SApCap - SAP packet sniffer and decompressor

SApCap is a proof of concept SAP packet sniffer and decompressor.

SensePost Logo header

SApCap

Find SapCap on GitHub.

author

Ian de Villiers

cost

Free

license, version, release, recent changes

  • License : GPL
  • Version : 0.1
  • Release Date : 2011-09-02

what is SApCap ?

SApCap is a SAP packet sniffer and decompression tool for analysing SAP GUI (DIAG) traffic.

Using a 3rd-party JNI interface for pCap, it is also able to load previously captured tcpdump files.

Details on running SApCap can be found in the README.txt file included in the ZIP file.

who should use it ?

Pen-testers. SAP Researchers

requirements

  • Java runtime environment.
  • Jpcap (http://netresearch.ics.uci.edu/kfujii/Jpcap/doc/index.html)
  • Custom JNI Library.

The custom JNI library is included in the download.

Binary builds of the JNI library are only available for the following platforms:

  • Mac OS/X
  • Windows (32-bit)
  • Linux (32-bit)

If you wish to use a different platform, please download the sources for SAPPRox and SapCompress and build the library yourself.

more details

SApCap is available with source code from the resource links available on the right hand side.

Ian de Villiers' original 44con slide-deck is also available from this link for your reference.

Copyright © SensePost Pty Ltd