Attacking an ERP with Open Source Software

被引:0
作者
Astudillo, Catalina [1 ]
Carvajal, Fabian [1 ]
Pablo Carvallo, Juan [1 ]
Crespo-Martinez, Esteban [1 ]
Orellana, Marcos [1 ]
Vintimilla, Rosalva [1 ]
机构
[1] Univ Azuay, Cuenca, Ecuador
来源
ENFOQUE UTE | 2018年 / 9卷 / 01期
关键词
Pentesting; IT Security; Hacking; ERP; APEX;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Information security is a growing concern in companies and organizations, being even higher when linked to financial platforms where sensitive information exists. This article explains the techniques used in the pentesting performed on the ERP software developed in APEX 5 by the University of Azuay. To achieve this goal, six stages has been considered for perform a penetration test: I) Conceptualization, where is defined the scope of the tests to be performed. II) Preparation of the laboratory, which identifies some of the tools used to initiate the safety tests. III) Obtaining of information, where the possible objects are recognized and scanned in greater depth to identify intrinsic characteristics for subsequently exploit them. IV) Analysis of the vulnerabilities found in the previous stage. V) Exploitation of vulnerabilities; and VI) Post- exploitation, a stage that contemplates the destruction of evidence of the attack and the conservation of the connection and the accesses obtained to extract information. All these stages were carried out within the facilities of the "Universidad del Azuay", considering the development environment in which this software is currently located.
引用
收藏
页码:138 / 148
页数:11
相关论文
共 50 条
[31]   Analysis of the Software Implementation Process for ERP Systems [J].
Erazo, Jennifer ;
Arboleda, Hugo ;
Pino, Francisco J. .
ADVANCES IN COMPUTING, CCC 2017, 2017, 735 :297-312
[32]   CODE IS SPEECH: Legal Tinkering, Expertise, and Protest among Free and Open Source Software Developers [J].
Coleman, Gabriella .
CULTURAL ANTHROPOLOGY, 2009, 24 (03) :420-454
[33]   Software as a Service in Cloud based ERP change management [J].
Orosz, Istvan ;
Orosz, Tamas .
2017 IEEE 15TH INTERNATIONAL SYMPOSIUM ON INTELLIGENT SYSTEMS AND INFORMATICS (SISY), 2017, :181-186
[34]   An ERP study of multidimensional source retrieval in depression [J].
Barrick, Elyssa M. ;
Dillon, Daniel G. .
BIOLOGICAL PSYCHOLOGY, 2018, 132 :176-191
[35]   Integration of Material Flow Cost Accounting and ERP Software [J].
Sun, Mei ;
Sun, Yongchao ;
Li, Chunxiao .
2014 SCIENCE AND INFORMATION CONFERENCE (SAI), 2014, :87-92
[36]   Business-Aware ERP Cloud Software Evolution [J].
Tang, Longye ;
Xu, Wenjie ;
Wei, Daisen .
PROCEEDINGS OF 2019 IEEE 10TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2019), 2019, :565-570
[37]   COMPUTER INTEGRATED ENTERPRISE IN THE MRP/ERP SOFTWARE IMPLEMENTATION [J].
Kaminski, Andrzej .
FOUNDATIONS OF MANAGEMENT, 2010, 2 (02) :25-36
[38]   A Practical Experience Applying Security Audit Techniques in an Industrial e-Health System Which Uses an Open Source ERP [J].
Gomez, Julian ;
Olivero, Miguel A. ;
Garcia-Garcia, J. A. ;
Escalona, Maria J. .
PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES (WEBIST), 2021, :482-489
[39]   ERP software selection using fuzzy methodology: A case study [J].
Kutlu, B. ;
Akpinar, E. .
Journal of Applied Sciences, 2009, 9 (18) :3378-3384
[40]   Integrated CAD Software with ERP Interface for Steel Portal Frames [J].
Liu, Shenru ;
Yang, Huizhu ;
Chang, Zhiguo ;
Zhang, Qilin .
MANUFACTURING ENGINEERING AND AUTOMATION I, PTS 1-3, 2011, 139-141 :2136-+