Attacking an ERP with Open Source Software

被引:0
作者
Astudillo, Catalina [1 ]
Carvajal, Fabian [1 ]
Pablo Carvallo, Juan [1 ]
Crespo-Martinez, Esteban [1 ]
Orellana, Marcos [1 ]
Vintimilla, Rosalva [1 ]
机构
[1] Univ Azuay, Cuenca, Ecuador
来源
ENFOQUE UTE | 2018年 / 9卷 / 01期
关键词
Pentesting; IT Security; Hacking; ERP; APEX;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Information security is a growing concern in companies and organizations, being even higher when linked to financial platforms where sensitive information exists. This article explains the techniques used in the pentesting performed on the ERP software developed in APEX 5 by the University of Azuay. To achieve this goal, six stages has been considered for perform a penetration test: I) Conceptualization, where is defined the scope of the tests to be performed. II) Preparation of the laboratory, which identifies some of the tools used to initiate the safety tests. III) Obtaining of information, where the possible objects are recognized and scanned in greater depth to identify intrinsic characteristics for subsequently exploit them. IV) Analysis of the vulnerabilities found in the previous stage. V) Exploitation of vulnerabilities; and VI) Post- exploitation, a stage that contemplates the destruction of evidence of the attack and the conservation of the connection and the accesses obtained to extract information. All these stages were carried out within the facilities of the "Universidad del Azuay", considering the development environment in which this software is currently located.
引用
收藏
页码:138 / 148
页数:11
相关论文
共 50 条
[41]   Integrated CAD Software with ERP Interface for Steel Portal Frames [J].
Liu, Shenru ;
Yang, Huizhu ;
Chang, Zhiguo ;
Zhang, Qilin .
MANUFACTURING ENGINEERING AND AUTOMATION I, PTS 1-3, 2011, 139-141 :2136-+
[42]   A Model Approach for the Analysis of Dominant Factors in ERP Software Implementation [J].
Al-Aboud, Fahad N. .
INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2011, 11 (10) :179-182
[43]   USEFULNESS OF SOFTWARE VALUATION METHODS AT INITIAL STAGES OF ERP IMPLEMENTATION [J].
Plecka, Przemyslaw ;
Bzdyra, Krzysztof .
FOUNDATIONS OF MANAGEMENT, 2013, 5 (03) :33-48
[44]   Study on ERP software maintenance (ID: 3-064) [J].
Zhang Dawei ;
Ye Anna ;
Zhang Yuzhu .
PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT, VOLS 1-5: INDUSTRIAL ENGINEERING AND MANAGEMENT INNOVATION IN NEW-ERA, 2006, :1287-1291
[45]   Software as a Service operation model in cloud based ERP systems [J].
Orosz, I. ;
Selmeci, A. ;
Orosz, T. .
2019 IEEE 17TH WORLD SYMPOSIUM ON APPLIED MACHINE INTELLIGENCE AND INFORMATICS (SAMI 2019), 2019, :345-353
[46]   Emotion impairs extrinsic source memory-An ERP study [J].
Mao, Xinrui ;
You, Yuqi ;
Li, Wen ;
Guo, Chunyan .
BIOLOGICAL PSYCHOLOGY, 2015, 110 :182-189
[47]   Technology Acceptance Model of ERP software in Small Business: A Systematic Literature review [J].
Crespo-Martinez, Esteban ;
Astudillo-Rodriguez, Catalina ;
Chica-Contreras, Gabriela ;
Vasquez-Aguilera, Ana .
ENFOQUE UTE, 2023, 14 (01) :46-61
[48]   A Three-Dimensional Approach in Evaluating ERP Software Within the Acquisition Process [J].
Verville, Jacques ;
Bernadas, Christine ;
Halingten, Alannah .
INTERNATIONAL JOURNAL OF ENTERPRISE INFORMATION SYSTEMS, 2005, 1 (03) :1-16
[49]   Global implementation of ERP software - Critical success factors on upgrading technical infrastructure [J].
Ghosh, S ;
Ghosh, S .
IEMC-2003: MANAGING TECHNOLOGICALLY DRIVEN ORGANIZATIONS: THE HUMAN SIDE OF INNOVATION AND CHANGE, PROCEEDINGS, 2003, :320-324
[50]   Data Security Issues in Cloud-Based Software-as-a-Service ERP [J].
Saa, Pablo ;
Moscoso-Zea, Oswaldo ;
Cueva Costales, Andres ;
Lujan-Mora, Sergio .
2017 12TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2017,