Tuesday, August 9, 2016

HEAD /irj/portal request

HEAD /irj/portal HTTP/1.0

Saw this in the logs, wondered what it was? It appears it's a common probe that an attacker does if they're trying to discover websites running SAP Java Engine. SAP is an ERP (enterprise resource planning) software. Perhaps they know of a vulnerability or attack on SAP and are trying to discover those sites.

