS, LotusScript for Lotus and much, much more. Here, we will try to categorize them into 9 main areas filtered by criticality. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE, SANS, OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
== 9 most critical types of issues in source code (EASAD-9-2013) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 Injections (code, SQL, OS)&lt;br /&gt;
&amp;lt;br&amp;gt;2 Critical calls (to DB, to OS)&lt;br /&gt;
&amp;lt;br&amp;gt;3 Missing or bad access control checks (missing auth checks)&lt;br /&gt;
&amp;lt;br&amp;gt;4 Directory / path traversal (write, read, SMBRelay)&lt;br /&gt;
&amp;lt;br&amp;gt;5 Modification of displayed content (XSS stored, XSS linked, JS/HTML injections)&lt;br /&gt;
&amp;lt;br&amp;gt;6 Backdoors (hardcoded credentials)&lt;br /&gt;
&amp;lt;br&amp;gt;7 Covert channels (sockets, HTTP calls, SSRFs)&lt;br /&gt;
&amp;lt;br&amp;gt;8 Information  disclosure (hardcoded users, passwords, debug information) &lt;br /&gt;
&amp;lt;br&amp;gt;9 Obsolete statements (READ TABLE, kernel methods)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
&lt;br /&gt;
Alexander Minozhenko&lt;br /&gt;
&lt;br /&gt;
Pavel Kuzmin&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158521</id>
		<title>Enterprise Business Application Security Development Issues</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158521"/>
				<updated>2013-09-16T17:13:28Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
=== Development Issues  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in the source code of Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write custom code such as ABAP for SAP, PeopleCode for PeopleSoft, X++ for Microsoft Dynamics, PL/SQL for Oracle EBS, LotusScript for Lotus and much, much more. Here, we will try to categorize them into 9 main areas filtered by criticality. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE, SANS, OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
== 9 most critical types of issues in source code (EASAD-9-2013) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 Injections (code, SQL, OS)&lt;br /&gt;
&amp;lt;br&amp;gt;2 Critical calls (to DB, to OS)&lt;br /&gt;
&amp;lt;br&amp;gt;3 Missing or bad access control checks (missing auth checks)&lt;br /&gt;
&amp;lt;br&amp;gt;4 Directory / path traversal (write, read, SMBRelay)&lt;br /&gt;
&amp;lt;br&amp;gt;5 Modification of displayed content (XSS stored, XSS linked, JS/HTML injections)&lt;br /&gt;
&amp;lt;br&amp;gt;6 Backdoors (hardcoded credentials)&lt;br /&gt;
&amp;lt;br&amp;gt;7 Covert channels (sockets, HTTP calls, SSRFs)&lt;br /&gt;
&amp;lt;br&amp;gt;8 Information  disclosure (hardcoded users, passwords, debug information) &lt;br /&gt;
&amp;lt;br&amp;gt;9 Obsolete statements (READ TABLE, kernel methods)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Alexander Minozhenko&lt;br /&gt;
Pavel Kuzmin&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Implementation_Assessment&amp;diff=158520</id>
		<title>Enterprise Business Application Security Implementation Assessment</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Implementation_Assessment&amp;diff=158520"/>
				<updated>2013-09-16T17:09:10Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start self-assessment of their systems to find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give an attacker full access to business data, even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All of the data was collected and categorized during our extensive experience of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
In this document, we will describe top 10 violations for every layer of Enterprise Business Applications that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues - 2010  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and corporate network&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lacking or vulnerable encryption between corporate network and EA network&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod systems&amp;lt;&amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of encryption inside EA network&amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure trust relations between components&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecurely configured Internet-facing applications &amp;lt;br&amp;gt;&lt;br /&gt;
7 Vulnerable or default configuration of routers&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of frontend access filtration&amp;lt;br&amp;gt;&lt;br /&gt;
9 Lacking or misconfigured IDS/IPS&amp;lt;br&amp;gt;&lt;br /&gt;
10 Insecure or inappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&amp;lt;br&amp;gt;&lt;br /&gt;
2 Missing 3rd party software patches&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
4 Universal OS passwords&amp;lt;br&amp;gt;&lt;br /&gt;
5 Missing OS patches&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Lacking or misconfigured monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
8 Insecure internal acces control &amp;lt;br&amp;gt;&lt;br /&gt;
9 Unencrypted remote access &amp;lt;br&amp;gt;&lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of DB patch management&amp;lt;br&amp;gt;&lt;br /&gt;
3 Unnecessary enabled DB features &amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Extensive user and group privileges&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lacking or misconfigured audit&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of server trust check&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of encryption&amp;lt;br&amp;gt;&lt;br /&gt;
4 Autocomplete enabled in the browser &amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure browser scripting options&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecure configuration &amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure sortware distribution service&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of AV software&amp;lt;br&amp;gt;&lt;br /&gt;
9 Password stored in configuration file&amp;lt;br&amp;gt;&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Top 9 Application issues - 2013 ==&lt;br /&gt;
&lt;br /&gt;
1. Lack of patch management&amp;lt;br&amp;gt;&lt;br /&gt;
2. Default passwords for application access&amp;lt;br&amp;gt;&lt;br /&gt;
3. Unnecessary enabled functionality&amp;lt;br&amp;gt;&lt;br /&gt;
4. Open remote management interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
5. Insecure configuration&amp;lt;br&amp;gt;&lt;br /&gt;
6. Unencrypted communication&amp;lt;br&amp;gt;&lt;br /&gt;
7. Access control and SoD&amp;lt;br&amp;gt;&lt;br /&gt;
8. Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
9. Logging and monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovsky&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Nikolay Mesherin&lt;br /&gt;
Kirill Nikitenkov&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics&amp;diff=158519</id>
		<title>Enterprise Business Application Vulnerability Statistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics&amp;diff=158519"/>
				<updated>2013-09-16T17:01:34Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show a result of statistical research in the business application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what kind of tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still don’t pay much attention to enterprise business application area, as we see during our and our collegues' researches and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: &lt;br /&gt;
&lt;br /&gt;
• Network architecture security &lt;br /&gt;
&lt;br /&gt;
• OS security &lt;br /&gt;
&lt;br /&gt;
• Database security &lt;br /&gt;
&lt;br /&gt;
• Application security &lt;br /&gt;
&lt;br /&gt;
• Front-end security &lt;br /&gt;
&lt;br /&gt;
Each of the described layers may have their own vulnerabilities that can give an attacker full access to business data, even if other layers are fully secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness about business application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Nikolay Mescherin, Kirill Nikitenkov, Dmitry Chastukhin, Dmitry Evdokimov&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics&amp;diff=158518</id>
		<title>Enterprise Business Application Vulnerability Statistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics&amp;diff=158518"/>
				<updated>2013-09-16T16:57:31Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show a result of statistical research in the business application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what kind of tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still don’t pay much attention to enterprise business application area, as we see during our and our collegues' researches and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: &lt;br /&gt;
• Network architecture security &lt;br /&gt;
• OS security &lt;br /&gt;
• Database security &lt;br /&gt;
• Application security &lt;br /&gt;
• Front-end security &lt;br /&gt;
&lt;br /&gt;
Each of the described layers may have their own vulnerabilities that can give an attacker full access to business data, even if other layers are fully secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness about business application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Nikolay Mescherin, Kirill Nikitenkov, Dmitry Chastukhin, Dmitry Evdokimov&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=158517</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=158517"/>
				<updated>2013-09-16T16:48:11Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation, or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin the assessment of enterprise applications &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Implementation Assessment]] &lt;br /&gt;
&lt;br /&gt;
3 Help companies to securely develop and customize business applications&lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Development Issues]] &lt;br /&gt;
&lt;br /&gt;
4 Develop free tools for enterprise business applications assessment &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Implementation_Assessment&amp;diff=158486</id>
		<title>Enterprise Business Application Security Implementation Assessment</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Implementation_Assessment&amp;diff=158486"/>
				<updated>2013-09-15T21:53:37Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start a self-assessment of their systems and find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All the data was collected and categorized during our big practice of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
In this document, we will describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues - 2010  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack or vulnerable encryption between corp net and EA Network&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod system&amp;lt;&amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of encryption inside EA Network&amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure trusted relations between components&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecurely configured Internet facing applications &amp;lt;br&amp;gt;&lt;br /&gt;
7 Vulnerable / default configuration of routers&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of frontend access filtration&amp;lt;br&amp;gt;&lt;br /&gt;
9 Lack or misconfigured monitoring IDS/IPS&amp;lt;br&amp;gt;&lt;br /&gt;
10 Insecure/unappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&amp;lt;br&amp;gt;&lt;br /&gt;
2 Missing 3rd party software patches&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
4 Universal OS passwords&amp;lt;br&amp;gt;&lt;br /&gt;
5 Missing OS patches&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Lacking or misconfigured monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
8 Insecure internal acces control &amp;lt;br&amp;gt;&lt;br /&gt;
9 Unencrypted remote access &amp;lt;br&amp;gt;&lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of DB patch management&amp;lt;br&amp;gt;&lt;br /&gt;
3 Unnecessary enabled DB features &amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Extensive user and group privileges&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lacking or misconfigured audit&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 9 Application issues - 2013 ==&lt;br /&gt;
&lt;br /&gt;
1. Lack of patch management&amp;lt;br&amp;gt;&lt;br /&gt;
2. Default Passwords for application access&amp;lt;br&amp;gt;&lt;br /&gt;
3. Unnecessary enabled functionality&amp;lt;br&amp;gt;&lt;br /&gt;
4. Open remote management interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
5. Insecure configuration&amp;lt;br&amp;gt;&lt;br /&gt;
6. Unencrypted communication&amp;lt;br&amp;gt;&lt;br /&gt;
7. Access control and SOD&amp;lt;br&amp;gt;&lt;br /&gt;
8. Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
9. Logging and Monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues - 2010   ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of server trust check&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of encryption&amp;lt;br&amp;gt;&lt;br /&gt;
4 Autocomplete enabled in the browser &amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure browser scripting options&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecure configuration &amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure sortware distribution service&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of AV software&amp;lt;br&amp;gt;&lt;br /&gt;
9 Password stored in configuration file&amp;lt;br&amp;gt;&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovsky&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Nikolay Mesherin&lt;br /&gt;
Kirill Nikitenkov&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=158484</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=158484"/>
				<updated>2013-09-15T21:33:24Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applications &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Implementation Assessment]] &lt;br /&gt;
&lt;br /&gt;
3 Help companies to securely develop and customize business applications&lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Development Issues]] &lt;br /&gt;
&lt;br /&gt;
4 Develop free tools for Enterprise business applications assessment &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Implementation_Assessment&amp;diff=158483</id>
		<title>Enterprise Business Application Security Implementation Assessment</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Implementation_Assessment&amp;diff=158483"/>
				<updated>2013-09-15T21:33:13Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: Created page with &amp;quot;=== Implementation guides  ===  == Objective  ==  This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Her...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start a self-assessment of their systems and find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All the data was collected and categorized during our big practice of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
In this document, we will describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack or vulnerable encryption between corp net and EA Network&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod system&amp;lt;&amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of encryption inside EA Network&amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure trusted relations between components&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecurely configured Internet facing applications &amp;lt;br&amp;gt;&lt;br /&gt;
7 Vulnerable / default configuration of routers&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of frontend access filtration&amp;lt;br&amp;gt;&lt;br /&gt;
9 Lack or misconfigured monitoring IDS/IPS&amp;lt;br&amp;gt;&lt;br /&gt;
10 Insecure/unappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&amp;lt;br&amp;gt;&lt;br /&gt;
2 Missing 3rd party software patches&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
4 Universal OS passwords&amp;lt;br&amp;gt;&lt;br /&gt;
5 Missing OS patches&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Lacking or misconfigured monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
8 Insecure internal acces control &amp;lt;br&amp;gt;&lt;br /&gt;
9 Unencrypted remote access &amp;lt;br&amp;gt;&lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of DB patch management&amp;lt;br&amp;gt;&lt;br /&gt;
3 Unnecessary enabled DB features &amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Extensive user and group privileges&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lacking or misconfigured audit&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&amp;lt;br&amp;gt;&lt;br /&gt;
2 Default passwords for application access&amp;lt;br&amp;gt;&lt;br /&gt;
3 SoD conficts&amp;lt;br&amp;gt;&lt;br /&gt;
4 Unnecessary enabled application features &amp;lt;br&amp;gt;&lt;br /&gt;
5 Open remote management interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure options &amp;lt;br&amp;gt;&lt;br /&gt;
8 Unecrypted communications&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Guest access&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of server trust check&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of encryption&amp;lt;br&amp;gt;&lt;br /&gt;
4 Autocomplete enabled in the browser &amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure browser scripting options&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecure configuration &amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure sortware distribution service&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of AV software&amp;lt;br&amp;gt;&lt;br /&gt;
9 Password stored in configuration file&amp;lt;br&amp;gt;&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovsky&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Nikolay Mesherin&lt;br /&gt;
Kirill Nikitenkov&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158474</id>
		<title>Enterprise Business Application Security Development Issues</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158474"/>
				<updated>2013-09-15T20:44:12Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
=== Development Issues  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in source code of Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write costom code such as ABAP for SAP, PeopleCode for PeopleSoft,X++ for Microsoft Dynamics, PL/SQL for Oracle EBS, LotusScript for Lotus and much much more. Here, we will try to categorize them into 9 main areas filtered by criticality. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE, SANS, OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
== 9 most critical types of issues in source code (EASAD-9-2013) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 injections (Code sql os)&lt;br /&gt;
&amp;lt;br&amp;gt;2 critical calls (to db to os )&lt;br /&gt;
&amp;lt;br&amp;gt;3 missing or bad access control checks (miss auth checks )&lt;br /&gt;
&amp;lt;br&amp;gt;4 directory/path traversal (write, read, smbrelay)&lt;br /&gt;
&amp;lt;br&amp;gt;5 Modification of displayed content (XSS stored, linked, js/html injections)&lt;br /&gt;
&amp;lt;br&amp;gt;6 backdoors (hardcoded credentials)&lt;br /&gt;
&amp;lt;br&amp;gt;7 covert channels (sockets, http calls, ssrf's, )&lt;br /&gt;
&amp;lt;br&amp;gt;8 information  disclose (hardcoded users, passwords, debug information, &lt;br /&gt;
&amp;lt;br&amp;gt;9 obsolete statements ( READ TABLE, kernel methods,….)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Alexander Minojenko&lt;br /&gt;
Pavel Kuzmin&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158473</id>
		<title>Enterprise Business Application Security Development Issues</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158473"/>
				<updated>2013-09-15T20:42:38Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
=== Development Issues  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in source code of Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write costom code such as ABAP for SAP, PeopleCode for PeopleSoft,X++ for Microsoft Dynamics, PL/SQL for Oracle EBS, LotusScript for Lotus and much much more. Here, we will try to categorize them into 9 main areas filtered by criticality. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE, SANS, OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
== 9 most critical types of issues in source code (EASAD-9-2013) ==&lt;br /&gt;
&lt;br /&gt;
1 injections (Code sql os)&lt;br /&gt;
2 critical calls (to db to os )&lt;br /&gt;
3 missing or bad access control checks (miss auth checks )&lt;br /&gt;
4 directory/path traversal (write, read, smbrelay)&lt;br /&gt;
5 Modification of displayed content (XSS stored, linked, js/html injections)&lt;br /&gt;
6 backdoors (hardcoded credentials)&lt;br /&gt;
7 covert channels (sockets, http calls, ssrf's, )&lt;br /&gt;
8 information  disclose (hardcoded users, passwords, debug information, &lt;br /&gt;
9 obsolete statements ( READ TABLE, kernel methods,….)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Alexander Minojenko&lt;br /&gt;
Pavel Kuzmin&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158472</id>
		<title>Enterprise Business Application Security Development Issues</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Development_Issues&amp;diff=158472"/>
				<updated>2013-09-15T20:36:07Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: Created page with &amp;quot; === Development of guides  ===  == Objective  ==  This document will describe different areas of program vulnerabilities that can be found in Enterprise Business applications...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
=== Development of guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write costom code. Here, we will try to categorize it first by dividing into Server and Client side. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
1 XSS&amp;lt;br&amp;gt;&lt;br /&gt;
2 Improper Access Control&amp;lt;br&amp;gt;&lt;br /&gt;
3 Information disclosure&amp;lt;br&amp;gt;&lt;br /&gt;
4 Command/code injection in proprietary language&amp;lt;br&amp;gt;&lt;br /&gt;
5 SQL Injection &amp;lt;br&amp;gt;&lt;br /&gt;
6 Missing Encryption of Sensitive Data&amp;lt;br&amp;gt;&lt;br /&gt;
7 Buffer overflows &amp;lt;br&amp;gt;&lt;br /&gt;
8 Path traversal&amp;lt;br&amp;gt;&lt;br /&gt;
9 CSRF &amp;lt;br&amp;gt;&lt;br /&gt;
10 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX)&amp;lt;br&amp;gt;&lt;br /&gt;
2 Exposed Dangerous Method or Function (ActiveX)&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure scripting server access &amp;lt;br&amp;gt;&lt;br /&gt;
4 File handling Frontend vulnerabilities&amp;lt;br&amp;gt;&lt;br /&gt;
5 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;&lt;br /&gt;
6 Cleartext Storage of Sensitive Information&amp;lt;br&amp;gt;&lt;br /&gt;
7 Use of hard-coded password&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of integrity checking for front-end application&amp;lt;br&amp;gt;&lt;br /&gt;
9 Cleartext Transmission of Sensitive Information&amp;lt;br&amp;gt;&lt;br /&gt;
10 Vulnerable remote services&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group) &amp;lt;br&amp;gt;&lt;br /&gt;
Mikhail Markevich &amp;lt;br&amp;gt;&lt;br /&gt;
Dmitry Evdokimov (ERPScan Research Group) &amp;lt;br&amp;gt;&lt;br /&gt;
Alexey Sintsov (ERPScan Research Group)&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics&amp;diff=158471</id>
		<title>Enterprise Business Application Vulnerability Statistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics&amp;diff=158471"/>
				<updated>2013-09-15T20:33:19Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually with showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document we will show a result of statistical research in the Business Application security area made by DSECRG and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical are those and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security as these applications store business data and any vulnerability in these applications will cause a significant monetary loss. Nonetheless people still don’t pay much attention to Enterprise Business Application area as we see during our and our collegues research and audit data. Business applications are very large and complex systems that consists of different components such as Database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security &lt;br /&gt;
&lt;br /&gt;
Every described layer may have their own vulnerabilities that can give attacker full access to business data even if other layers are fully secured. In this document all the popular applications from described levels and their vulnerabilities vill be shown. The purpose of this document to Increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmityy Chastuhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tuyrin, Nikolay Mescherin, Kirill Nikitenkov, Dmitriy Chastuhin, Dmitriy Evdokimov&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=158470</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=158470"/>
				<updated>2013-09-15T20:30:59Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applications &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Implementation Assessment]] &lt;br /&gt;
&lt;br /&gt;
3 Help companies to securely develop and customize business applications&lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Development Issues]] &lt;br /&gt;
&lt;br /&gt;
4 Develop free tools for Enterprise business applications assessment &lt;br /&gt;
&lt;br /&gt;
[[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
=== Statistics  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually including tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show the results of statistical research in the Business Application security area made by ERPscan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM, and others are one of the major topics within the field of computer security as these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still do not pay much attention to Enterprise Business Application, judging by our and our collegues' research and assessment data. &lt;br /&gt;
Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. &lt;br /&gt;
Overall security of an Enterprise Business Application consist of different layers, such as: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attacker full access to business data even if other layers are completely secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Dmitry Chastukhin, Dmitry Evdokimov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Development of guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write costom code. Here, we will try to categorize it first by dividing into Server and Client side. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
1 XSS&amp;lt;br&amp;gt;&lt;br /&gt;
2 Improper Access Control&amp;lt;br&amp;gt;&lt;br /&gt;
3 Information disclosure&amp;lt;br&amp;gt;&lt;br /&gt;
4 Command/code injection in proprietary language&amp;lt;br&amp;gt;&lt;br /&gt;
5 SQL Injection &amp;lt;br&amp;gt;&lt;br /&gt;
6 Missing Encryption of Sensitive Data&amp;lt;br&amp;gt;&lt;br /&gt;
7 Buffer overflows &amp;lt;br&amp;gt;&lt;br /&gt;
8 Path traversal&amp;lt;br&amp;gt;&lt;br /&gt;
9 CSRF &amp;lt;br&amp;gt;&lt;br /&gt;
10 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX)&amp;lt;br&amp;gt;&lt;br /&gt;
2 Exposed Dangerous Method or Function (ActiveX)&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure scripting server access &amp;lt;br&amp;gt;&lt;br /&gt;
4 File handling Frontend vulnerabilities&amp;lt;br&amp;gt;&lt;br /&gt;
5 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;&lt;br /&gt;
6 Cleartext Storage of Sensitive Information&amp;lt;br&amp;gt;&lt;br /&gt;
7 Use of hard-coded password&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of integrity checking for front-end application&amp;lt;br&amp;gt;&lt;br /&gt;
9 Cleartext Transmission of Sensitive Information&amp;lt;br&amp;gt;&lt;br /&gt;
10 Vulnerable remote services&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group) &amp;lt;br&amp;gt;&lt;br /&gt;
Mikhail Markevich &amp;lt;br&amp;gt;&lt;br /&gt;
Dmitry Evdokimov (ERPScan Research Group) &amp;lt;br&amp;gt;&lt;br /&gt;
Alexey Sintsov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start a self-assessment of their systems and find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All the data was collected and categorized during our big practice of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
In this document, we will describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack or vulnerable encryption between corp net and EA Network&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod system&amp;lt;&amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of encryption inside EA Network&amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure trusted relations between components&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecurely configured Internet facing applications &amp;lt;br&amp;gt;&lt;br /&gt;
7 Vulnerable / default configuration of routers&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of frontend access filtration&amp;lt;br&amp;gt;&lt;br /&gt;
9 Lack or misconfigured monitoring IDS/IPS&amp;lt;br&amp;gt;&lt;br /&gt;
10 Insecure/unappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&amp;lt;br&amp;gt;&lt;br /&gt;
2 Missing 3rd party software patches&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
4 Universal OS passwords&amp;lt;br&amp;gt;&lt;br /&gt;
5 Missing OS patches&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Lacking or misconfigured monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
8 Insecure internal acces control &amp;lt;br&amp;gt;&lt;br /&gt;
9 Unencrypted remote access &amp;lt;br&amp;gt;&lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of DB patch management&amp;lt;br&amp;gt;&lt;br /&gt;
3 Unnecessary enabled DB features &amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Extensive user and group privileges&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lacking or misconfigured audit&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&amp;lt;br&amp;gt;&lt;br /&gt;
2 Default passwords for application access&amp;lt;br&amp;gt;&lt;br /&gt;
3 SoD conficts&amp;lt;br&amp;gt;&lt;br /&gt;
4 Unnecessary enabled application features &amp;lt;br&amp;gt;&lt;br /&gt;
5 Open remote management interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure options &amp;lt;br&amp;gt;&lt;br /&gt;
8 Unecrypted communications&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Guest access&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of server trust check&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of encryption&amp;lt;br&amp;gt;&lt;br /&gt;
4 Autocomplete enabled in the browser &amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure browser scripting options&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecure configuration &amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure sortware distribution service&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of AV software&amp;lt;br&amp;gt;&lt;br /&gt;
9 Password stored in configuration file&amp;lt;br&amp;gt;&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovsky &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics_2009&amp;diff=141466</id>
		<title>Enterprise Business Application Vulnerability Statistics 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics_2009&amp;diff=141466"/>
				<updated>2012-12-26T16:44:05Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Objective ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area.  &lt;br /&gt;
&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
In this document, we will show the results of statistical research in the Business Application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical they are and what kind of tendencies we see.&lt;br /&gt;
&lt;br /&gt;
== Intro ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in them will cause significant monetary loss. Nonetheless, people still don’t pay much attention to Enterprise Business Application area, as we see during our and our colleagues' research and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server, and other parts. Also, those systems rely on various hardware and software that can have their own vulnerabilities. The overall security of Enterprise Business Application consists of different layers, such as:&amp;lt;br&amp;gt;&lt;br /&gt;
•	Network architecture security;&amp;lt;br&amp;gt;&lt;br /&gt;
•	OS security;&amp;lt;br&amp;gt;&lt;br /&gt;
•	Database security;&amp;lt;br&amp;gt;&lt;br /&gt;
•	Application security;&amp;lt;br&amp;gt;&lt;br /&gt;
•	Front-end security.&lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attackers full access to business data even if other layers are fully secured.&lt;br /&gt;
In this document, all popular applications from the described levels and their vulnerabilities will be shown. The purpose of this document to increase awareness of Business Application security.&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities]&lt;br /&gt;
&lt;br /&gt;
Annual report coming soon...&lt;br /&gt;
&lt;br /&gt;
== Authors==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&amp;lt;br&amp;gt;&lt;br /&gt;
Dmitry Chastukhin (ERPScan Research Group)&amp;lt;br&amp;gt;&lt;br /&gt;
Dmitry Evdokimov (ERPScan Research Group)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Contributors==&lt;br /&gt;
&lt;br /&gt;
Leodid Kats   (dsec.ru)&amp;lt;br&amp;gt;&lt;br /&gt;
Olga Yurova   (dsec.ru)&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics_2009&amp;diff=141465</id>
		<title>Enterprise Business Application Vulnerability Statistics 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics_2009&amp;diff=141465"/>
				<updated>2012-12-26T16:43:18Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Objective ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area.  &lt;br /&gt;
&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
In this document, we will show the results of statistical research in the Business Application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical they are and what kind of tendencies we see.&lt;br /&gt;
&lt;br /&gt;
== Intro ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in them will cause significant monetary loss. Nonetheless, people still don’t pay much attention to Enterprise Business Application area, as we see during our and our colleagues' research and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server, and other parts. Also, those systems rely on various hardware and software that can have their own vulnerabilities. The overall security of Enterprise Business Application consists of different layers, such as:&amp;lt;br&amp;gt;&lt;br /&gt;
•	Network architecture security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Os security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Database security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Application security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Front-end security.&lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attackers full access to business data even if other layers are fully secured.&lt;br /&gt;
In this document, all popular applications from the described levels and their vulnerabilities will be shown. The purpose of this document to increase awareness of Business Application security.&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities]&lt;br /&gt;
&lt;br /&gt;
Annual report comming soon...&lt;br /&gt;
&lt;br /&gt;
== Authors==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&amp;lt;br&amp;gt;&lt;br /&gt;
Dmitry Chastukhin (ERPScan Research Group)&amp;lt;br&amp;gt;&lt;br /&gt;
Dmitriy Evdokimov (ERPScan Research Group)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Contributors==&lt;br /&gt;
&lt;br /&gt;
Leodid Kats   (dsec.ru)&amp;lt;br&amp;gt;&lt;br /&gt;
Olga Yurova   (dsec.ru)&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics_2009&amp;diff=141464</id>
		<title>Enterprise Business Application Vulnerability Statistics 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics_2009&amp;diff=141464"/>
				<updated>2012-12-26T16:43:03Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Objective ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area.  &lt;br /&gt;
&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
In this document, we will show the results of statistical research in the Business Application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical they are and what kind of tendencies we see.&lt;br /&gt;
&lt;br /&gt;
== Intro ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in them will cause significant monetary loss. Nonetheless, people still don’t pay much attention to Enterprise Business Application area, as we see during our and our colleagues' research and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server, and other parts. Also, those systems rely on various hardware and software that can have their own vulnerabilities. The overall security of Enterprise Business Application consists of different layers, such as:&amp;lt;br&amp;gt;&lt;br /&gt;
•	Network architecture security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Os security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Database security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Application security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Front-end security.&lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attackers full access to business data even if other layers are fully secured.&lt;br /&gt;
In this document, all popular applications from the described levels and their vulnerabilities will be shown. The purpose of this document to increase awareness of Business Application security.&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities]&lt;br /&gt;
&lt;br /&gt;
Annual report comming soon...&lt;br /&gt;
&lt;br /&gt;
== Authors==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&amp;lt;br&amp;gt;&lt;br /&gt;
Dmitry Chastukhin (ERPScan Research Group)&amp;lt;br&amp;gt;&lt;br /&gt;
Dmitriy Evdokimov (ERPScan Research Group)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Contributors==&lt;br /&gt;
&lt;br /&gt;
Leodid Kats   (dsec.ru)&lt;br /&gt;
Olga Yurova   (dsec.ru)&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics_2009&amp;diff=141463</id>
		<title>Enterprise Business Application Vulnerability Statistics 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics_2009&amp;diff=141463"/>
				<updated>2012-12-26T16:42:39Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Objective ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually, showing tendencies and changes in Enterprise Business Application Security area.  &lt;br /&gt;
&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
In this document, we will show the results of statistical research in the Business Application security area made by ERPScan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical they are and what kind of tendencies we see.&lt;br /&gt;
&lt;br /&gt;
== Intro ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM are one of the major topics within the field of computer security because these applications store business data, and any vulnerability in them will cause significant monetary loss. Nonetheless, people still don’t pay much attention to Enterprise Business Application area, as we see during our and our colleagues' research and audits. Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server, and other parts. Also, those systems rely on various hardware and software that can have their own vulnerabilities. The overall security of Enterprise Business Application consists of different layers, such as:&amp;lt;br&amp;gt;&lt;br /&gt;
•	Network architecture security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Os security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Database security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Application security&amp;lt;br&amp;gt;&lt;br /&gt;
•	Front-end security.&lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attackers full access to business data even if other layers are fully secured.&lt;br /&gt;
In this document, all popular applications from the described levels and their vulnerabilities will be shown. The purpose of this document to increase awareness of Business Application security.&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities]&lt;br /&gt;
&lt;br /&gt;
Annual report comming soon...&lt;br /&gt;
&lt;br /&gt;
== Authors==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&lt;br /&gt;
Dmitry Chastukhin (ERPScan Research Group)&lt;br /&gt;
Dmitriy Evdokimov (ERPScan Research Group)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Contributors==&lt;br /&gt;
&lt;br /&gt;
Leodid Kats   (dsec.ru)&lt;br /&gt;
Olga Yurova   (dsec.ru)&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project/Roadmp&amp;diff=141462</id>
		<title>OWASP Enterprise Application Security Project/Roadmp</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project/Roadmp&amp;diff=141462"/>
				<updated>2012-12-26T16:37:40Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*'''Primary goals''':&lt;br /&gt;
#Aware people about EA security vulnerabilities by releasing annual (later, quarterly) statistics of enterprise application security vulnerabilities,&lt;br /&gt;
#Help companies to begin EA assessment by creating a guideline for assessing EA security, &lt;br /&gt;
#Create a report of top 10 vulnerabilities or a similar report for EA,&lt;br /&gt;
#Publish a free tools for EA assessment.&lt;br /&gt;
&lt;br /&gt;
*'''Project Roadmap''' (as mentioned above):&lt;br /&gt;
#Create a dashboard with high level overview,&lt;br /&gt;
#Create a dashboard about security assessment,&lt;br /&gt;
#Create links to other guidelines,&lt;br /&gt;
#Publish statistical reports annually,&lt;br /&gt;
#Create OWASP EAS Top 10 vulnerabilities page, &lt;br /&gt;
#Finish our first security assessment tool.&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141240</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141240"/>
				<updated>2012-12-17T17:03:51Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Statistics  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually including tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show the results of statistical research in the Business Application security area made by ERPscan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM, and others are one of the major topics within the field of computer security as these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still do not pay much attention to Enterprise Business Application, judging by our and our collegues' research and assessment data. &lt;br /&gt;
Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. &lt;br /&gt;
Overall security of an Enterprise Business Application consist of different layers, such as: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attacker full access to business data even if other layers are completely secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Dmitry Chastukhin, Dmitry Evdokimov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Development of guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write costom code. Here, we will try to categorize it first by dividing into Server and Client side. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
1 XSS&amp;lt;br&amp;gt;&lt;br /&gt;
2 Improper Access Control&amp;lt;br&amp;gt;&lt;br /&gt;
3 Information disclosure&amp;lt;br&amp;gt;&lt;br /&gt;
4 Command/code injection in proprietary language&amp;lt;br&amp;gt;&lt;br /&gt;
5 SQL Injection &amp;lt;br&amp;gt;&lt;br /&gt;
6 Missing Encryption of Sensitive Data&amp;lt;br&amp;gt;&lt;br /&gt;
7 Buffer overflows &amp;lt;br&amp;gt;&lt;br /&gt;
8 Path traversal&amp;lt;br&amp;gt;&lt;br /&gt;
9 CSRF &amp;lt;br&amp;gt;&lt;br /&gt;
10 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX)&amp;lt;br&amp;gt;&lt;br /&gt;
2 Exposed Dangerous Method or Function (ActiveX)&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure scripting server access &amp;lt;br&amp;gt;&lt;br /&gt;
4 File handling Frontend vulnerabilities&amp;lt;br&amp;gt;&lt;br /&gt;
5 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;&lt;br /&gt;
6 Cleartext Storage of Sensitive Information&amp;lt;br&amp;gt;&lt;br /&gt;
7 Use of hard-coded password&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of integrity checking for front-end application&amp;lt;br&amp;gt;&lt;br /&gt;
9 Cleartext Transmission of Sensitive Information&amp;lt;br&amp;gt;&lt;br /&gt;
10 Vulnerable remote services&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group) &amp;lt;br&amp;gt;&lt;br /&gt;
Mikhail Markevich &amp;lt;br&amp;gt;&lt;br /&gt;
Dmitry Evdokimov (ERPScan Research Group) &amp;lt;br&amp;gt;&lt;br /&gt;
Alexey Sintsov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start a self-assessment of their systems and find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All the data was collected and categorized during our big practice of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &amp;lt;br&amp;gt;&lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
In this document, we will describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack or vulnerable encryption between corp net and EA Network&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod system&amp;lt;&amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of encryption inside EA Network&amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure trusted relations between components&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecurely configured Internet facing applications &amp;lt;br&amp;gt;&lt;br /&gt;
7 Vulnerable / default configuration of routers&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of frontend access filtration&amp;lt;br&amp;gt;&lt;br /&gt;
9 Lack or misconfigured monitoring IDS/IPS&amp;lt;br&amp;gt;&lt;br /&gt;
10 Insecure/unappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&amp;lt;br&amp;gt;&lt;br /&gt;
2 Missing 3rd party software patches&amp;lt;br&amp;gt;&lt;br /&gt;
3 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
4 Universal OS passwords&amp;lt;br&amp;gt;&lt;br /&gt;
5 Missing OS patches&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lacking or misconfigured network access control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Lacking or misconfigured monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
8 Insecure internal acces control &amp;lt;br&amp;gt;&lt;br /&gt;
9 Unencrypted remote access &amp;lt;br&amp;gt;&lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of DB patch management&amp;lt;br&amp;gt;&lt;br /&gt;
3 Unnecessary enabled DB features &amp;lt;br&amp;gt;&lt;br /&gt;
4 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;&lt;br /&gt;
7 Extensive user and group privileges&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lacking or misconfigured audit&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&amp;lt;br&amp;gt;&lt;br /&gt;
2 Default passwords for application access&amp;lt;br&amp;gt;&lt;br /&gt;
3 SoD conficts&amp;lt;br&amp;gt;&lt;br /&gt;
4 Unnecessary enabled application features &amp;lt;br&amp;gt;&lt;br /&gt;
5 Open remote management interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
6 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure options &amp;lt;br&amp;gt;&lt;br /&gt;
8 Unecrypted communications&amp;lt;br&amp;gt;&lt;br /&gt;
9 Insecure trust relations&amp;lt;br&amp;gt;&lt;br /&gt;
10 Guest access&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&amp;lt;br&amp;gt;&lt;br /&gt;
2 Lack of server trust check&amp;lt;br&amp;gt;&lt;br /&gt;
3 Lack of encryption&amp;lt;br&amp;gt;&lt;br /&gt;
4 Autocomplete enabled in the browser &amp;lt;br&amp;gt;&lt;br /&gt;
5 Insecure browser scripting options&amp;lt;br&amp;gt;&lt;br /&gt;
6 Insecure configuration &amp;lt;br&amp;gt;&lt;br /&gt;
7 Insecure sortware distribution service&amp;lt;br&amp;gt;&lt;br /&gt;
8 Lack of AV software&amp;lt;br&amp;gt;&lt;br /&gt;
9 Password stored in configuration file&amp;lt;br&amp;gt;&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovsky &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141239</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141239"/>
				<updated>2012-12-17T17:02:04Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Statistics  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually including tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show the results of statistical research in the Business Application security area made by ERPscan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM, and others are one of the major topics within the field of computer security as these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still do not pay much attention to Enterprise Business Application, judging by our and our collegues' research and assessment data. &lt;br /&gt;
Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. &lt;br /&gt;
Overall security of an Enterprise Business Application consist of different layers, such as: &lt;br /&gt;
• Network architecture security &amp;lt;br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attacker full access to business data even if other layers are completely secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Dmitry Chastukhin, Dmitry Evdokimov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Development of guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write costom code. Here, we will try to categorize it first by dividing into Server and Client side. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
1 XSS&lt;br /&gt;
2 Improper Access Control&lt;br /&gt;
3 Information disclosure&lt;br /&gt;
4 Command/code injection in proprietary language&lt;br /&gt;
5 SQL Injection &lt;br /&gt;
6 Missing Encryption of Sensitive Data&lt;br /&gt;
7 Buffer overflows &lt;br /&gt;
8 Path traversal&lt;br /&gt;
9 CSRF &lt;br /&gt;
10 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX )&lt;br /&gt;
2 Exposed Dangerous Method or Function (ActiveX)&lt;br /&gt;
3 Insecure scripting server access &lt;br /&gt;
4 File handling Frontend vulnerabilities&lt;br /&gt;
5 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
6 Cleartext Storage of Sensitive Information&lt;br /&gt;
7 Use of Hard-coded Password&lt;br /&gt;
8 Lack of integrity checking for front-end application&lt;br /&gt;
9 Cleartext Transmission of Sensitive Information&lt;br /&gt;
10 Vulnerable remote services&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group) &lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
Dmitry Evdokimov (ERPScan Research Group) &lt;br /&gt;
Alexey Sintsov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start a self-assessment of their systems and find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All the data was collected and categorized during our big practice of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &lt;br /&gt;
• Network architecture security &lt;br /&gt;
• OS security &lt;br /&gt;
• Database security &lt;br /&gt;
• Application security &lt;br /&gt;
• Front-end security &lt;br /&gt;
In this document, we will describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&lt;br /&gt;
2 Lack or vulnerable encryption between corp net and EA Network&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod system&amp;lt;&lt;br /&gt;
4 Lack of encryption inside EA Network&lt;br /&gt;
5 Insecure trusted relations between components&lt;br /&gt;
6 Insecurely configured Internet facing applicatins &lt;br /&gt;
7 Vulnerable / default configuration of routers&lt;br /&gt;
8 Lack of frontend access filtration&lt;br /&gt;
9 Lack or misconfigured monitoring IDS/IPS&lt;br /&gt;
10 Insecure/unappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&lt;br /&gt;
2 Missing 3rd party software patches&lt;br /&gt;
3 Insecure trust relations&lt;br /&gt;
4 Universal OS passwords&lt;br /&gt;
5 Missing OS patches&lt;br /&gt;
6 Lacking or misconfigured network access control&lt;br /&gt;
7 Lacking or misconfigured monitoring&lt;br /&gt;
8 Insecure internal acces control &lt;br /&gt;
9 Unencrypted remote access &lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&lt;br /&gt;
2 Lack of DB patch management&lt;br /&gt;
3 Unnecessary enabled DB features &lt;br /&gt;
4 Lack of password lockout/complexity checks&lt;br /&gt;
5 Unencrypted sensitive data transport / data&lt;br /&gt;
6 Lack or misconfigured network acess control&lt;br /&gt;
7 Extensive user and group privileges&lt;br /&gt;
8 Lacking or misconfigured audit&lt;br /&gt;
9 Insecure trust relations&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&lt;br /&gt;
2 Default passwords for application access&lt;br /&gt;
3 SoD conficts&lt;br /&gt;
4 Unnecessary enabled application features &lt;br /&gt;
5 Open remote management interfaces&lt;br /&gt;
6 Lack of password lockout/complexity checks&lt;br /&gt;
7 Insecure options &lt;br /&gt;
8 Unecrypted communications&lt;br /&gt;
9 Insecure trust relations&lt;br /&gt;
10 Guest access&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&lt;br /&gt;
2 Lack of server trust check&lt;br /&gt;
3 Lack of encryption&lt;br /&gt;
4 Autocomplete enabled in the browser &lt;br /&gt;
5 Insecure browser scripting options&lt;br /&gt;
6 Insecure configuration &lt;br /&gt;
7 Insecure sortware distribution service&lt;br /&gt;
8 Lack of AV software&lt;br /&gt;
9 Password stored in configuration file&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovsky &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141238</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141238"/>
				<updated>2012-12-17T17:01:45Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Statistics  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually including tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show the results of statistical research in the Business Application security area made by ERPscan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM, and others are one of the major topics within the field of computer security as these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still do not pay much attention to Enterprise Business Application, judging by our and our collegues' research and assessment data. &lt;br /&gt;
Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. &lt;br /&gt;
Overall security of an Enterprise Business Application consist of different layers, such as: &lt;br /&gt;
• Network architecture security &amp;lt;/br&amp;gt;&lt;br /&gt;
• OS security &amp;lt;/br&amp;gt;&lt;br /&gt;
• Database security &amp;lt;/br&amp;gt;&lt;br /&gt;
• Application security &amp;lt;/br&amp;gt;&lt;br /&gt;
• Front-end security &amp;lt;/br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attacker full access to business data even if other layers are completely secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Dmitry Chastukhin, Dmitry Evdokimov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Development of guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write costom code. Here, we will try to categorize it first by dividing into Server and Client side. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
1 XSS&lt;br /&gt;
2 Improper Access Control&lt;br /&gt;
3 Information disclosure&lt;br /&gt;
4 Command/code injection in proprietary language&lt;br /&gt;
5 SQL Injection &lt;br /&gt;
6 Missing Encryption of Sensitive Data&lt;br /&gt;
7 Buffer overflows &lt;br /&gt;
8 Path traversal&lt;br /&gt;
9 CSRF &lt;br /&gt;
10 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX )&lt;br /&gt;
2 Exposed Dangerous Method or Function (ActiveX)&lt;br /&gt;
3 Insecure scripting server access &lt;br /&gt;
4 File handling Frontend vulnerabilities&lt;br /&gt;
5 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
6 Cleartext Storage of Sensitive Information&lt;br /&gt;
7 Use of Hard-coded Password&lt;br /&gt;
8 Lack of integrity checking for front-end application&lt;br /&gt;
9 Cleartext Transmission of Sensitive Information&lt;br /&gt;
10 Vulnerable remote services&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group) &lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
Dmitry Evdokimov (ERPScan Research Group) &lt;br /&gt;
Alexey Sintsov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start a self-assessment of their systems and find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All the data was collected and categorized during our big practice of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &lt;br /&gt;
• Network architecture security &lt;br /&gt;
• OS security &lt;br /&gt;
• Database security &lt;br /&gt;
• Application security &lt;br /&gt;
• Front-end security &lt;br /&gt;
In this document, we will describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&lt;br /&gt;
2 Lack or vulnerable encryption between corp net and EA Network&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod system&amp;lt;&lt;br /&gt;
4 Lack of encryption inside EA Network&lt;br /&gt;
5 Insecure trusted relations between components&lt;br /&gt;
6 Insecurely configured Internet facing applicatins &lt;br /&gt;
7 Vulnerable / default configuration of routers&lt;br /&gt;
8 Lack of frontend access filtration&lt;br /&gt;
9 Lack or misconfigured monitoring IDS/IPS&lt;br /&gt;
10 Insecure/unappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&lt;br /&gt;
2 Missing 3rd party software patches&lt;br /&gt;
3 Insecure trust relations&lt;br /&gt;
4 Universal OS passwords&lt;br /&gt;
5 Missing OS patches&lt;br /&gt;
6 Lacking or misconfigured network access control&lt;br /&gt;
7 Lacking or misconfigured monitoring&lt;br /&gt;
8 Insecure internal acces control &lt;br /&gt;
9 Unencrypted remote access &lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&lt;br /&gt;
2 Lack of DB patch management&lt;br /&gt;
3 Unnecessary enabled DB features &lt;br /&gt;
4 Lack of password lockout/complexity checks&lt;br /&gt;
5 Unencrypted sensitive data transport / data&lt;br /&gt;
6 Lack or misconfigured network acess control&lt;br /&gt;
7 Extensive user and group privileges&lt;br /&gt;
8 Lacking or misconfigured audit&lt;br /&gt;
9 Insecure trust relations&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&lt;br /&gt;
2 Default passwords for application access&lt;br /&gt;
3 SoD conficts&lt;br /&gt;
4 Unnecessary enabled application features &lt;br /&gt;
5 Open remote management interfaces&lt;br /&gt;
6 Lack of password lockout/complexity checks&lt;br /&gt;
7 Insecure options &lt;br /&gt;
8 Unecrypted communications&lt;br /&gt;
9 Insecure trust relations&lt;br /&gt;
10 Guest access&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&lt;br /&gt;
2 Lack of server trust check&lt;br /&gt;
3 Lack of encryption&lt;br /&gt;
4 Autocomplete enabled in the browser &lt;br /&gt;
5 Insecure browser scripting options&lt;br /&gt;
6 Insecure configuration &lt;br /&gt;
7 Insecure sortware distribution service&lt;br /&gt;
8 Lack of AV software&lt;br /&gt;
9 Password stored in configuration file&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovsky &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141237</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141237"/>
				<updated>2012-12-17T17:00:07Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Main  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (i.e. 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== The purpose of the project  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications control money and resources, and any security violation can result in significant money loss. The purpose of this project is to aware people about enterprise application security problems and create guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise application security vulnerabilities by releasing annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Statistics  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually including tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document will show the results of statistical research in the Business Application security area made by ERPscan Research Group and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical those are and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM, and others are one of the major topics within the field of computer security as these applications store business data, and any vulnerability in these applications will cause a significant monetary loss. Nonetheless, people still do not pay much attention to Enterprise Business Application, judging by our and our collegues' research and assessment data. &lt;br /&gt;
Business applications are very large and complex systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. &lt;br /&gt;
Overall security of an Enterprise Business Application consist of different layers, such as: &lt;br /&gt;
• Network architecture security &lt;br /&gt;
• OS security &lt;br /&gt;
• Database security &lt;br /&gt;
• Application security &lt;br /&gt;
• Front-end security &lt;br /&gt;
&lt;br /&gt;
Every described layer may have its own vulnerabilities that can give attacker full access to business data even if other layers are completely secured. In this document, all the popular applications from described levels and their vulnerabilities will be shown. The purpose of this document is to increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmitry Chastukhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tyurin, Dmitry Chastukhin, Dmitry Evdokimov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Development of guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of program vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the developers of Enterprise Business software. Here, we will collect top software vulnerabilities in server side and frontend side that can exist in Business Applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used to develop business applications and write costom code. Here, we will try to categorize it first by dividing into Server and Client side. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
1 XSS&lt;br /&gt;
2 Improper Access Control&lt;br /&gt;
3 Information disclosure&lt;br /&gt;
4 Command/code injection in proprietary language&lt;br /&gt;
5 SQL Injection &lt;br /&gt;
6 Missing Encryption of Sensitive Data&lt;br /&gt;
7 Buffer overflows &lt;br /&gt;
8 Path traversal&lt;br /&gt;
9 CSRF &lt;br /&gt;
10 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX )&lt;br /&gt;
2 Exposed Dangerous Method or Function (ActiveX)&lt;br /&gt;
3 Insecure scripting server access &lt;br /&gt;
4 File handling Frontend vulnerabilities&lt;br /&gt;
5 Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
6 Cleartext Storage of Sensitive Information&lt;br /&gt;
7 Use of Hard-coded Password&lt;br /&gt;
8 Lack of integrity checking for front-end application&lt;br /&gt;
9 Cleartext Transmission of Sensitive Information&lt;br /&gt;
10 Vulnerable remote services&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
coming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group) &lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
Dmitry Evdokimov (ERPScan Research Group) &lt;br /&gt;
Alexey Sintsov (ERPScan Research Group) &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation guides  ===&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document will describe different areas of secure implementation of Enterprise Business Applications and ERP systems. Here, we will mainly focus on security architecture and configuration threats because program errors are well described in the &amp;quot;Software vulnerabilities&amp;quot; topic.&lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document is to increase awareness of the administrators of Business Application security and help them to start a self-assessment of their systems and find the most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (like ERP, it is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consist of different components such as Database server, Front-end, Web server, Application server and other parts. Also, those systems rely on different hardware and software that can have their own vulnerabilities. Every described layer may have its own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are completely secured. &lt;br /&gt;
&lt;br /&gt;
All the data was collected and categorized during our big practice of assessing the security of popular Business Applications such as SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers, including: &lt;br /&gt;
• Network architecture security &lt;br /&gt;
• OS security &lt;br /&gt;
• Database security &lt;br /&gt;
• Application security &lt;br /&gt;
• Front-end security &lt;br /&gt;
In this document, we will describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&lt;br /&gt;
2 Lack or vulnerable encryption between corp net and EA Network&lt;br /&gt;
3 Lack of separation between Test, Dev, and Prod system&amp;lt;&lt;br /&gt;
4 Lack of encryption inside EA Network&lt;br /&gt;
5 Insecure trusted relations between components&lt;br /&gt;
6 Insecurely configured Internet facing applicatins &lt;br /&gt;
7 Vulnerable / default configuration of routers&lt;br /&gt;
8 Lack of frontend access filtration&lt;br /&gt;
9 Lack or misconfigured monitoring IDS/IPS&lt;br /&gt;
10 Insecure/unappropriate wireless comunications&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary enabled services&lt;br /&gt;
2 Missing 3rd party software patches&lt;br /&gt;
3 Insecure trust relations&lt;br /&gt;
4 Universal OS passwords&lt;br /&gt;
5 Missing OS patches&lt;br /&gt;
6 Lacking or misconfigured network access control&lt;br /&gt;
7 Lacking or misconfigured monitoring&lt;br /&gt;
8 Insecure internal acces control &lt;br /&gt;
9 Unencrypted remote access &lt;br /&gt;
10 Lack of password lockout/complexity checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&lt;br /&gt;
2 Lack of DB patch management&lt;br /&gt;
3 Unnecessary enabled DB features &lt;br /&gt;
4 Lack of password lockout/complexity checks&lt;br /&gt;
5 Unencrypted sensitive data transport / data&lt;br /&gt;
6 Lack or misconfigured network acess control&lt;br /&gt;
7 Extensive user and group privileges&lt;br /&gt;
8 Lacking or misconfigured audit&lt;br /&gt;
9 Insecure trust relations&lt;br /&gt;
10 Open additional interfaces&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&lt;br /&gt;
2 Default passwords for application access&lt;br /&gt;
3 SoD conficts&lt;br /&gt;
4 Unnecessary enabled application features &lt;br /&gt;
5 Open remote management interfaces&lt;br /&gt;
6 Lack of password lockout/complexity checks&lt;br /&gt;
7 Insecure options &lt;br /&gt;
8 Unecrypted communications&lt;br /&gt;
9 Insecure trust relations&lt;br /&gt;
10 Guest access&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable frontend applications&lt;br /&gt;
2 Lack of server trust check&lt;br /&gt;
3 Lack of encryption&lt;br /&gt;
4 Autocomplete enabled in the browser &lt;br /&gt;
5 Insecure browser scripting options&lt;br /&gt;
6 Insecure configuration &lt;br /&gt;
7 Insecure sortware distribution service&lt;br /&gt;
8 Lack of AV software&lt;br /&gt;
9 Password stored in configuration file&lt;br /&gt;
10 Sensitive information storage&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovsky &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (ERPScan Research Group)&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alexander&amp;diff=141187</id>
		<title>User:Alexander</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alexander&amp;diff=141187"/>
				<updated>2012-12-15T13:10:56Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A father of ERPScan Security Scanner for SAP. Organizer of ZeroNights deep-technical security conference. His expertise covers security of enterprise business-critical software like ERP, CRM, SRM, banking and processing software. He is the manager of OWASP-EAS (OWASP subproject), a well-known security expert of the enterprise applications of such vendors as SAP and Oracle, who published a significant number of the vulnerabilities found in the applications of these vendors with acknowledgements from SAP. He is the writer of multiple whitepapers and surveys devoted to information security research in SAP like &amp;quot;SAP Security in figures&amp;quot;. Alexander were invited to speak and train at international conferences such as BlackHat, RSA, HITB and 30 others around globe  as well as in internal workshops for SAP and fortune 500 companies.&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141186</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141186"/>
				<updated>2012-12-15T13:02:13Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (ie 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== Project purpose  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications controls money and resources and every security violation can result a significant money loss. Purpose of this project is to aware people about enterprise application security problems and create a guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise applicatio security vulnerabilities by making an Annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop a free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually with showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document we will show a result of statistical research in the Business Application security area made by DSECRG and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical are those and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security as these applications store business data and any vulnerability in these applications will cause a significant monetary loss. Nonetheless people still don’t pay much attention to Enterprise Business Application area as we see during our and our collegues research and audit data. Business applications are very large and complex systems that consists of different components such as Database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security &lt;br /&gt;
&lt;br /&gt;
Every described layer may have their own vulnerabilities that can give attacker full access to business data even if other layers are fully secured. In this document all the popular applications from described levels and their vulnerabilities vill be shown. The purpose of this document to Increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmityy Chastuhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tuyrin, Dmitriy Chastuhin, Dmitriy Evdokimov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Development guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of programm vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Developers of Enterprise business application software. Here we will collect top software vulnerabilities in server site and frontend side that can exist in Business applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used for developing business applications and writing a costom code. Here we will try to categorize it firstly by dividing into Server and Client site. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 XSS&amp;lt;br&amp;gt;2 Improper Access Control &amp;lt;br&amp;gt;3 Information disclosure &amp;lt;br&amp;gt;4 Command/code injection in proprietary language&amp;lt;br&amp;gt;5 SQL Injection &amp;lt;br&amp;gt;6 Missing Encryption of Sensitive Data&amp;lt;br&amp;gt;7 Buffer overflows &amp;lt;br&amp;gt;8 Path traversal&amp;lt;br&amp;gt;9 CSRF &amp;lt;br&amp;gt;10 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX )&amp;lt;br&amp;gt;2 Exposed Dangerous Method or Function (ActiveX)&amp;lt;br&amp;gt;3 Insecure scripting server access &amp;lt;br&amp;gt;4 File handling Frontend vulnerabilities&amp;lt;br&amp;gt;5 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;6 Cleartext Storage of Sensitive Information&amp;lt;br&amp;gt;7 Use of Hard-coded Password&amp;lt;br&amp;gt;8 Lack of integrity checking for front-end application&amp;lt;br&amp;gt;9 Cleartext Transmission of Sensitive Information&amp;lt;br&amp;gt;10 Vulnerable remote services&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
cooming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) Mikhail Markevich Dmitriy Evdokimov (DSecRG) Alexey Sintsov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Implementation guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of Secure implementation of g Enterprise Business Applications and ERP systems. Here we will mainly focus on security architecture and configuration threads because pragramm errors are well described in &amp;quot;Software vulnerabilities&amp;quot; topic &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Administrators of Business Application security and help them to start a beginning self-assessment of their systems and find a most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (Like ERP - is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consists of different components such as database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Every described layer may have their own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are fully secured. &lt;br /&gt;
&lt;br /&gt;
 All information was collected and catecorized during our big practice of security assessing Popular business applications Like in SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security In this document we will Describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&amp;lt;br&amp;gt;2 Lack or vulnerable encryption between corp net and EA Network&amp;lt;br&amp;gt;3 Lack of separation between Test Dev and Prod system&amp;lt;br&amp;gt;4 Lack of encryption inside EA Network&amp;lt;br&amp;gt;5 Insecure trusted realations between components&amp;lt;br&amp;gt;6 Insecure configured Internet facing applicatins &amp;lt;br&amp;gt;7 Vulnerable / default configured Routers&amp;lt;br&amp;gt;8 lack of frontend access filtration&amp;lt;br&amp;gt;9 Lack or misconfigured monitoring IDS/IPS&amp;lt;br&amp;gt;10 Insecure/unappropriate wireless comunications&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary Enabled services&amp;lt;br&amp;gt;2 Missing 3rd party software patches&amp;lt;br&amp;gt;3 Insecure trust relations&amp;lt;br&amp;gt;4 Universal OS passwords&amp;lt;br&amp;gt;5 Missing OS patches&amp;lt;br&amp;gt;6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;7 Lack or misconfigured monitoring&amp;lt;br&amp;gt;8 Insecure internal acces control &amp;lt;br&amp;gt;9 Unencrypted remote access &amp;lt;br&amp;gt;10 Lack of password lockout/complexiry checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;2 Lack of DB patch management&amp;lt;br&amp;gt;3 unnecessary Enabled DB features &amp;lt;br&amp;gt;4 lack of password lockout/complexiry checks&amp;lt;br&amp;gt;5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;7 Extensive user and group privileges&amp;lt;br&amp;gt;8 lack or misconfigured audit&amp;lt;br&amp;gt;9 Insecure trust relations&amp;lt;br&amp;gt;10 Open additional interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&amp;lt;br&amp;gt;2 Default Passwords for application access&amp;lt;br&amp;gt;3 SOD conficts&amp;lt;br&amp;gt;4 Unnecessary Enabled Application features &amp;lt;br&amp;gt;5 Open Remote mngmt interfaces&amp;lt;br&amp;gt;6 lack of password lockout/complexity checks&amp;lt;br&amp;gt;7 Insecure options &amp;lt;br&amp;gt;8 Unecrypted cominications&amp;lt;br&amp;gt;9 Insecure trust relations&amp;lt;br&amp;gt;10 Guest access&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable Frontend applications&amp;lt;br&amp;gt;2 Lack of server trust check&amp;lt;br&amp;gt;3 Lack of encryption&amp;lt;br&amp;gt;4 Aotocomplete browser &amp;lt;br&amp;gt;5 Insecure Browser scripting options&amp;lt;br&amp;gt;6 Insecure configuration &amp;lt;br&amp;gt;7 Insecure sortware distribution service&amp;lt;br&amp;gt;8 Lack of AV software&amp;lt;br&amp;gt;9 Password storing in configuration file&amp;lt;br&amp;gt;10 Sensitive information storage&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovskiy &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG)&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Software&amp;diff=141185</id>
		<title>Enterprise Business Application Security Software</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Software&amp;diff=141185"/>
				<updated>2012-12-15T13:01:09Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Software  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
Here will be given information on a tools and services that can be used for assessment of business applications &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this area is to provide free tools that can help companies to assess security of their business applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;[http://online.erpscan.com test SAPGUI Security Online]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com/products/erpscan-pentesting-tool/ SAP Pentesting Tool by ERPScan]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com/products/erpscan-webxml-checker/ ERPScan's web.xml checker]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://www.metasploit.com/modules/auxiliary/scanner/sap Metasploit modules for SAP Pentesting]&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Software&amp;diff=141184</id>
		<title>Enterprise Business Application Security Software</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Software&amp;diff=141184"/>
				<updated>2012-12-15T13:00:03Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Software  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
Here will be given information on a tools and services that can be used for assessment of business applications &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this area is to provide free tools that can help companies to assess security of their business applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;[http://online.erpscan.com test SAPGUI Security Online]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com/products/erpscan-pentesting-tool/ test SAP Pentesting Tool by ERPScan]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com/products/erpscan-webxml-checker/ test SAP web.xml with ERPScan webxml checker]&lt;br /&gt;
&amp;lt;br&amp;gt;[http://www.metasploit.com/modules/auxiliary/scanner/sap Metasploit modules for SAP Pentesting]&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Software&amp;diff=141183</id>
		<title>Enterprise Business Application Security Software</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Security_Software&amp;diff=141183"/>
				<updated>2012-12-15T12:53:29Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: Created page with &amp;quot;==== Software  ====  == Objective  ==  Here will be given information on a tools and services that can be used for assessment of business applications   == Purpose  ==  The pu...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Software  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
Here will be given information on a tools and services that can be used for assessment of business applications &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this area is to provide free tools that can help companies to assess security of their business applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com You can help us to test ERPSCAN Online] &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Alexey Sintsov  &lt;br /&gt;
Dmitriy Evdokimov &lt;br /&gt;
Dmitriy Chastuhin&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics&amp;diff=141182</id>
		<title>Enterprise Business Application Vulnerability Statistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Enterprise_Business_Application_Vulnerability_Statistics&amp;diff=141182"/>
				<updated>2012-12-15T12:51:01Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: Created page with &amp;quot;==== Statistics  ====  == Objective  ==  This document is the first statistics report which will be repeated annually with showing tendencies and changes in Enterprise Busines...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually with showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document we will show a result of statistical research in the Business Application security area made by DSECRG and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical are those and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security as these applications store business data and any vulnerability in these applications will cause a significant monetary loss. Nonetheless people still don’t pay much attention to Enterprise Business Application area as we see during our and our collegues research and audit data. Business applications are very large and complex systems that consists of different components such as Database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security &lt;br /&gt;
&lt;br /&gt;
Every described layer may have their own vulnerabilities that can give attacker full access to business data even if other layers are fully secured. In this document all the popular applications from described levels and their vulnerabilities vill be shown. The purpose of this document to Increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmityy Chastuhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tuyrin, Dmitriy Chastuhin, Dmitriy Evdokimov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141181</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141181"/>
				<updated>2012-12-15T12:48:52Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (ie 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== Project purpose  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications controls money and resources and every security violation can result a significant money loss. Purpose of this project is to aware people about enterprise application security problems and create a guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise applicatio security vulnerabilities by making an Annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop a free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually with showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document we will show a result of statistical research in the Business Application security area made by DSECRG and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical are those and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security as these applications store business data and any vulnerability in these applications will cause a significant monetary loss. Nonetheless people still don’t pay much attention to Enterprise Business Application area as we see during our and our collegues research and audit data. Business applications are very large and complex systems that consists of different components such as Database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security &lt;br /&gt;
&lt;br /&gt;
Every described layer may have their own vulnerabilities that can give attacker full access to business data even if other layers are fully secured. In this document all the popular applications from described levels and their vulnerabilities vill be shown. The purpose of this document to Increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmityy Chastuhin &lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/6/6b/SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf SAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tuyrin, Dmitriy Chastuhin, Dmitriy Evdokimov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Development guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of programm vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Developers of Enterprise business application software. Here we will collect top software vulnerabilities in server site and frontend side that can exist in Business applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used for developing business applications and writing a costom code. Here we will try to categorize it firstly by dividing into Server and Client site. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 XSS&amp;lt;br&amp;gt;2 Improper Access Control &amp;lt;br&amp;gt;3 Information disclosure &amp;lt;br&amp;gt;4 Command/code injection in proprietary language&amp;lt;br&amp;gt;5 SQL Injection &amp;lt;br&amp;gt;6 Missing Encryption of Sensitive Data&amp;lt;br&amp;gt;7 Buffer overflows &amp;lt;br&amp;gt;8 Path traversal&amp;lt;br&amp;gt;9 CSRF &amp;lt;br&amp;gt;10 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX )&amp;lt;br&amp;gt;2 Exposed Dangerous Method or Function (ActiveX)&amp;lt;br&amp;gt;3 Insecure scripting server access &amp;lt;br&amp;gt;4 File handling Frontend vulnerabilities&amp;lt;br&amp;gt;5 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;6 Cleartext Storage of Sensitive Information&amp;lt;br&amp;gt;7 Use of Hard-coded Password&amp;lt;br&amp;gt;8 Lack of integrity checking for front-end application&amp;lt;br&amp;gt;9 Cleartext Transmission of Sensitive Information&amp;lt;br&amp;gt;10 Vulnerable remote services&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
cooming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) Mikhail Markevich Dmitriy Evdokimov (DSecRG) Alexey Sintsov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Implementation guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of Secure implementation of g Enterprise Business Applications and ERP systems. Here we will mainly focus on security architecture and configuration threads because pragramm errors are well described in &amp;quot;Software vulnerabilities&amp;quot; topic &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Administrators of Business Application security and help them to start a beginning self-assessment of their systems and find a most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (Like ERP - is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consists of different components such as database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Every described layer may have their own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are fully secured. &lt;br /&gt;
&lt;br /&gt;
 All information was collected and catecorized during our big practice of security assessing Popular business applications Like in SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security In this document we will Describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&amp;lt;br&amp;gt;2 Lack or vulnerable encryption between corp net and EA Network&amp;lt;br&amp;gt;3 Lack of separation between Test Dev and Prod system&amp;lt;br&amp;gt;4 Lack of encryption inside EA Network&amp;lt;br&amp;gt;5 Insecure trusted realations between components&amp;lt;br&amp;gt;6 Insecure configured Internet facing applicatins &amp;lt;br&amp;gt;7 Vulnerable / default configured Routers&amp;lt;br&amp;gt;8 lack of frontend access filtration&amp;lt;br&amp;gt;9 Lack or misconfigured monitoring IDS/IPS&amp;lt;br&amp;gt;10 Insecure/unappropriate wireless comunications&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary Enabled services&amp;lt;br&amp;gt;2 Missing 3rd party software patches&amp;lt;br&amp;gt;3 Insecure trust relations&amp;lt;br&amp;gt;4 Universal OS passwords&amp;lt;br&amp;gt;5 Missing OS patches&amp;lt;br&amp;gt;6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;7 Lack or misconfigured monitoring&amp;lt;br&amp;gt;8 Insecure internal acces control &amp;lt;br&amp;gt;9 Unencrypted remote access &amp;lt;br&amp;gt;10 Lack of password lockout/complexiry checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;2 Lack of DB patch management&amp;lt;br&amp;gt;3 unnecessary Enabled DB features &amp;lt;br&amp;gt;4 lack of password lockout/complexiry checks&amp;lt;br&amp;gt;5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;7 Extensive user and group privileges&amp;lt;br&amp;gt;8 lack or misconfigured audit&amp;lt;br&amp;gt;9 Insecure trust relations&amp;lt;br&amp;gt;10 Open additional interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&amp;lt;br&amp;gt;2 Default Passwords for application access&amp;lt;br&amp;gt;3 SOD conficts&amp;lt;br&amp;gt;4 Unnecessary Enabled Application features &amp;lt;br&amp;gt;5 Open Remote mngmt interfaces&amp;lt;br&amp;gt;6 lack of password lockout/complexity checks&amp;lt;br&amp;gt;7 Insecure options &amp;lt;br&amp;gt;8 Unecrypted cominications&amp;lt;br&amp;gt;9 Insecure trust relations&amp;lt;br&amp;gt;10 Guest access&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable Frontend applications&amp;lt;br&amp;gt;2 Lack of server trust check&amp;lt;br&amp;gt;3 Lack of encryption&amp;lt;br&amp;gt;4 Aotocomplete browser &amp;lt;br&amp;gt;5 Insecure Browser scripting options&amp;lt;br&amp;gt;6 Insecure configuration &amp;lt;br&amp;gt;7 Insecure sortware distribution service&amp;lt;br&amp;gt;8 Lack of AV software&amp;lt;br&amp;gt;9 Password storing in configuration file&amp;lt;br&amp;gt;10 Sensitive information storage&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovskiy &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG)&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Software  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
Here will be given information on a tools and services that can be used for assessment of business applications &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this area is to provide free tools that can help companies to assess security of their business applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com You can help us to test ERPSCAN Online] &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Alexey Sintsov  &lt;br /&gt;
Dmitriy Evdokimov &lt;br /&gt;
Dmitriy Chastuhin&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf&amp;diff=141180</id>
		<title>File:SAP Security in figures - a global survey 2007-2011. OWASP-EAS.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:SAP_Security_in_figures_-_a_global_survey_2007-2011._OWASP-EAS.pdf&amp;diff=141180"/>
				<updated>2012-12-15T12:46:17Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: The purpose of this report. is to show a high level view of SAP Security in figures so that the problem area is not just theoretically comprehensible but based on actual numbers and metrics – from the information about the number of found issues and the&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The purpose of this report. is to show a high level view of SAP Security in figures so that the problem area is not just theoretically comprehensible but based on actual numbers and metrics – from the information about the number of found issues and their popularity to the number of vulnerable systems, all acquired as a result of a global scan.&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141176</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=141176"/>
				<updated>2012-12-15T11:44:46Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (ie 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== Project purpose  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications controls money and resources and every security violation can result a significant money loss. Purpose of this project is to aware people about enterprise application security problems and create a guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise applicatio security vulnerabilities by making an Annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop a free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually with showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document we will show a result of statistical research in the Business Application security area made by DSECRG and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical are those and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security as these applications store business data and any vulnerability in these applications will cause a significant monetary loss. Nonetheless people still don’t pay much attention to Enterprise Business Application area as we see during our and our collegues research and audit data. Business applications are very large and complex systems that consists of different components such as Database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security &lt;br /&gt;
&lt;br /&gt;
Every described layer may have their own vulnerabilities that can give attacker full access to business data even if other layers are fully secured. In this document all the popular applications from described levels and their vulnerabilities vill be shown. The purpose of this document to Increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
Surveys:&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmityy Chastuhin &lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com/wp-content/uploads/2012/06/SAP-Security-in-figures-a-global-survey-2007-2011-final.pdfSAP Security In Figures – A Global Survey 2007-2011]&lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov, Alexey Tuyrin, Dmitriy Chastuhin, Dmitriy Evdokimov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Development guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of programm vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Developers of Enterprise business application software. Here we will collect top software vulnerabilities in server site and frontend side that can exist in Business applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used for developing business applications and writing a costom code. Here we will try to categorize it firstly by dividing into Server and Client site. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 XSS&amp;lt;br&amp;gt;2 Improper Access Control &amp;lt;br&amp;gt;3 Information disclosure &amp;lt;br&amp;gt;4 Command/code injection in proprietary language&amp;lt;br&amp;gt;5 SQL Injection &amp;lt;br&amp;gt;6 Missing Encryption of Sensitive Data&amp;lt;br&amp;gt;7 Buffer overflows &amp;lt;br&amp;gt;8 Path traversal&amp;lt;br&amp;gt;9 CSRF &amp;lt;br&amp;gt;10 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX )&amp;lt;br&amp;gt;2 Exposed Dangerous Method or Function (ActiveX)&amp;lt;br&amp;gt;3 Insecure scripting server access &amp;lt;br&amp;gt;4 File handling Frontend vulnerabilities&amp;lt;br&amp;gt;5 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;6 Cleartext Storage of Sensitive Information&amp;lt;br&amp;gt;7 Use of Hard-coded Password&amp;lt;br&amp;gt;8 Lack of integrity checking for front-end application&amp;lt;br&amp;gt;9 Cleartext Transmission of Sensitive Information&amp;lt;br&amp;gt;10 Vulnerable remote services&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
cooming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) Mikhail Markevich Dmitriy Evdokimov (DSecRG) Alexey Sintsov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Implementation guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of Secure implementation of g Enterprise Business Applications and ERP systems. Here we will mainly focus on security architecture and configuration threads because pragramm errors are well described in &amp;quot;Software vulnerabilities&amp;quot; topic &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Administrators of Business Application security and help them to start a beginning self-assessment of their systems and find a most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (Like ERP - is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consists of different components such as database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Every described layer may have their own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are fully secured. &lt;br /&gt;
&lt;br /&gt;
 All information was collected and catecorized during our big practice of security assessing Popular business applications Like in SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security In this document we will Describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&amp;lt;br&amp;gt;2 Lack or vulnerable encryption between corp net and EA Network&amp;lt;br&amp;gt;3 Lack of separation between Test Dev and Prod system&amp;lt;br&amp;gt;4 Lack of encryption inside EA Network&amp;lt;br&amp;gt;5 Insecure trusted realations between components&amp;lt;br&amp;gt;6 Insecure configured Internet facing applicatins &amp;lt;br&amp;gt;7 Vulnerable / default configured Routers&amp;lt;br&amp;gt;8 lack of frontend access filtration&amp;lt;br&amp;gt;9 Lack or misconfigured monitoring IDS/IPS&amp;lt;br&amp;gt;10 Insecure/unappropriate wireless comunications&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary Enabled services&amp;lt;br&amp;gt;2 Missing 3rd party software patches&amp;lt;br&amp;gt;3 Insecure trust relations&amp;lt;br&amp;gt;4 Universal OS passwords&amp;lt;br&amp;gt;5 Missing OS patches&amp;lt;br&amp;gt;6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;7 Lack or misconfigured monitoring&amp;lt;br&amp;gt;8 Insecure internal acces control &amp;lt;br&amp;gt;9 Unencrypted remote access &amp;lt;br&amp;gt;10 Lack of password lockout/complexiry checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;2 Lack of DB patch management&amp;lt;br&amp;gt;3 unnecessary Enabled DB features &amp;lt;br&amp;gt;4 lack of password lockout/complexiry checks&amp;lt;br&amp;gt;5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;7 Extensive user and group privileges&amp;lt;br&amp;gt;8 lack or misconfigured audit&amp;lt;br&amp;gt;9 Insecure trust relations&amp;lt;br&amp;gt;10 Open additional interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&amp;lt;br&amp;gt;2 Default Passwords for application access&amp;lt;br&amp;gt;3 SOD conficts&amp;lt;br&amp;gt;4 Unnecessary Enabled Application features &amp;lt;br&amp;gt;5 Open Remote mngmt interfaces&amp;lt;br&amp;gt;6 lack of password lockout/complexity checks&amp;lt;br&amp;gt;7 Insecure options &amp;lt;br&amp;gt;8 Unecrypted cominications&amp;lt;br&amp;gt;9 Insecure trust relations&amp;lt;br&amp;gt;10 Guest access&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable Frontend applications&amp;lt;br&amp;gt;2 Lack of server trust check&amp;lt;br&amp;gt;3 Lack of encryption&amp;lt;br&amp;gt;4 Aotocomplete browser &amp;lt;br&amp;gt;5 Insecure Browser scripting options&amp;lt;br&amp;gt;6 Insecure configuration &amp;lt;br&amp;gt;7 Insecure sortware distribution service&amp;lt;br&amp;gt;8 Lack of AV software&amp;lt;br&amp;gt;9 Password storing in configuration file&amp;lt;br&amp;gt;10 Sensitive information storage&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovskiy &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG)&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Software  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
Here will be given information on a tools and services that can be used for assessment of business applications &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this area is to provide free tools that can help companies to assess security of their business applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com You can help us to test ERPSCAN Online] &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov&lt;br /&gt;
Alexey Sintsov  &lt;br /&gt;
Dmitriy Evdokimov &lt;br /&gt;
Dmitriy Chastuhin&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project/Roadmp&amp;diff=139103</id>
		<title>OWASP Enterprise Application Security Project/Roadmp</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project/Roadmp&amp;diff=139103"/>
				<updated>2012-11-09T09:18:47Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*'''Primary goals''':&lt;br /&gt;
#Aware people about EA security vulnerabilities by releasing annual (later, quarterly) statistics of enterprise application security vulnerabilities,&lt;br /&gt;
#Help companies to begin EA assessment by creating a guideline for assessing EA security, &lt;br /&gt;
#Create a report of top 10 vulnerabilities or a similar report for EA,&lt;br /&gt;
#Publish a free tools for EA assessment,&lt;br /&gt;
&lt;br /&gt;
*'''Project Roadmap''' (as mentioned above):&lt;br /&gt;
#Create a dashboard with high level overview,&lt;br /&gt;
#Create a dashboard about security assessment,&lt;br /&gt;
#Create links to other guidelines,&lt;br /&gt;
#Publish statistical reports annually,&lt;br /&gt;
#Create OWASP EAS Top 10 vulnerabilities page, &lt;br /&gt;
#Finish our first security assessment tool.&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alexander&amp;diff=139102</id>
		<title>User:Alexander</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alexander&amp;diff=139102"/>
				<updated>2012-11-09T09:02:20Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Alexander Polyakov aka @sh2kerr, CTO at ERPSCAN, head of DSecRG and architect of ERPSCAN Security scanner for SAP. His expertise covers security of enterprise business-critical software like ERP, CRM, SRM, RDBMS, banking and processing software. He is the manager of OWASP-EAS (OWASP subproject), a well-known security expert of the enterprise applications of such vendors as SAP and Oracle, who published a significant number of vulnerabilities found in the applications of these vendors. He is the author of multiple whitepapers devoted to information security research, and the author of the book &amp;quot;Oracle Security Through the Eyes of the Auditor: Attack and Defense&amp;quot; (in Russian). He is also one of the contributors to Oracle with Metasploit project. Alexander spoke at the international conferences like BlackHat, RSA, Defcon, HITB, InfoSecurity. Co-organizer of the ZeroNights conference and the PCI DSS Russia conference, held in Moscow, Russia.&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=91272</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=91272"/>
				<updated>2010-10-12T12:57:35Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (ie 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== Project purpose  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications controls money and resources and every security violation can result a significant money loss. Purpose of this project is to aware people about enterprise application security problems and create a guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise applicatio security vulnerabilities by making an Annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics 2009]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop a free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually with showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document we will show a result of statistical research in the Business Application security area made by DSECRG and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical are those and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security as these applications store business data and any vulnerability in these applications will cause a significant monetary loss. Nonetheless people still don’t pay much attention to Enterprise Business Application area as we see during our and our collegues research and audit data. Business applications are very large and complex systems that consists of different components such as Database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security &lt;br /&gt;
&lt;br /&gt;
Every described layer may have their own vulnerabilities that can give attacker full access to business data even if other layers are fully secured. In this document all the popular applications from described levels and their vulnerabilities vill be shown. The purpose of this document to Increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmityy Chastuhin &lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
Annual report comming soon... &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) Dmitriy Chastuhin (DSecRG) Dmitriy Evdokimov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
Leodid Kats (dsec.ru) Olga Yurova (dsec.ru) &lt;br /&gt;
&lt;br /&gt;
==== Development guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of programm vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Developers of Enterprise business application software. Here we will collect top software vulnerabilities in server site and frontend side that can exist in Business applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used for developing business applications and writing a costom code. Here we will try to categorize it firstly by dividing into Server and Client site. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Dev1.png|484x290px]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities (EASAD) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 XSS&amp;lt;br&amp;gt;2 Improper Access Control &amp;lt;br&amp;gt;3 Information disclosure &amp;lt;br&amp;gt;4 Command/code injection in proprietary language&amp;lt;br&amp;gt;5 SQL Injection &amp;lt;br&amp;gt;6 Missing Encryption of Sensitive Data&amp;lt;br&amp;gt;7 Buffer overflows &amp;lt;br&amp;gt;8 Path traversal&amp;lt;br&amp;gt;9 CSRF &amp;lt;br&amp;gt;10 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities (EASFD) ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX )&amp;lt;br&amp;gt;2 Exposed Dangerous Method or Function (ActiveX)&amp;lt;br&amp;gt;3 Insecure scripting server access &amp;lt;br&amp;gt;4 File handling Frontend vulnerabilities&amp;lt;br&amp;gt;5 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;6 Cleartext Storage of Sensitive Information&amp;lt;br&amp;gt;7 Use of Hard-coded Password&amp;lt;br&amp;gt;8 Lack of integrity checking for front-end application&amp;lt;br&amp;gt;9 Cleartext Transmission of Sensitive Information&amp;lt;br&amp;gt;10 Vulnerable remote services&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
cooming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) Mikhail Markevich Dmitriy Evdokimov (DSecRG) Alexey Sintsov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Implementation guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of Secure implementation of g Enterprise Business Applications and ERP systems. Here we will mainly focus on security architecture and configuration threads because pragramm errors are well described in &amp;quot;Software vulnerabilities&amp;quot; topic &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Administrators of Business Application security and help them to start a beginning self-assessment of their systems and find a most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (Like ERP - is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consists of different components such as database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Every described layer may have their own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are fully secured. &lt;br /&gt;
&lt;br /&gt;
 All information was collected and catecorized during our big practice of security assessing Popular business applications Like in SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security In this document we will Describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:Dev2.png]] &lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of proper network filtration between EA and Corporate network&amp;lt;br&amp;gt;2 Lack or vulnerable encryption between corp net and EA Network&amp;lt;br&amp;gt;3 Lack of separation between Test Dev and Prod system&amp;lt;br&amp;gt;4 Lack of encryption inside EA Network&amp;lt;br&amp;gt;5 Insecure trusted realations between components&amp;lt;br&amp;gt;6 Insecure configured Internet facing applicatins &amp;lt;br&amp;gt;7 Vulnerable / default configured Routers&amp;lt;br&amp;gt;8 lack of frontend access filtration&amp;lt;br&amp;gt;9 Lack or misconfigured monitoring IDS/IPS&amp;lt;br&amp;gt;10 Insecure/unappropriate wireless comunications&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Unnecessary Enabled services&amp;lt;br&amp;gt;2 Missing 3rd party software patches&amp;lt;br&amp;gt;3 Insecure trust relations&amp;lt;br&amp;gt;4 Universal OS passwords&amp;lt;br&amp;gt;5 Missing OS patches&amp;lt;br&amp;gt;6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;7 Lack or misconfigured monitoring&amp;lt;br&amp;gt;8 Insecure internal acces control &amp;lt;br&amp;gt;9 Unencrypted remote access &amp;lt;br&amp;gt;10 Lack of password lockout/complexiry checks&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Default passwords for DB access&amp;lt;br&amp;gt;2 Lack of DB patch management&amp;lt;br&amp;gt;3 unnecessary Enabled DB features &amp;lt;br&amp;gt;4 lack of password lockout/complexiry checks&amp;lt;br&amp;gt;5 Unencrypted sensitive data transport / data&amp;lt;br&amp;gt;6 Lack or misconfigured network acess control&amp;lt;br&amp;gt;7 Extensive user and group privileges&amp;lt;br&amp;gt;8 lack or misconfigured audit&amp;lt;br&amp;gt;9 Insecure trust relations&amp;lt;br&amp;gt;10 Open additional interfaces&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Lack of patch management&amp;lt;br&amp;gt;2 Default Passwords for application access&amp;lt;br&amp;gt;3 SOD conficts&amp;lt;br&amp;gt;4 Unnecessary Enabled Application features &amp;lt;br&amp;gt;5 Open Remote mngmt interfaces&amp;lt;br&amp;gt;6 lack of password lockout/complexity checks&amp;lt;br&amp;gt;7 Insecure options &amp;lt;br&amp;gt;8 Unecrypted cominications&amp;lt;br&amp;gt;9 Insecure trust relations&amp;lt;br&amp;gt;10 Guest access&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
1 Vulnerable Frontend applications&amp;lt;br&amp;gt;2 Lack of server trust check&amp;lt;br&amp;gt;3 Lack of encryption&amp;lt;br&amp;gt;4 Aotocomplete browser &amp;lt;br&amp;gt;5 Insecure Browser scripting options&amp;lt;br&amp;gt;6 Insecure configuration &amp;lt;br&amp;gt;7 Insecure sortware distribution service&amp;lt;br&amp;gt;8 Lack of AV software&amp;lt;br&amp;gt;9 Password storing in configuration file&amp;lt;br&amp;gt;10 Sensitive information storage&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovskiy &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG)&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Software  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
Here will be given information on a tools and services that can be used for assessment of business applications &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this area is to provide free and commercial tools that can help companies to assess security of their business applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Currently we are on the beta testing stage of free online service that cen be used to assess security of SAP Frontend. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com You can help us to test ERPSCAN Online] &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com] - by DSECRG &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
Alexey Sintsov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
Dmitriy Evdokimov (DSecRG) Dmitriy Chastuhin (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=91271</id>
		<title>OWASP Enterprise Application Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Enterprise_Application_Security_Project&amp;diff=91271"/>
				<updated>2010-10-12T12:46:31Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Enterprise Application Security Project (OWASP-EAS) exists to provide guidance to people involved in the procurement, design, implementation or sign-off of large scale (ie 'Enterprise') applications. &lt;br /&gt;
&lt;br /&gt;
== Project purpose  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise applications security is one of the major topics in overall security area because those applications controls money and resources and every security violation can result a significant money loss. Purpose of this project is to aware people about enterprise application security problems and create a guidelines and tools for enterprise application security assessment. &lt;br /&gt;
&lt;br /&gt;
== Our Subprojects  ==&lt;br /&gt;
&lt;br /&gt;
Here are our primary goals: &lt;br /&gt;
&lt;br /&gt;
1 Aware people about enterprise applicatio security vulnerabilities by making an Annual statistics of enterprise business application security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Vulnerability Statistics 2009]] &lt;br /&gt;
&lt;br /&gt;
[[Projects/OWASP Enterprise Application Security Project|Statistics]] &lt;br /&gt;
&lt;br /&gt;
2 Help companies to begin assessment of enterprise applicatios by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Implementation Assessment Guide]] &lt;br /&gt;
&lt;br /&gt;
3 Help software companies to improve security of their solutions by creating a &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Vulnerability Testing Guide v1]] &lt;br /&gt;
&lt;br /&gt;
4 Develop a free tools for Enterprise business applicatioons assessment &lt;br /&gt;
&lt;br /&gt;
Subproject [[Enterprise Business Application Security Software]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Roadmap  ==&lt;br /&gt;
&lt;br /&gt;
Have a look at the [[OWASP Enterprise Application Security Project/Roadmp]] &lt;br /&gt;
&lt;br /&gt;
==== Statistics  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document is the first statistics report which will be repeated annually with showing tendencies and changes in Enterprise Business Application Security area. &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
This document we will show a result of statistical research in the Business Application security area made by DSECRG and OWASP-EAS project. The purpose of this document is to raise awareness about Enterprise Business Application security by showing the current number of vulnerabilities found in those applications, how critical are those and what tendences we see. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Business applications like ERP, CRM, SRM and others are one of the major topics within the field of computer security as these applications store business data and any vulnerability in these applications will cause a significant monetary loss. Nonetheless people still don’t pay much attention to Enterprise Business Application area as we see during our and our collegues research and audit data. Business applications are very large and complex systems that consists of different components such as Database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security &lt;br /&gt;
&lt;br /&gt;
Every described layer may have their own vulnerabilities that can give attacker full access to business data even if other layers are fully secured. In this document all the popular applications from described levels and their vulnerabilities vill be shown. The purpose of this document to Increase awareness of Business Application security. &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com Business applications vulnerability statistics 2009 and future trends] - Presentation by Dmitry Evdokimov and Dmityy Chastuhin &lt;br /&gt;
&lt;br /&gt;
[http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a SAP SDN page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
[http://www.oracle.com/security/critical-patch-update.html Oracle Secalert CPU page with latest vulnerabilities] &lt;br /&gt;
&lt;br /&gt;
Annual report comming soon... &lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) Dmitriy Chastuhin (DSecRG) Dmitriy Evdokimov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
Leodid Kats (dsec.ru) Olga Yurova (dsec.ru) &lt;br /&gt;
&lt;br /&gt;
==== Development guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of programm vulnerabilities that can be found in Enterprise Business applications and ERP systems. &lt;br /&gt;
&lt;br /&gt;
== Purpose ==  &lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Developers of Enterprise business application software. Here we will collect top software vulnerabilities in server site and frontend side that can exist in Business applications. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
There are many different languages and technologies that can be used for developing business applications and writing a costom code. Here we will try to categorize it firstly by dividing into Server and Client site. Top 10 list of vulnerabilities for both areas will be shown. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Crosslinks to CWE SANS OWASP and risks with descriptions will be added soon. &lt;br /&gt;
&lt;br /&gt;
[[Image:Vulns1]][[File:Dev1.png]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Server vulnerabilities  ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;1 XSS&amp;lt;br&amp;gt;2 Improper Access Control &amp;lt;br&amp;gt;3 Information disclosure &amp;lt;br&amp;gt;4 Command/code injection in proprietary language&amp;lt;br&amp;gt;5 SQL Injection &amp;lt;br&amp;gt;6 Missing Encryption of Sensitive Data&amp;lt;br&amp;gt;7 Buffer overflows &amp;lt;br&amp;gt;8 Path traversal&amp;lt;br&amp;gt;9 CSRF &amp;lt;br&amp;gt;10 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend vulnerabilities  ==&lt;br /&gt;
&lt;br /&gt;
1 Buffer overflows (ActiveX )&amp;lt;br&amp;gt;2 Exposed Dangerous Method or Function (ActiveX)&amp;lt;br&amp;gt;3 Insecure scripting server access &amp;lt;br&amp;gt;4 File handling Frontend vulnerabilities&amp;lt;br&amp;gt;5 Use of a Broken or Risky Cryptographic Algorithm&amp;lt;br&amp;gt;6 Cleartext Storage of Sensitive Information&amp;lt;br&amp;gt;7 Use of Hard-coded Password&amp;lt;br&amp;gt;8 Lack of integrity checking for front-end application&amp;lt;br&amp;gt;9 Cleartext Transmission of Sensitive Information&amp;lt;br&amp;gt;10 Vulnerable remote services&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
cooming soon &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) Mikhail Markevich Dmitriy Evdokimov (DSecRG) Alexey Sintsov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Implementation guides  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
This document we will describe different areas of Secure implementation of g Enterprise Business Applications and ERP systems. Here we will mainly focus on security architecture and configuration threads because pragramm errors are well described in &amp;quot;Software vulnerabilities&amp;quot; topic &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this document to Increase awareness for Administrators of Business Application security and help them to start a beginning self-assessment of their systems and find a most critical violations. &lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
Enterprise Business Applications (Like ERP - is any software system that has been designed to support and automate the business process of medium and large business) are very large systems that consists of different components such as database server, Front-end, Web server, Application server and other parts. Also those systems lay on different Hardware and software that can have their own vulnerabilities. Every described layer may have their own vulnerabilities and misconfigurations that can give attacker full access to business data even if other layers are fully secured. &lt;br /&gt;
&lt;br /&gt;
 All information was collected and catecorized during our big practice of security assessing Popular business applications Like in SAP ERP, Oracle E-Business Suite, Oracle Peoplesoft, JD-Edwards and other less known or custom applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Overall security of Enterprise Business Application consists of different layers such as: • Network architecture security • Os security • Database security • Application security • Front-end security In this document we will Describe top 10 violations on every layer of Enterprise Business Application that can be easily assessed and mitigated. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:Vulns1]][[File:Dev2.png]]&lt;br /&gt;
&lt;br /&gt;
== Top 10 Network/Architecture issues  ==&lt;br /&gt;
&lt;br /&gt;
== Top 10 OS issues  ==&lt;br /&gt;
&lt;br /&gt;
== Top 10 Database issues  ==&lt;br /&gt;
&lt;br /&gt;
== Top 10 Application issues  ==&lt;br /&gt;
&lt;br /&gt;
== Top 10 Frontend issues  ==&lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://dsecrg.com ERP Security:Myths Problems Solutions] - by Alexander Polyakov and Ilya Medvedovskiy &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) Mikhail Markevich &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Contributors  ==&lt;br /&gt;
&lt;br /&gt;
==== Software  ====&lt;br /&gt;
&lt;br /&gt;
== Objective  ==&lt;br /&gt;
&lt;br /&gt;
Here will be given information on a tools and services that can be used for assessment of business applications &lt;br /&gt;
&lt;br /&gt;
== Purpose  ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this area is to provide free and commercial tools that can help companies to assess security of their business applications. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Intro  ==&lt;br /&gt;
&lt;br /&gt;
== Main  ==&lt;br /&gt;
&lt;br /&gt;
Currently we are on the beta testing stage of free online service that cen be used to assess security of SAP Frontend. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;[http://erpscan.com You can help us to test ERPSCAN Online] &lt;br /&gt;
&lt;br /&gt;
== Links  ==&lt;br /&gt;
&lt;br /&gt;
[http://erpscan.com] - by DSECRG &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Authors  ==&lt;br /&gt;
&lt;br /&gt;
Alexander Polyakov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
Alexey Sintsov (DSecRG) &lt;br /&gt;
&lt;br /&gt;
Dmitriy Evdokimov (DSecRG) Dmitriy Chastuhin (DSecRG) &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP Enterprise Application Security Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Enterprise Application Security Project]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Dev2.png&amp;diff=91270</id>
		<title>File:Dev2.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Dev2.png&amp;diff=91270"/>
				<updated>2010-10-12T12:44:16Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Dev1.png&amp;diff=91269</id>
		<title>File:Dev1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Dev1.png&amp;diff=91269"/>
				<updated>2010-10-12T12:43:43Z</updated>
		
		<summary type="html">&lt;p&gt;Alexander: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Alexander</name></author>	</entry>

	</feed>