2020 Jan 14 9:24 AM
Is there any way by which we can hide or encrypt or scramble ABAP program or function module from client?
Any method, will work for me
2020 Jan 14 11:14 AM
One can only hope that the system in question is patched so that *@# does not work anymore.
Here is why: 2198580 - Code injection vulnerability in ABAP.
As a humble consultant, I would be very much against the idea of using software by vendors who hide their code (yes, I have worked with such add-ons and the support is tedious, not to mention that you cannot easily validate the code quality, the security risk implications, etc.).
Is there any way by which we can hide or encrypt or scramble ABAP program or function module from client?
Any method, will work for me
2020 Jan 14 10:25 AM
Try entering
*@#@@[SAP] on the very first line of your code.
There is no easy way to get the code back, so make sure you make a backup before you do it.
Alternatively, here is a program I found online (I wasn't able to find any other solution. Some are saying that it is no longer possible):
PROGRAM ZHIDE NO STANDARD PAGE HEADING.
************************************************************************
* This program hides any ABAP's source code and protects it with a
* password in this source code. So the first candidate to be hidden
* should be ZHIDE itself.
*
* After hiding, you can still run the abap (the load version is intact)
* but it cannot be displayed, edited, traced, transported or generated.
*
* If the ABAP is not hidden, the program hides it, if it is hidden, it
* unhides it.
*
* To execute this program, change the user name and password in this
* source code first.
************************************************************************
SELECTION-SCREEN BEGIN OF BLOCK BLOCK.
SELECTION-SCREEN BEGIN OF LINE.
SELECTION-SCREEN COMMENT 1(8) PWD.
SELECTION-SCREEN POSITION 35.
PARAMETERS: PASSWORD(8) MODIF ID AAA.
SELECTION-SCREEN END OF LINE.
PARAMETERS: PROGRAM(8).
SELECTION-SCREEN END OF BLOCK BLOCK.
*
AT SELECTION-SCREEN OUTPUT.
LOOP AT SCREEN.
IF SCREEN-GROUP1 = 'AAA'.
SCREEN-INVISIBLE = '1'.
MODIFY SCREEN.
ENDIF.
ENDLOOP.
*
INITIALIZATION.
PWD = 'PASSWORD'.
*
START-OF-SELECTION.
TABLES: TRDIR.
* User name and passsword check
IF SY-UNAME <> 'SAP' OR PASSWORD <> 'PASSWORD'.
WRITE: / 'Wrong password'.
EXIT.
ENDIF.
* SAP owned?
IF NOT PROGRAM CP 'Z*' AND NOT PROGRAM CP 'Y*'.
WRITE: / 'Do not hide original SAP programs!'.
EXIT.
ENDIF.
* Exists?
SELECT SINGLE * FROM TRDIR WHERE NAME = PROGRAM.
IF SY-SUBRC <> 0.
WRITE: / 'Program does not exists!'.
EXIT.
ENDIF.
* Does it have a current generated version?
DATA: F1 TYPE D, F3 TYPE D.
DATA: F2 TYPE T, F4 TYPE T.
EXEC SQL.
SELECT UDAT, UTIME, SDAT, STIME INTO :F1, :F2, :F3, :F4 FROM D010LINF
WHERE PROG = :PROGRAM
ENDEXEC.
IF F1 < F3 OR ( F1 = F3 AND F2 < F4 ).
WRITE: / 'The program has no recent generated version!'.
EXIT.
ENDIF.
* Compose a new program name
DATA: NEW_NAME(8), I TYPE I, J TYPE I.
NEW_NAME = PROGRAM.
DO 8 TIMES.
I = SY-INDEX - 1.
NEW_NAME+I(1) = '_'.
* Search for acceptable program name variations
J = 0.
SELECT * FROM TRDIR WHERE NAME LIKE NEW_NAME.
J = J + 1.
ENDSELECT.
IF J = 1.
EXIT.
ENDIF.
NEW_NAME = PROGRAM.
ENDDO.
* Cannot generate appropriate program name
IF J > 1.
WRITE: / 'Cannot generate appropriate program name'.
EXIT.
ENDIF.
* Check if it is already in d010s (already hidden)
DATA: F5(8).
EXEC SQL.
SELECT PROG INTO :F5 FROM D010S WHERE PROG = :NEW_NAME
ENDEXEC.
IF F5 IS INITIAL.
* There is no such hidden program, hide it
EXEC SQL.
UPDATE D010S SET PROG = :NEW_NAME WHERE PROG = :PROGRAM
ENDEXEC.
ELSE.
* There is already a hidden program there, unhide it
EXEC SQL.
UPDATE D010S SET PROG = :PROGRAM WHERE PROG = :NEW_NAME
ENDEXEC.
ENDIF.
*** end of program
2020 Jan 14 11:38 AM
These suggestions are valid for older version so it won't be valid. It's not useful
2020 Jan 14 11:47 AM
The question didn't specify which platform you're on. I'm supposed to guess?
2020 Jan 14 11:14 AM
One can only hope that the system in question is patched so that *@# does not work anymore.
Here is why: 2198580 - Code injection vulnerability in ABAP.
As a humble consultant, I would be very much against the idea of using software by vendors who hide their code (yes, I have worked with such add-ons and the support is tedious, not to mention that you cannot easily validate the code quality, the security risk implications, etc.).
2020 Jan 14 3:39 PM
2020 Jan 14 3:47 PM
anuragkathal but why do you have to do this in the first place?
2020 Jan 16 9:35 AM
we have developed a product in ABAP due to which we want to hide
2020 Jan 16 1:11 PM
Even if you could hide it, only foolish customers would buy it.
2020 Jan 14 3:45 PM
As this question about ABAP development techniques, and not about the ABAP Application Server platform, I have changed the primary tag accordingly.
2020 Jan 16 9:40 AM
the question has been asked several time, the answer is always: It is not possible anymore.
2020 Jan 16 1:10 PM
Not possible and even when it was it was very much frowned upon - in discussions going back over twenty years.
| User | Count |
|---|---|
| 6 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |