Metadata-Version: 2.4
Name: honeysap
Version: 0.2.0
Summary: SAP low-interaction honeypot
Home-page: https://owasp.org/www-project-core-business-application-security/
Author: Martin Gallo, OWASP CBAS Project
Author-email: martin.gallo@gmail.com
License: GPL-2.0-or-later
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: Information Technology
Classifier: Intended Audience :: System Administrators
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Programming Language :: Python :: 3.14
Classifier: Topic :: Security
Provides: honeysap
Requires-Python: >=3.10
Description-Content-Type: text/markdown
License-File: COPYING
Requires-Dist: pysap==0.2.1
Requires-Dist: flask>=2.0
Requires-Dist: gevent>=21.1.0
Requires-Dist: SQLAlchemy>=1.4.11
Requires-Dist: PyYAML>=5.4.1
Requires-Dist: colorlog<6
Requires-Dist: jsoncomment>=0.3.3
Requires-Dist: hpfeeds>=3.0.0
Requires-Dist: netaddr
Provides-Extra: tests
Requires-Dist: pytest; extra == "tests"
Provides-Extra: docs
Requires-Dist: Sphinx<8.0,>=7.4.7; extra == "docs"
Requires-Dist: ipykernel; extra == "docs"
Requires-Dist: nbsphinx>=0.9.0; extra == "docs"
Requires-Dist: ipython; extra == "docs"
Requires-Dist: myst-parser; extra == "docs"
Dynamic: author
Dynamic: author-email
Dynamic: classifier
Dynamic: description
Dynamic: description-content-type
Dynamic: home-page
Dynamic: license
Dynamic: license-file
Dynamic: provides
Dynamic: provides-extra
Dynamic: requires-dist
Dynamic: requires-python
Dynamic: summary

HoneySAP: SAP Low-interaction honeypot
======================================

[![Build and test HoneySAP](https://github.com/OWASP/HoneySAP/actions/workflows/build_and_test.yml/badge.svg)](https://github.com/OWASP/HoneySAP/actions/workflows/build_and_test.yml)
[![Read the Docs](https://img.shields.io/readthedocs/HoneySAP?logo=readthedocs)](https://honeysap.readthedocs.io/)
[![Discord](https://img.shields.io/discord/710814201358319676?logo=discord&label=Discord)](https://discord.com/channels/710814201358319676/1155823765561815051)


Version 0.2.0


Overview
--------

HoneySAP is a low-interaction research-focused honeypot specific for SAP
services. It's aimed at learn the techniques and motivations behind attacks
against SAP systems.


Features
--------

- low-interaction honeypot for SAP services
- YAML and JSON-based configuration
- pluggable datastore backend
- modular services system
- modular feeds system
- console logging
- SAP RFC Gateway emulation with full NWRFC SDK handshake support
- RFM and DDIC catalog-driven responses for realistic function module interface replies
- Credential capture (SAP logon user, client, descrambled password, OS user, IP)
- XML parameter extraction and logging for all RFC business function calls
- CVE-2025-42957 (`/SLOAE/DEPLOY`) exploit detection and ABAP code capture


Installation
------------

To install HoneySAP, simply download the sources and run:

    $ python -m pip install .

A more complete guidance on how to install HoneySAP on different environments
is provided in the documentation.


Documentation
-------------

Documentation is available at [Read the Docs](https://honeysap.readthedocs.io/en/latest/).


License
-------

This tool is distributed under the GPLv2 license. Check the [COPYING](COPYING)
file for more details.


Authors
-------

The tool was initially designed and developed by Martin Gallo wile working at
[SecureAuth's Innovation Labs](https://www.secureauth.com/labs/) team, with the
help of many contributors. The code was then contributed by SecureAuth to the
OWASP CBAS Project in October 2022.


Disclaimer
----------

The spirit of this Open Source initiative is to help security researchers,
and the community, speed up research and educational activities related to
the implementation of networking protocols and stacks.

The information in this repository is for research and educational purposes
and not meant to be used in production environments and/or as part
of commercial products.

If you desire to use this code or some part of it for your own uses, we
recommend applying proper security development life cycle and secure coding
practices, as well as generate and track the respective indicators of
compromise according to your needs.


Contact Us
----------

Whether you want to report a bug, send a patch, or give some suggestions
on this package, drop a few lines to
[OWASP CBAS' project leaders](https://owasp.org/www-project-core-business-application-security/#leaders).

For security-related questions check our [security policy](SECURITY.md).
