Attacking an ERP with Open Source Software

被引:0
作者
Astudillo, Catalina [1 ]
Carvajal, Fabian [1 ]
Pablo Carvallo, Juan [1 ]
Crespo-Martinez, Esteban [1 ]
Orellana, Marcos [1 ]
Vintimilla, Rosalva [1 ]
机构
[1] Univ Azuay, Cuenca, Ecuador
来源
ENFOQUE UTE | 2018年 / 9卷 / 01期
关键词
Pentesting; IT Security; Hacking; ERP; APEX;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Information security is a growing concern in companies and organizations, being even higher when linked to financial platforms where sensitive information exists. This article explains the techniques used in the pentesting performed on the ERP software developed in APEX 5 by the University of Azuay. To achieve this goal, six stages has been considered for perform a penetration test: I) Conceptualization, where is defined the scope of the tests to be performed. II) Preparation of the laboratory, which identifies some of the tools used to initiate the safety tests. III) Obtaining of information, where the possible objects are recognized and scanned in greater depth to identify intrinsic characteristics for subsequently exploit them. IV) Analysis of the vulnerabilities found in the previous stage. V) Exploitation of vulnerabilities; and VI) Post- exploitation, a stage that contemplates the destruction of evidence of the attack and the conservation of the connection and the accesses obtained to extract information. All these stages were carried out within the facilities of the "Universidad del Azuay", considering the development environment in which this software is currently located.
引用
收藏
页码:138 / 148
页数:11
相关论文
共 50 条
  • [21] MODELING THE ACCOUNTING SYSTEM IN ERP SOFTWARE
    Kuzdowicz, Pawel
    Kuzdowicz, Dorota
    Saniuk, Anna
    CLC 2015: CARPATHIAN LOGISTICS CONGRESS - CONFERENCE PROCEEDINGS, 2016, : 370 - 379
  • [22] SOFTWARE INFRASTRUCTURE FOR EEG/ERP RESEARCH
    Moucek, Roman
    Jaros, Petr
    Jezek, Petr
    Papez, Vaclav
    KEOD 2011: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON KNOWLEDGE ENGINEERING AND ONTOLOGY DEVELOPMENT, 2011, : 478 - 481
  • [23] Understanding the Flexibility of Cloud ERP Software
    Nowak, Dawid
    Kurbel, Karl
    INNOVATIONS IN ENTERPRISE INFORMATION SYSTEMS MANAGEMENT AND ENGINEERING, 2017, 285 : 135 - 146
  • [24] IMPACT OF OPEN SOURCE ODOO ERP TOOL IN HIGHER EDUCATION, CASE GUAYAQUIL SUPERIOR TECHNOLOGICAL INSTITUTE
    Norona Alarcon, Janeth Catalina
    REVISTA CONRADO, 2019, 15 (69): : 65 - 70
  • [25] An Alternative Framework of Open Source Enterprise Resource Planning (ERP) System for Small and Medium Enterprise (SME)
    Baharum, Zirawani
    Ngadiman, Salihin
    Haron, Habibollah
    KMICE 2008 - KNOWLEDGE MANAGEMENT INTERNATIONAL CONFERENCE, 2008 - TRANSFERRING, MANAGING AND MAINTAINING KNOWLEDGE FOR NATION CAPACITY DEVELOPMENT, 2008, : 153 - 157
  • [26] Configurations and implementation of payroll system using open source erp: a case study of Koperasi PT Sri
    Terminanto, A.
    Swantoro, H. A.
    Hidayanto, A. N.
    10TH INTERNATIONAL SEMINAR ON INDUSTRIAL ENGINEERING AND MANAGEMENT: SUSTAINABLE DEVELOPMENT IN INDUSTRY AND MANAGEMENT, 2017, 277
  • [27] Development of the MES software and Integration with an existing ERP Software in Industrial Enterprise
    Beric, Dalibor
    Havzi, Sara
    Lolic, Teodora
    Simeunovic, Nenad
    Stefanovic, Darko
    2020 19TH INTERNATIONAL SYMPOSIUM INFOTEH-JAHORINA (INFOTEH), 2020,
  • [28] Agile Software Engineering Practices in ERP Implementation
    Kraljic, Adnan
    Kraljic, Tarik
    INFORMATION SYSTEMS, EMCIS 2019, 2020, 381 : 279 - 290
  • [29] Software Internationalization and Localization in Web Based ERP
    Hau, Elvis
    Aparicio, Manuela
    SIGDOC'08: PROCEEDINGS OF THE 26TH ACM INTERNATIONAL CONFERENCE ON DESIGN OF COMMUNICATION, 2008, : 175 - 180
  • [30] ERP Software Quality Using Paraconsistent Logic
    Tavaves, Priscila F.
    Abe, Jair M.
    Silva, Genivaldo Carlos
    Pimenta, Avelino P., Jr.
    ADVANCES IN PRODUCTION MANAGEMENT SYSTEMS: INITIATIVES FOR A SUSTAINABLE WORLD, 2016, 488 : 731 - 738