Skip to content

Repository files navigation

Java Endpoint Analyzer

Introduction and goal

Java Endpoint Analyzer (JEA) helps you assess the scope of an SAP system based on Java in order to understand which HTTP endpoints are exposed. To do so, it automatically analyzes deployment files (like web.xml, webdympro.xml , portalapp.xml) in order to extract out the URLs (endpoints) that the system has. It is meant to be used internally as OS credentials are needed.

It currently works with the following type of applications:

  • Servlets
  • SOAP Applications
  • Portal Apps
  • Webdynpros

How does it works

JEA requires credentials of the target SAP system in order to log in through SSH and download specific files. These files are deployment configuration files that each type of webapp uses. Once they are downloaded locally, the analysis phase of the process begins. Every file is parsed and based on what those files state, the entry points are built.

The output of this tool will be an endpoints.json file holding all found HTTP endpoints of the java system.

Installation

This tool uses Python >= 3.8

Install the necessary dependencies with:

pip install -r requirements.txt

Usage

JEA can be used in two different modes:

  • Extraction + Analysis
  • Analysis Only

The final list of endpoints will be stored in the CWD inside a file named "endpoints.json"

Extraction + Analysis

Under this mode, JEA will connect to the SAP system, download deployment files of the types specified and later extract the endpoints from them.

There are three main arguments to be used in this situation:

  • --extract: Specifies that extraction of files should occur.
  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where all extracted files will be stored.

Due to extraction being activated, information and credentials of the targeted SAP system must be provided. This information is gathered from system_config.py file. You must create this file inside the lib directory, filling the necessary data. A template file called system_config.py.template can be found inside the lib directory. Feel free to make a copy of that file and start completing the necessary data.

SAP's required information for extraction (system_config.py):

  • SAP_HOST: Destination. SAP server's host.
  • SAP_INSTANCE: Instance number of the targeted instance.
  • SAP_SID: SID. SAP's SID.
  • SAP_SSH_PORT: SSH port. Default: 22.
  • SAP_SSH_USER: SSH user.
  • SAP_SSH_PASSWORD: SSH password (if needed). You can avoid using it if your OS user have already configured the SSH connection to that server through certs.

Analysis only

If you already executed the extraction phase and you want to re-analyze the deployment files without extracting again, this mode should be used. Similar to the previous case, the following parameters should be used:

  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where the extracted files were stored. IMPORTANT: Consider that while doing an extraction, JEA automatically creates a directory inside the provided output directory with the name of the host (for organization purposes). In this case, you should provide the full path to that directory (including the host name).

Examples

Extract and analyze SOAP files using SSH Certs for connection.

Retrieve endpoints from SOAP webapps from system saplab.example.com (DEV) instance 00. Having already a trust SSH connection

system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="00"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD=""
python jea.py --extract -t SOAP -d results

Extract and analyze ALL files using SSH password for connection.

Retrieve endpoints from ALL possible webapps from system saplab.example.com (DEV) instance 95 using "devadm:ILoveSAP1234." as credentials. system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="95"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD="ILoveSAP1234."
python jea.py --extract -t ALL -d results

Only analyze WEBDYNPROS files

Retrieve endpoints from WEBDYNPROS webapps. Results of extraction from saplab.example.com were placed under directory "/tmp/jea_extraction".

python jea.py -t WEBDYNPROS -d /tmp/jea_extraction/saplab.example.com

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - Onapsis/java_endpoint_analyzer · GitHub
Skip to content

Repository files navigation

Java Endpoint Analyzer

Introduction and goal

Java Endpoint Analyzer (JEA) helps you assess the scope of an SAP system based on Java in order to understand which HTTP endpoints are exposed. To do so, it automatically analyzes deployment files (like web.xml, webdympro.xml , portalapp.xml) in order to extract out the URLs (endpoints) that the system has. It is meant to be used internally as OS credentials are needed.

It currently works with the following type of applications:

  • Servlets
  • SOAP Applications
  • Portal Apps
  • Webdynpros

How does it works

JEA requires credentials of the target SAP system in order to log in through SSH and download specific files. These files are deployment configuration files that each type of webapp uses. Once they are downloaded locally, the analysis phase of the process begins. Every file is parsed and based on what those files state, the entry points are built.

The output of this tool will be an endpoints.json file holding all found HTTP endpoints of the java system.

Installation

This tool uses Python >= 3.8

Install the necessary dependencies with:

pip install -r requirements.txt

Usage

JEA can be used in two different modes:

  • Extraction + Analysis
  • Analysis Only

The final list of endpoints will be stored in the CWD inside a file named "endpoints.json"

Extraction + Analysis

Under this mode, JEA will connect to the SAP system, download deployment files of the types specified and later extract the endpoints from them.

There are three main arguments to be used in this situation:

  • --extract: Specifies that extraction of files should occur.
  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where all extracted files will be stored.

Due to extraction being activated, information and credentials of the targeted SAP system must be provided. This information is gathered from system_config.py file. You must create this file inside the lib directory, filling the necessary data. A template file called system_config.py.template can be found inside the lib directory. Feel free to make a copy of that file and start completing the necessary data.

SAP's required information for extraction (system_config.py):

  • SAP_HOST: Destination. SAP server's host.
  • SAP_INSTANCE: Instance number of the targeted instance.
  • SAP_SID: SID. SAP's SID.
  • SAP_SSH_PORT: SSH port. Default: 22.
  • SAP_SSH_USER: SSH user.
  • SAP_SSH_PASSWORD: SSH password (if needed). You can avoid using it if your OS user have already configured the SSH connection to that server through certs.

Analysis only

If you already executed the extraction phase and you want to re-analyze the deployment files without extracting again, this mode should be used. Similar to the previous case, the following parameters should be used:

  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where the extracted files were stored. IMPORTANT: Consider that while doing an extraction, JEA automatically creates a directory inside the provided output directory with the name of the host (for organization purposes). In this case, you should provide the full path to that directory (including the host name).

Examples

Extract and analyze SOAP files using SSH Certs for connection.

Retrieve endpoints from SOAP webapps from system saplab.example.com (DEV) instance 00. Having already a trust SSH connection

system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="00"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD=""
python jea.py --extract -t SOAP -d results

Extract and analyze ALL files using SSH password for connection.

Retrieve endpoints from ALL possible webapps from system saplab.example.com (DEV) instance 95 using "devadm:ILoveSAP1234." as credentials. system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="95"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD="ILoveSAP1234."
python jea.py --extract -t ALL -d results

Only analyze WEBDYNPROS files

Retrieve endpoints from WEBDYNPROS webapps. Results of extraction from saplab.example.com were placed under directory "/tmp/jea_extraction".

python jea.py -t WEBDYNPROS -d /tmp/jea_extraction/saplab.example.com

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Onapsis/java_endpoint_analyzer · GitHub
Skip to content

Repository files navigation

Java Endpoint Analyzer

Introduction and goal

Java Endpoint Analyzer (JEA) helps you assess the scope of an SAP system based on Java in order to understand which HTTP endpoints are exposed. To do so, it automatically analyzes deployment files (like web.xml, webdympro.xml , portalapp.xml) in order to extract out the URLs (endpoints) that the system has. It is meant to be used internally as OS credentials are needed.

It currently works with the following type of applications:

  • Servlets
  • SOAP Applications
  • Portal Apps
  • Webdynpros

How does it works

JEA requires credentials of the target SAP system in order to log in through SSH and download specific files. These files are deployment configuration files that each type of webapp uses. Once they are downloaded locally, the analysis phase of the process begins. Every file is parsed and based on what those files state, the entry points are built.

The output of this tool will be an endpoints.json file holding all found HTTP endpoints of the java system.

Installation

This tool uses Python >= 3.8

Install the necessary dependencies with:

pip install -r requirements.txt

Usage

JEA can be used in two different modes:

  • Extraction + Analysis
  • Analysis Only

The final list of endpoints will be stored in the CWD inside a file named "endpoints.json"

Extraction + Analysis

Under this mode, JEA will connect to the SAP system, download deployment files of the types specified and later extract the endpoints from them.

There are three main arguments to be used in this situation:

  • --extract: Specifies that extraction of files should occur.
  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where all extracted files will be stored.

Due to extraction being activated, information and credentials of the targeted SAP system must be provided. This information is gathered from system_config.py file. You must create this file inside the lib directory, filling the necessary data. A template file called system_config.py.template can be found inside the lib directory. Feel free to make a copy of that file and start completing the necessary data.

SAP's required information for extraction (system_config.py):

  • SAP_HOST: Destination. SAP server's host.
  • SAP_INSTANCE: Instance number of the targeted instance.
  • SAP_SID: SID. SAP's SID.
  • SAP_SSH_PORT: SSH port. Default: 22.
  • SAP_SSH_USER: SSH user.
  • SAP_SSH_PASSWORD: SSH password (if needed). You can avoid using it if your OS user have already configured the SSH connection to that server through certs.

Analysis only

If you already executed the extraction phase and you want to re-analyze the deployment files without extracting again, this mode should be used. Similar to the previous case, the following parameters should be used:

  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where the extracted files were stored. IMPORTANT: Consider that while doing an extraction, JEA automatically creates a directory inside the provided output directory with the name of the host (for organization purposes). In this case, you should provide the full path to that directory (including the host name).

Examples

Extract and analyze SOAP files using SSH Certs for connection.

Retrieve endpoints from SOAP webapps from system saplab.example.com (DEV) instance 00. Having already a trust SSH connection

system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="00"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD=""
python jea.py --extract -t SOAP -d results

Extract and analyze ALL files using SSH password for connection.

Retrieve endpoints from ALL possible webapps from system saplab.example.com (DEV) instance 95 using "devadm:ILoveSAP1234." as credentials. system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="95"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD="ILoveSAP1234."
python jea.py --extract -t ALL -d results

Only analyze WEBDYNPROS files

Retrieve endpoints from WEBDYNPROS webapps. Results of extraction from saplab.example.com were placed under directory "/tmp/jea_extraction".

python jea.py -t WEBDYNPROS -d /tmp/jea_extraction/saplab.example.com

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Onapsis/java_endpoint_analyzer · GitHub
Skip to content

Repository files navigation

Java Endpoint Analyzer

Introduction and goal

Java Endpoint Analyzer (JEA) helps you assess the scope of an SAP system based on Java in order to understand which HTTP endpoints are exposed. To do so, it automatically analyzes deployment files (like web.xml, webdympro.xml , portalapp.xml) in order to extract out the URLs (endpoints) that the system has. It is meant to be used internally as OS credentials are needed.

It currently works with the following type of applications:

  • Servlets
  • SOAP Applications
  • Portal Apps
  • Webdynpros

How does it works

JEA requires credentials of the target SAP system in order to log in through SSH and download specific files. These files are deployment configuration files that each type of webapp uses. Once they are downloaded locally, the analysis phase of the process begins. Every file is parsed and based on what those files state, the entry points are built.

The output of this tool will be an endpoints.json file holding all found HTTP endpoints of the java system.

Installation

This tool uses Python >= 3.8

Install the necessary dependencies with:

pip install -r requirements.txt

Usage

JEA can be used in two different modes:

  • Extraction + Analysis
  • Analysis Only

The final list of endpoints will be stored in the CWD inside a file named "endpoints.json"

Extraction + Analysis

Under this mode, JEA will connect to the SAP system, download deployment files of the types specified and later extract the endpoints from them.

There are three main arguments to be used in this situation:

  • --extract: Specifies that extraction of files should occur.
  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where all extracted files will be stored.

Due to extraction being activated, information and credentials of the targeted SAP system must be provided. This information is gathered from system_config.py file. You must create this file inside the lib directory, filling the necessary data. A template file called system_config.py.template can be found inside the lib directory. Feel free to make a copy of that file and start completing the necessary data.

SAP's required information for extraction (system_config.py):

  • SAP_HOST: Destination. SAP server's host.
  • SAP_INSTANCE: Instance number of the targeted instance.
  • SAP_SID: SID. SAP's SID.
  • SAP_SSH_PORT: SSH port. Default: 22.
  • SAP_SSH_USER: SSH user.
  • SAP_SSH_PASSWORD: SSH password (if needed). You can avoid using it if your OS user have already configured the SSH connection to that server through certs.

Analysis only

If you already executed the extraction phase and you want to re-analyze the deployment files without extracting again, this mode should be used. Similar to the previous case, the following parameters should be used:

  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where the extracted files were stored. IMPORTANT: Consider that while doing an extraction, JEA automatically creates a directory inside the provided output directory with the name of the host (for organization purposes). In this case, you should provide the full path to that directory (including the host name).

Examples

Extract and analyze SOAP files using SSH Certs for connection.

Retrieve endpoints from SOAP webapps from system saplab.example.com (DEV) instance 00. Having already a trust SSH connection

system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="00"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD=""
python jea.py --extract -t SOAP -d results

Extract and analyze ALL files using SSH password for connection.

Retrieve endpoints from ALL possible webapps from system saplab.example.com (DEV) instance 95 using "devadm:ILoveSAP1234." as credentials. system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="95"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD="ILoveSAP1234."
python jea.py --extract -t ALL -d results

Only analyze WEBDYNPROS files

Retrieve endpoints from WEBDYNPROS webapps. Results of extraction from saplab.example.com were placed under directory "/tmp/jea_extraction".

python jea.py -t WEBDYNPROS -d /tmp/jea_extraction/saplab.example.com

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - Onapsis/java_endpoint_analyzer · GitHub
Skip to content

Repository files navigation

Java Endpoint Analyzer

Introduction and goal

Java Endpoint Analyzer (JEA) helps you assess the scope of an SAP system based on Java in order to understand which HTTP endpoints are exposed. To do so, it automatically analyzes deployment files (like web.xml, webdympro.xml , portalapp.xml) in order to extract out the URLs (endpoints) that the system has. It is meant to be used internally as OS credentials are needed.

It currently works with the following type of applications:

  • Servlets
  • SOAP Applications
  • Portal Apps
  • Webdynpros

How does it works

JEA requires credentials of the target SAP system in order to log in through SSH and download specific files. These files are deployment configuration files that each type of webapp uses. Once they are downloaded locally, the analysis phase of the process begins. Every file is parsed and based on what those files state, the entry points are built.

The output of this tool will be an endpoints.json file holding all found HTTP endpoints of the java system.

Installation

This tool uses Python >= 3.8

Install the necessary dependencies with:

pip install -r requirements.txt

Usage

JEA can be used in two different modes:

  • Extraction + Analysis
  • Analysis Only

The final list of endpoints will be stored in the CWD inside a file named "endpoints.json"

Extraction + Analysis

Under this mode, JEA will connect to the SAP system, download deployment files of the types specified and later extract the endpoints from them.

There are three main arguments to be used in this situation:

  • --extract: Specifies that extraction of files should occur.
  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where all extracted files will be stored.

Due to extraction being activated, information and credentials of the targeted SAP system must be provided. This information is gathered from system_config.py file. You must create this file inside the lib directory, filling the necessary data. A template file called system_config.py.template can be found inside the lib directory. Feel free to make a copy of that file and start completing the necessary data.

SAP's required information for extraction (system_config.py):

  • SAP_HOST: Destination. SAP server's host.
  • SAP_INSTANCE: Instance number of the targeted instance.
  • SAP_SID: SID. SAP's SID.
  • SAP_SSH_PORT: SSH port. Default: 22.
  • SAP_SSH_USER: SSH user.
  • SAP_SSH_PASSWORD: SSH password (if needed). You can avoid using it if your OS user have already configured the SSH connection to that server through certs.

Analysis only

If you already executed the extraction phase and you want to re-analyze the deployment files without extracting again, this mode should be used. Similar to the previous case, the following parameters should be used:

  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where the extracted files were stored. IMPORTANT: Consider that while doing an extraction, JEA automatically creates a directory inside the provided output directory with the name of the host (for organization purposes). In this case, you should provide the full path to that directory (including the host name).

Examples

Extract and analyze SOAP files using SSH Certs for connection.

Retrieve endpoints from SOAP webapps from system saplab.example.com (DEV) instance 00. Having already a trust SSH connection

system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="00"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD=""
python jea.py --extract -t SOAP -d results

Extract and analyze ALL files using SSH password for connection.

Retrieve endpoints from ALL possible webapps from system saplab.example.com (DEV) instance 95 using "devadm:ILoveSAP1234." as credentials. system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="95"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD="ILoveSAP1234."
python jea.py --extract -t ALL -d results

Only analyze WEBDYNPROS files

Retrieve endpoints from WEBDYNPROS webapps. Results of extraction from saplab.example.com were placed under directory "/tmp/jea_extraction".

python jea.py -t WEBDYNPROS -d /tmp/jea_extraction/saplab.example.com

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Onapsis/java_endpoint_analyzer · GitHub
Skip to content

Repository files navigation

Java Endpoint Analyzer

Introduction and goal

Java Endpoint Analyzer (JEA) helps you assess the scope of an SAP system based on Java in order to understand which HTTP endpoints are exposed. To do so, it automatically analyzes deployment files (like web.xml, webdympro.xml , portalapp.xml) in order to extract out the URLs (endpoints) that the system has. It is meant to be used internally as OS credentials are needed.

It currently works with the following type of applications:

  • Servlets
  • SOAP Applications
  • Portal Apps
  • Webdynpros

How does it works

JEA requires credentials of the target SAP system in order to log in through SSH and download specific files. These files are deployment configuration files that each type of webapp uses. Once they are downloaded locally, the analysis phase of the process begins. Every file is parsed and based on what those files state, the entry points are built.

The output of this tool will be an endpoints.json file holding all found HTTP endpoints of the java system.

Installation

This tool uses Python >= 3.8

Install the necessary dependencies with:

pip install -r requirements.txt

Usage

JEA can be used in two different modes:

  • Extraction + Analysis
  • Analysis Only

The final list of endpoints will be stored in the CWD inside a file named "endpoints.json"

Extraction + Analysis

Under this mode, JEA will connect to the SAP system, download deployment files of the types specified and later extract the endpoints from them.

There are three main arguments to be used in this situation:

  • --extract: Specifies that extraction of files should occur.
  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where all extracted files will be stored.

Due to extraction being activated, information and credentials of the targeted SAP system must be provided. This information is gathered from system_config.py file. You must create this file inside the lib directory, filling the necessary data. A template file called system_config.py.template can be found inside the lib directory. Feel free to make a copy of that file and start completing the necessary data.

SAP's required information for extraction (system_config.py):

  • SAP_HOST: Destination. SAP server's host.
  • SAP_INSTANCE: Instance number of the targeted instance.
  • SAP_SID: SID. SAP's SID.
  • SAP_SSH_PORT: SSH port. Default: 22.
  • SAP_SSH_USER: SSH user.
  • SAP_SSH_PASSWORD: SSH password (if needed). You can avoid using it if your OS user have already configured the SSH connection to that server through certs.

Analysis only

If you already executed the extraction phase and you want to re-analyze the deployment files without extracting again, this mode should be used. Similar to the previous case, the following parameters should be used:

  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where the extracted files were stored. IMPORTANT: Consider that while doing an extraction, JEA automatically creates a directory inside the provided output directory with the name of the host (for organization purposes). In this case, you should provide the full path to that directory (including the host name).

Examples

Extract and analyze SOAP files using SSH Certs for connection.

Retrieve endpoints from SOAP webapps from system saplab.example.com (DEV) instance 00. Having already a trust SSH connection

system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="00"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD=""
python jea.py --extract -t SOAP -d results

Extract and analyze ALL files using SSH password for connection.

Retrieve endpoints from ALL possible webapps from system saplab.example.com (DEV) instance 95 using "devadm:ILoveSAP1234." as credentials. system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="95"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD="ILoveSAP1234."
python jea.py --extract -t ALL -d results

Only analyze WEBDYNPROS files

Retrieve endpoints from WEBDYNPROS webapps. Results of extraction from saplab.example.com were placed under directory "/tmp/jea_extraction".

python jea.py -t WEBDYNPROS -d /tmp/jea_extraction/saplab.example.com

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Onapsis/java_endpoint_analyzer · GitHub
Skip to content

Repository files navigation

Java Endpoint Analyzer

Introduction and goal

Java Endpoint Analyzer (JEA) helps you assess the scope of an SAP system based on Java in order to understand which HTTP endpoints are exposed. To do so, it automatically analyzes deployment files (like web.xml, webdympro.xml , portalapp.xml) in order to extract out the URLs (endpoints) that the system has. It is meant to be used internally as OS credentials are needed.

It currently works with the following type of applications:

  • Servlets
  • SOAP Applications
  • Portal Apps
  • Webdynpros

How does it works

JEA requires credentials of the target SAP system in order to log in through SSH and download specific files. These files are deployment configuration files that each type of webapp uses. Once they are downloaded locally, the analysis phase of the process begins. Every file is parsed and based on what those files state, the entry points are built.

The output of this tool will be an endpoints.json file holding all found HTTP endpoints of the java system.

Installation

This tool uses Python >= 3.8

Install the necessary dependencies with:

pip install -r requirements.txt

Usage

JEA can be used in two different modes:

  • Extraction + Analysis
  • Analysis Only

The final list of endpoints will be stored in the CWD inside a file named "endpoints.json"

Extraction + Analysis

Under this mode, JEA will connect to the SAP system, download deployment files of the types specified and later extract the endpoints from them.

There are three main arguments to be used in this situation:

  • --extract: Specifies that extraction of files should occur.
  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where all extracted files will be stored.

Due to extraction being activated, information and credentials of the targeted SAP system must be provided. This information is gathered from system_config.py file. You must create this file inside the lib directory, filling the necessary data. A template file called system_config.py.template can be found inside the lib directory. Feel free to make a copy of that file and start completing the necessary data.

SAP's required information for extraction (system_config.py):

  • SAP_HOST: Destination. SAP server's host.
  • SAP_INSTANCE: Instance number of the targeted instance.
  • SAP_SID: SID. SAP's SID.
  • SAP_SSH_PORT: SSH port. Default: 22.
  • SAP_SSH_USER: SSH user.
  • SAP_SSH_PASSWORD: SSH password (if needed). You can avoid using it if your OS user have already configured the SSH connection to that server through certs.

Analysis only

If you already executed the extraction phase and you want to re-analyze the deployment files without extracting again, this mode should be used. Similar to the previous case, the following parameters should be used:

  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where the extracted files were stored. IMPORTANT: Consider that while doing an extraction, JEA automatically creates a directory inside the provided output directory with the name of the host (for organization purposes). In this case, you should provide the full path to that directory (including the host name).

Examples

Extract and analyze SOAP files using SSH Certs for connection.

Retrieve endpoints from SOAP webapps from system saplab.example.com (DEV) instance 00. Having already a trust SSH connection

system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="00"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD=""
python jea.py --extract -t SOAP -d results

Extract and analyze ALL files using SSH password for connection.

Retrieve endpoints from ALL possible webapps from system saplab.example.com (DEV) instance 95 using "devadm:ILoveSAP1234." as credentials. system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="95"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD="ILoveSAP1234."
python jea.py --extract -t ALL -d results

Only analyze WEBDYNPROS files

Retrieve endpoints from WEBDYNPROS webapps. Results of extraction from saplab.example.com were placed under directory "/tmp/jea_extraction".

python jea.py -t WEBDYNPROS -d /tmp/jea_extraction/saplab.example.com

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - Onapsis/java_endpoint_analyzer · GitHub
Skip to content

Repository files navigation

Java Endpoint Analyzer

Introduction and goal

Java Endpoint Analyzer (JEA) helps you assess the scope of an SAP system based on Java in order to understand which HTTP endpoints are exposed. To do so, it automatically analyzes deployment files (like web.xml, webdympro.xml , portalapp.xml) in order to extract out the URLs (endpoints) that the system has. It is meant to be used internally as OS credentials are needed.

It currently works with the following type of applications:

  • Servlets
  • SOAP Applications
  • Portal Apps
  • Webdynpros

How does it works

JEA requires credentials of the target SAP system in order to log in through SSH and download specific files. These files are deployment configuration files that each type of webapp uses. Once they are downloaded locally, the analysis phase of the process begins. Every file is parsed and based on what those files state, the entry points are built.

The output of this tool will be an endpoints.json file holding all found HTTP endpoints of the java system.

Installation

This tool uses Python >= 3.8

Install the necessary dependencies with:

pip install -r requirements.txt

Usage

JEA can be used in two different modes:

  • Extraction + Analysis
  • Analysis Only

The final list of endpoints will be stored in the CWD inside a file named "endpoints.json"

Extraction + Analysis

Under this mode, JEA will connect to the SAP system, download deployment files of the types specified and later extract the endpoints from them.

There are three main arguments to be used in this situation:

  • --extract: Specifies that extraction of files should occur.
  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where all extracted files will be stored.

Due to extraction being activated, information and credentials of the targeted SAP system must be provided. This information is gathered from system_config.py file. You must create this file inside the lib directory, filling the necessary data. A template file called system_config.py.template can be found inside the lib directory. Feel free to make a copy of that file and start completing the necessary data.

SAP's required information for extraction (system_config.py):

  • SAP_HOST: Destination. SAP server's host.
  • SAP_INSTANCE: Instance number of the targeted instance.
  • SAP_SID: SID. SAP's SID.
  • SAP_SSH_PORT: SSH port. Default: 22.
  • SAP_SSH_USER: SSH user.
  • SAP_SSH_PASSWORD: SSH password (if needed). You can avoid using it if your OS user have already configured the SSH connection to that server through certs.

Analysis only

If you already executed the extraction phase and you want to re-analyze the deployment files without extracting again, this mode should be used. Similar to the previous case, the following parameters should be used:

  • -t: Specifies which type of webapps are going to be downloaded/analyzed
  • -d: Specifies the path to the directory where the extracted files were stored. IMPORTANT: Consider that while doing an extraction, JEA automatically creates a directory inside the provided output directory with the name of the host (for organization purposes). In this case, you should provide the full path to that directory (including the host name).

Examples

Extract and analyze SOAP files using SSH Certs for connection.

Retrieve endpoints from SOAP webapps from system saplab.example.com (DEV) instance 00. Having already a trust SSH connection

system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="00"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD=""
python jea.py --extract -t SOAP -d results

Extract and analyze ALL files using SSH password for connection.

Retrieve endpoints from ALL possible webapps from system saplab.example.com (DEV) instance 95 using "devadm:ILoveSAP1234." as credentials. system_config.py

SAP_HOST="saplab.example.com"SAP_INSTANCE="95"SAP_SID="DEV"SAP_SSH_PORT=22SAP_SSH_USER="devadm"SAP_SSH_PASSWORD="ILoveSAP1234."
python jea.py --extract -t ALL -d results

Only analyze WEBDYNPROS files

Retrieve endpoints from WEBDYNPROS webapps. Results of extraction from saplab.example.com were placed under directory "/tmp/jea_extraction".

python jea.py -t WEBDYNPROS -d /tmp/jea_extraction/saplab.example.com

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages