<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Research articles and posts on Martin Gallo</title><link>https://martingallo.ar/posts/</link><description>Recent content in Research articles and posts on Martin Gallo</description><generator>Hugo</generator><language>en-us</language><copyright>CC BY-SA 4.0 - Martin Gallo</copyright><lastBuildDate>Tue, 10 Aug 2021 00:00:00 +0000</lastBuildDate><atom:link href="https://martingallo.ar/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>The Rise of Consent and Other Application-based Phishing Attacks</title><link>https://martingallo.ar/posts/2021-08-10-the-rise-of-consent-and-other-application-based-phishing-attacks/</link><pubDate>Tue, 10 Aug 2021 00:00:00 +0000</pubDate><guid>https://martingallo.ar/posts/2021-08-10-the-rise-of-consent-and-other-application-based-phishing-attacks/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;Cloud-based applications are spreading across the entire Internet ecosystem.&#10;Developers can easily build applications that integrate with users and&#10;organizations by accessing their data directly from cloud platforms. The digital&#10;transformation has even accelerated this process, which in most cases relies on&#10;these processes to enhance and tailor as much as possible the user journey.&lt;/p&gt;&#10;&lt;p&gt;Knowing this scenario, malicious actors started to leverage the fact that users&#10;are bombarded with dozens of applications that connect to their accounts and&#10;identities and entice them into providing access to their valuable data. While&#10;most phishing attacks focus on the users themselves, application-based attacks&#10;use a cloud-enabled application as their main vector to access the victim’s&#10;information.&lt;/p&gt;</description></item><item><title>Protecting Credentials in SAP HANA: The Client Secure User Store</title><link>https://martingallo.ar/posts/2021-04-29-protecting-credentials-in-sap-hana-the-client-secure-user-store/</link><pubDate>Thu, 29 Apr 2021 00:00:00 +0000</pubDate><guid>https://martingallo.ar/posts/2021-04-29-protecting-credentials-in-sap-hana-the-client-secure-user-store/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;One of the (many) challenges of managing large distributed systems is how to&#10;secure usage of credentials and cryptographic material. If you are doing things&#10;right, you are authenticating and securing all network paths and communications&#10;between systems, which requires the use of credentials, keys, tokens,&#10;certificates, and other forms of secrets. Protecting all those secrets is not an&#10;easy task, especially if applications and systems need to use them unattended&#10;and without an administrator’s intervention.&lt;/p&gt;</description></item><item><title>Exploring the SAP HANA SQL Command Network Protocol – Federated Authentication</title><link>https://martingallo.ar/posts/2020-10-21-exploring-sap-hana-sql-command-network-protocol-federated-authentication/</link><pubDate>Wed, 21 Oct 2020 00:00:00 +0000</pubDate><guid>https://martingallo.ar/posts/2020-10-21-exploring-sap-hana-sql-command-network-protocol-federated-authentication/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;As detailed in the previous articles, the HANA SQL Command Network Protocol&#10;supports a variety of authentication mechanisms. In the early posts, we&#10;&lt;a href="https://martingallo.ar/posts/2020-07-20-exploring-sap-hana-sql-command-network-protocol-basics-and-authentication"&gt;listed the supported authentication methods&lt;/a&gt;,&#10;and&#10;&lt;a href="https://martingallo.ar/posts/2020-08-10-exploring-sap-hana-sql-command-network-protocol-password-based-authentication-and-tls"&gt;reviewed with some detail the password-based ones&lt;/a&gt;.&#10;This time, we are going to focus on the mechanisms available to federate the&#10;authentication process, and integrate SAP HANA with external identity providers&#10;through the use of different federation and Single Sign-On (SSO) technologies.&lt;/p&gt;</description></item><item><title>Exploring the SAP HANA SQL Command Network Protocol – Password-based Authentication and TLS</title><link>https://martingallo.ar/posts/2020-08-10-exploring-sap-hana-sql-command-network-protocol-password-based-authentication-and-tls/</link><pubDate>Mon, 10 Aug 2020 00:00:00 +0000</pubDate><guid>https://martingallo.ar/posts/2020-08-10-exploring-sap-hana-sql-command-network-protocol-password-based-authentication-and-tls/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;In this article about SAP security topics, we continue exploring the HANA SQL&#10;Command Network Protocol, now looking into password-based authentication&#10;mechanisms and how to protect traffic with the use of &lt;code&gt;TLS&lt;/code&gt;. The following is&#10;the second installment in our three-part series covering SAP HANA SQL Command&#10;Network Protocol. It is recommended you read the first installment in the series&#10;if you missed it:&#10;&lt;a href="https://martingallo.ar/posts/2020-07-20-exploring-sap-hana-sql-command-network-protocol-basics-and-authentication"&gt;Exploring the SAP HANA SQL Command Network Protocol – Protocol Basics and Authentication&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Exploring the SAP HANA SQL Command Network Protocol – Protocol Basics and Authentication</title><link>https://martingallo.ar/posts/2020-07-20-exploring-sap-hana-sql-command-network-protocol-basics-and-authentication/</link><pubDate>Mon, 20 Jul 2020 00:00:00 +0000</pubDate><guid>https://martingallo.ar/posts/2020-07-20-exploring-sap-hana-sql-command-network-protocol-basics-and-authentication/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;HANA Database is an in-memory database developed and sold by&#10;&lt;a href="https://sap.com/"&gt;SAP&lt;/a&gt;. It has become the enterprise software company’s&#10;flagship product, by sitting at the core of SAP’s data management and advanced&#10;analytics offering. HANA serves also as the foundation of the technological&#10;platform on which its ERP, CRM and SRM run, by having it not only act as the&#10;database layer but additionally as an application server. Web-based business&#10;applications can be developed and run on top of the HANA platform. In this&#10;blogpost I’ll share a little bit about the basics of the network protocol that&#10;the HANA database (some time ago also called HDB from “Hybrid Data Base”) uses&#10;to communicate with clients, and discuss some particular scenarios concerning&#10;password-based authentication. Throughout the rest of the article we will refer&#10;to HANA and HDB as on-premise HANA Platform instances. Most of the content&#10;applies to HANA Cloud Platform and the SAP HANA Service in AWS, GCP and other&#10;cloud providers as well, but there might be small differences.&lt;/p&gt;</description></item><item><title>Why Browser Fingerprinting is Creating Challenges for Identity Security</title><link>https://martingallo.ar/posts/2020-05-12-why-browser-fingerprinting-is-creating-challenges-for-identity-security/</link><pubDate>Tue, 12 May 2020 00:00:00 +0000</pubDate><guid>https://martingallo.ar/posts/2020-05-12-why-browser-fingerprinting-is-creating-challenges-for-identity-security/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;Uniquely identifying the user’s device or browser when accessing an online&#10;resource can be useful in very different contexts, and the impact can be&#10;different according to those contexts. With respect to identity security, the&#10;intelligence can significantly contribute to adaptive authentication journeys&#10;and the evaluation of risks when allowing access to resources. In this article&#10;we introduce the concept of browser fingerprinting and explore some of the&#10;challenges the industry is facing when it comes to utilizing this tool in a&#10;secure and privacy-preserving fashion.&lt;/p&gt;</description></item><item><title>Revisiting the Old and Looking at New Potential SAP Vulnerabilities</title><link>https://martingallo.ar/posts/2020-04-07-revisiting-old-and-looking-new-potential-sap-vulnerabilities/</link><pubDate>Tue, 07 Apr 2020 00:00:00 +0000</pubDate><guid>https://martingallo.ar/posts/2020-04-07-revisiting-old-and-looking-new-potential-sap-vulnerabilities/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;Targeted attacks against system administrators are known to be practices some&#10;bad actors use when attempting to gain access to and compromise high-value&#10;environments. As system administrators use of a wide range of tools to manage&#10;the environments under their reach, an interesting entry point for such targeted&#10;attacks is through those tools and the way they are used. In this blogpost I’ll&#10;share a couple of stories of my past journey researching and understanding&#10;&lt;a href="https://sap.com/"&gt;SAP&lt;/a&gt;’s archive file format, the tools available to operate&#10;them, and some of the findings that were derived from that learning process.&lt;/p&gt;</description></item><item><title>Hijacking 2FA – A look at Mobile Malware Through an Identity Lens</title><link>https://martingallo.ar/posts/2020-03-25-hijacking-2fa-a-look-at-mobile-malware-through-an-identity-lens/</link><pubDate>Wed, 25 Mar 2020 00:00:00 +0000</pubDate><guid>https://martingallo.ar/posts/2020-03-25-hijacking-2fa-a-look-at-mobile-malware-through-an-identity-lens/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;In the last weeks, several&#10;&lt;a href="https://www.zdnet.com/article/android-malware-can-steal-google-authenticator-2fa-codes/"&gt;news outlets&lt;/a&gt;&#10;&lt;a href="https://www.pcmag.com/news/android-malware-can-steal-2fa-codes-from-google-authenticator-app"&gt;reported&lt;/a&gt;&#10;on a new Android malware variant, that added capabilities to steal second-factor&#10;authentication codes using innovative ways. The&#10;&lt;a href="https://www.threatfabric.com/blogs/2020_year_of_the_rat.html"&gt;original report&lt;/a&gt;&#10;from &lt;a href="https://www.threatfabric.com/"&gt;Threat Fabric&lt;/a&gt; includes interesting details&#10;about the overall malware behavior. In this post we’re going to focus on these&#10;new capabilities, review them from an identity perspective, and discuss what&#10;does it mean for identity security in general and for authentication strategies&#10;in particular.&lt;/p&gt;</description></item></channel></rss>