<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Break Security in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750216#M902250</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jürgen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still don't see how you can debug around the authorisation check on object S_TCODE.  Further to my earlier test where I used a system where I had limited access, I repeated it on a system where I have full access, with the following results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enter /h&lt;/P&gt;&lt;P&gt;Run transaction sm12&lt;/P&gt;&lt;P&gt;In debug set a break-point on statement AUTHORITY-CHECK and execute&lt;/P&gt;&lt;P&gt;The dubugger does not stop, the transaction starts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The auth object S_TCODE is checked for the start of every transaction.  But, even with full authorisation the ABAP debugger will not stop on the S_TCODE check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Apr 2008 13:57:18 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-04-22T13:57:18Z</dc:date>
    <item>
      <title>Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750210#M902244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guys, last nigth I was thinking, if a user is not allow to execute for example transaction  sm50 and he execute /h before of perform sm50 , he can change the values of variables in debugging process ? and worst access to transaction ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 09:15:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750210#M902244</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-22T09:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750211#M902245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its a very good question....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But SAP is much more aware of it. It can be controlled by authorization. In our production system we cannot change the values in debug mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __default_attr="red" __jive_macro_name="color"&gt;&lt;STRONG&gt;&amp;lt;REMOVED BY MODERATOR&amp;gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Alvaro Tejada Galindo on Apr 22, 2008 12:33 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 09:27:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750211#M902245</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-22T09:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750212#M902246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be possible if he bypass all the authority check statement.&lt;/P&gt;&lt;P&gt;But to do this he must have of course debug right and also be able to change values in debug mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I have answered your qestion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 09:30:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750212#M902246</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-22T09:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750213#M902247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I sounds a nice theory, but have you tried it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have developer only access in a dev system, no basis transactions.  So if I run SM12 I get message "You are not authorized to use transaction SM12".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I type /h, then run transaction SM12 I get "You are not authorized to use transaction SM12", no debugger.  The check for S_TCODE is not explicity coded, I think the check is at system level, so it can't be bypassed in debug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 09:38:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750213#M902247</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-22T09:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750214#M902248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All depends the level of authorizations you have &lt;/P&gt;&lt;P&gt;Also don't forget all transactions are linked to an ABAP program and a ABAP source code can be debugged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 11:48:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750214#M902248</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-22T11:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750215#M902249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our security is set in Production that we are not allowed to alter values in DEBUG mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 11:53:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750215#M902249</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-22T11:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750216#M902250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jürgen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still don't see how you can debug around the authorisation check on object S_TCODE.  Further to my earlier test where I used a system where I had limited access, I repeated it on a system where I have full access, with the following results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enter /h&lt;/P&gt;&lt;P&gt;Run transaction sm12&lt;/P&gt;&lt;P&gt;In debug set a break-point on statement AUTHORITY-CHECK and execute&lt;/P&gt;&lt;P&gt;The dubugger does not stop, the transaction starts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The auth object S_TCODE is checked for the start of every transaction.  But, even with full authorisation the ABAP debugger will not stop on the S_TCODE check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 13:57:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750216#M902250</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-22T13:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750217#M902251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;System debugging has to be switched on, then one can actually see the S_TCODE authority check done in function AUTH_CHECK_TCODE. (I'm on 6.20, might be different in subsequent releases).&lt;/P&gt;&lt;P&gt;So it's always recommended to not allow anybody the changing of field values in debugging, at least in productive systems.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 14:36:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750217#M902251</guid>
      <dc:creator>ThomasZloch</dc:creator>
      <dc:date>2008-04-22T14:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Break Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750218#M902252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;System dubugging!  That was it, I knew there was something else that needed to be set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 15:10:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/break-security/m-p/3750218#M902252</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-04-22T15:10:33Z</dc:date>
    </item>
  </channel>
</rss>

