๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
SAP

[๊ธฐํƒ€] SAP GUI์™€ Application Server๊ฐ„ ํ†ต์‹  - DIAG ํ”„๋กœํ† ์ฝœ

by applemango2021 2021. 8. 5.

๊ธฐ์ดˆ ๋„คํŠธ์›Œํฌ ๊ณต๋ถ€๋ฅผ ํ•˜๋‹ค๊ฐ€ ์ •์ž‘ ์—…๋ฌด์—์„œ ์‚ฌ์šฉํ•˜๋Š” SAP์—์„œ์˜ ๋„คํŠธ์›Œํฌ ํ†ต์‹  ๋ฐฉ๋ฒ•์— ๋Œ€ํ•ด์„œ๋Š” ์ž˜ ๋ชจ๋ฅด๊ณ  ์žˆ๋‹ค๋Š” ์ƒ๊ฐ์ด ๋“ค์—ˆ๋‹ค. ๋ง‰์—ฐํžˆ 'TCP/IP ํ”„๋กœํ† ์ฝœ ์‚ฌ์šฉํ•˜๊ฒ ์ง€~' ์ƒ๊ฐ์€ ํ–ˆ๋Š”๋ฐ, ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋‹จ์—์„œ์˜ ํ”„๋กœํ† ์ฝœ์€ ์–ด๋–ค ๊ฑธ ์“ฐ๊ณ  ์žˆ๋Š”์ง€ ๋ชฐ๋ผ์„œ ์ด๋ฒˆ ๊ธฐํšŒ์— ์ฐพ์•„๋ดค๋‹ค. 

 

์ผ๋ฐ˜ ์‚ฌ์šฉ์ž๋“ค์€ ๋Œ€๊ฐœ SAP GUI๋ฅผ ํ†ตํ•ด์„œ SAP Application Server์— ์ ‘์†ํ•˜๋Š”๋ฐ, GUI์™€ Application Server ๊ฐ„์˜ ํ†ต์‹ ์€ DIAG(Dynamic Information and Action Gateway) Protocol๋กœ ์ด๋ฃจ์–ด์ง„๋‹ค. DIAG ํ”„๋กœํ† ์ฝœ์— ๋Œ€ํ•ด ์ฒ˜์Œ ๋“ค์–ด๋ณธ๋‹ค ํ•ด๋„ ๋†€๋ž์ง€ ์•Š์€ ๊ฒŒ, SAP์—์„œ ๋งŒ๋“  ํ”„๋กœํ† ์ฝœ์ด๋ฉฐ ์ƒ์„ธ ๊ทœ์•ฝ๋„ ๊ณต๊ฐœ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. SAP ๋ฌธ์„œ์—๋„ ํ”„๋กœํ† ์ฝœ์€ SAP-specificํ•˜๋‹ค๊ณ  ์ ํ˜€ ์žˆ๋‹ค. 

The communication protocols that enable the communication between the SAP GUI and the AS ABAP are SAP-specific.

 

HTTP ํ”„๋กœํ† ์ฝœ๊ณผ ๋น„๊ตํ•˜๋ฉด '๊ณต๊ฐœ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค'๋Š” ๋ง์˜ ์˜๋ฏธ๋ฅผ ์ดํ•ดํ•˜๊ธฐ ์‰ฌ์šธ ๊ฒƒ ๊ฐ™๋‹ค. HTTP ํ”„๋กœํ† ์ฝœ์˜ ๊ฒฝ์šฐ์—๋Š”, ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜๋“ค์ด ํ•ด๋‹น ๊ทœ์•ฝ์„ ๋”ฐ๋ฅด๋ฉด์„œ ๊ฐœ๋ฐœ๋˜์–ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ƒ์„ธํ•œ ๋‚ด์šฉ์ด ์•„์˜ˆ ๊ณต๊ฐœ ๋˜์–ด์žˆ๋‹ค.  ๊ทธ๋ž˜์„œ ์›น์„ ๊ณต๋ถ€ํ•œ ์‚ฌ๋žŒ๋“ค์€ HTTP ๋ฉ”์†Œ๋“œ์— GET, POST ๋“ฑ์ด ์žˆ๊ณ  Header์—๋Š” accept, content-type๊ณผ ๊ฐ™์€ ํ•ญ๋ชฉ์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๋‚ด์šฉ์„ ์•Œ๊ณ  ์žˆ๋‹ค.

ํ•˜์ง€๋งŒ DIAG ํ”„๋กœํ† ์ฝœ์€ GUI์™€ Application Server ๊ฐ„์˜ ํ†ต์‹ ์„ ๋‹ด๋‹นํ•˜๊ธฐ ์œ„ํ•ด SAP์—์„œ ๋งŒ๋“  ํ”„๋กœํ† ์ฝœ์ด๊ธฐ์— ๋Œ€์ค‘์—๊ฒŒ ๊ทธ ๋‚ด์šฉ์ด ๊ณต๊ฐœ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. ์–ด๋–ค ์‹์œผ๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ์š”์ฒญํ•˜๋Š”์ง€, ์‘๋‹ต์œผ๋กœ๋Š” ์–ด๋–ค ๋‚ด์šฉ์„ ์ „๋‹ฌํ•˜๋Š”์ง€(ex. HTTP์—์„œ๋Š” 200, 404 ๋“ฑ์˜ ์ฝ”๋“œ๋ฅผ ๋ฐ˜ํ™˜ํ•œ๋‹ค) ์šฐ๋ฆฌ๋Š” ์•Œ์ง€ ๋ชปํ•œ๋‹ค. 

 

๋ฌผ๋ก  ๋‚ด๊ฐ€ ์ฐพ์ง€ ๋ชปํ•œ ๊ฒƒ์ผ ์ˆ˜๋„ ์žˆ๋Š”๋ฐ, ์ถœ์ฒ˜์— ์ ํžŒ ๊ธ€๋“ค์˜ ๋‰˜์•™์Šค๋ฅผ ๋ณด๋‹ˆ SAP ์ธก์—์„œ ๊ณต์‹์ ์œผ๋กœ ๊ณต๊ฐœํ•œ ์ ์ด ์—†๋Š” ๊ฒƒ ๊ฐ™๋‹ค.  ๊ฐœ๋ฐœ์ž๋“ค์„ ํฌํ•จํ•œ SAP ํ”„๋กœ๊ทธ๋žจ์˜ ์‚ฌ์šฉ์ž๋“ค์€ ๊ตณ์ด ์•Œ ํ•„์š”๊ฐ€ ์—†๋Š” ๋‚ด์šฉ์ด๊ธฐ๋„ ํ•˜๊ณ , ๊ณต๊ฐœํ–ˆ๋‹ค๊ฐ€๋Š” ์˜คํžˆ๋ ค ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ๋“œ๋Ÿฌ๋‚  ์ˆ˜๋„ ์žˆ๋‹ค. ๊ทธ๋ ‡๋‹ค๊ณ  ํ•ด์„œ DIAG์— ๋Œ€ํ•œ ์ •๋ณด๊ฐ€ ์ „ํ˜€ ์—†๋Š” ๊ฒƒ์€ ์•„๋‹ˆ๋‹ค. ํŠนํžˆ ์ด ์Šฌ๋ผ์ด๋“œ๋ฅผ ๋ณด๋ฉด ํ—ค๋”๋Š” ์–ด๋–ค ์‹์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ๊ณ , ํŽ˜์ด๋กœ๋“œ์—๋Š” ์–ด๋–ค ๋‚ด์šฉ๋“ค์ด ๋‹ด๊ฒจ์žˆ๋Š”์ง€ ๋Œ€๋žต์ ์œผ๋กœ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์ฐธ๊ณ ๋กœ ์œ„ ๋งํฌ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์•„๋ž˜์˜ ์ถœ์ฒ˜๋“ค์€ SAP์—์„œ ์ž‘์„ฑํ•œ ๊ฒƒ์ด ์•„๋‹ˆ๋ผ ๋Œ€๋ถ€๋ถ„ ๋ณด์•ˆ์—…์ฒด๋“ค์—์„œ ๋ฆฌ๋ฒ„์Šค ์—”์ง€๋‹ˆ์–ด๋ง์„ ํ†ตํ•ด ํŒŒ์•…ํ•œ ๋‚ด์šฉ์„ ์ •๋ฆฌํ•œ ๊ธ€๋“ค์ด๋‹ค. 

 

๊ธ€์„ ์ฝ์œผ๋ฉด์„œ ํ•œ ๊ฐ€์ง€ ํฅ๋ฏธ๋กœ์› ๋˜ ์ ์€ SAP๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ํšŒ์‚ฌ์—์„œ DIAG ํ”„๋กœํ† ์ฝœ์˜ ๋ณด์•ˆ์— ๋Œ€ํ•ด์„œ๋Š” ํฌ๊ฒŒ ์‹ ๊ฒฝ์“ฐ์ง€ ์•Š๋Š”๋‹ค๋Š” ๊ฒƒ ๊ฐ™๋‹ค๊ณ  ์ง€์ ํ•œ ๋‚ด์šฉ์ด์—ˆ๋‹ค. DIAG ํ”„๋กœํ† ์ฝœ์„ ํ†ตํ•ด ๋ฐ์ดํ„ฐ๋ฅผ ์ฃผ๊ณ  ๋ฐ›์„ ๋•Œ์—๋Š” SAP๊ฐ€ ์†Œ์œ ํ•œ(์ถœ์ฒ˜์—๋Š” proprietary๋ผ๊ณ  ์ ํ˜€์žˆ๋‹ค) ์ฆ‰, SAP๋งŒ์ด ์•Œ๊ณ  ์žˆ๋Š” ์•Œ๊ณ ๋ฆฌ์ฆ˜์— ์˜ํ•ด ์••์ถ•๋œ๋‹ค. ์ด ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ์™ธ๋ถ€์—์„œ๋Š” ์•Œ์ง€ ๋ชปํ•˜๊ธฐ ๋•Œ๋ฌธ์—, ์ด ์ ์„ ๋ฏฟ๊ณ  ์ถ”๊ฐ€์ ์ธ ๋ณด์•ˆ์„ ์„ค์ •ํ•˜์ง€ ์•Š๋Š” ๊ฒƒ ๊ฐ™๋‹ค๊ณ  ๋ถ„์„ํ–ˆ๋‹ค.

 

ํ•˜์ง€๋งŒ ์„ธ ๋ฒˆ์งธ ์ถœ์ฒ˜ ๊ธ€์— ๋”ฐ๋ฅด๋ฉด ์••์ถ•๋œ ๋ฐ์ดํ„ฐ ํ•ด์ œ์— ์„ฑ๊ณตํ•œ ํšŒ์‚ฌ๊ฐ€ ์žˆ๋‹ค๊ณ  ํ•œ๋‹ค. ๋˜ํ•œ, SAP์—์„œ๋Š” SNC(Secure Network Communication) ๋ผ๋Š” ์ผ์ข…์˜ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ œ๊ณตํ•˜์—ฌ ์จ๋“œํŒŒํ‹ฐ ๋ณด์•ˆ ์†”๋ฃจ์…˜์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด๋†“์€ ๊ฒƒ์„ ๋ณด๋ฉด ์••์ถ• ์•Œ๊ณ ๋ฆฌ์ฆ˜๋งŒ ๋ฏฟ์–ด์„œ๋Š” ์•ˆ ๋  ๊ฒƒ ๊ฐ™๋‹ค. ๋ถ„๋ช… ๋ณด์•ˆ์ด ์ƒ๋ช…์ธ ํšŒ์‚ฌ๋“ค์ด ๋งŽ๊ธฐ ๋•Œ๋ฌธ์— ๊ฐ ํ”„๋กœ์ ํŠธ ํ˜น์€ ์šด์˜ ํ™˜๊ฒฝ์—์„œ ์„ ํƒํ•œ ๋ฐฉ์‹์ด ์žˆ์„ ํ…๋ฐ ์ง€๊ธˆ๊นŒ์ง€ ์ด๋Ÿฐ ๋‚ด์šฉ์„ ๋ชฐ๋ผ ํ™•์ธํ•ด๋ณด์ง€ ๋ชปํ•œ ๊ฒŒ ์•„์‰ฝ๋‹ค. 


์ถœ์ฒ˜

- 1) https://yurichev.com/non-wiki-files/blog/SAP/sniffing_diag.pdf

- 2) https://archive.sap.com/kmuuid2/c0fd5c2a-0759-2d10-9385-eef89c57945b/SAP%20GUI%20Technical%20Infrastructure.pdf

- 3) https://layersevensecurity.com/exploring-the-sap-diag-protocol/

- 4) https://www.coresecurity.com/sites/default/files/private-files/publications/2016/05/corelabs-Slides-reversing-breaking-diag-protocol.pdf 

'SAP' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[HANA] HANA DB ์‚ฌ์šฉ ์‹œ ์ฃผ์˜์  : SORT BY  (2) 2021.08.30