Re: z/OS, OS/390 Pen testing tips/ideas/papers?

From: visigoth (visigoth@securitycentric.com)
Date: 01/30/03

  • Next message: Rainer Duffner: "Re: z/OS, OS/390 Pen testing tips/ideas/papers?"
    Date: Wed, 29 Jan 2003 21:08:40 -0600
    From: visigoth <visigoth@securitycentric.com>
    To: Nick Jacobsen <nick@ethicsdesign.com>
    
    
    

    On Tue, Jan 28, 2003 at 05:24:22AM -0800, Nick Jacobsen wrote:
    > Hi all,
    > One of my clients has an IBM OS/390 running on one of their networks I
    > am doing some security testing on, and considering I really have not dealt
    > with any IBM mainframes before when it comes to security, I was hoping that
    > some of you might be able to point me the right direction. Anything would
    > be helpful, but especially from a penetration viewpoint.

    I haven't particularly touched any OS/390 boxen, but in testing other "big
    iron" systems like OS/400 we often find that the most common security
    vulnerability is STILL default passwords and accounts. I have assessed
    banks who still have default accounts in place for accounts ranging from
    user template accounts all the way to the QSECOFR account. If the box
    you're assessing seems to have any standard authentication interfaces
    available, I would start there.... The next issue after that in frequency
    is usually internally developed web based apps with gaping holes.

    Cheers (and good luck ;)

    -visigoth

    -- 
    ______________________________________________________________________________
    	Damieon Stark		| Microsoft: Where do you want to go today?
    e: visigoth@securitycentric.com	| Linux: Where do you want to go tommorow?
    	p: 612.382.6945		| FreeBSD/Sun: Are you guys coming or what?
    	pgp: 0xBE5D0C57		| http://www.sun.com/solaris - To the Nth!
    	pgp.mit.edu		| http://www.freebsd.org - The power to serve!
    ------------------------------------------------------------------------------
    I'll see your DMCA and raise you a First Amendment.
    http://www.anti-dmca.org
    ------------------------------------------------------------------------------
    eot
    
    




    Relevant Pages

    • IBM AIX 4.3.x and 5.1: Buffer overflow vulnerability in telnet daemon
      ... Subject: IBM AIX 4.3.x and 5.1: Buffer overflow vulnerability in telnet daemon ... IBM Global Services ... IBM Managed Security Services with access to the security advisories ...
      (Bugtraq)
    • IBM AIX: Buffer Overflow Vulnerability in libi18n Library
      ... IBM Global Services ... IBM Managed Security Services with access to the security advisories ... IBM MSS is forwarding the following information from IBM. ...
      (Bugtraq)
    • [NEWS] Cisco Voice Products Vulnerabilities on IBM Servers
      ... Get your security news from a reliable source. ... The default installation of Cisco voice products on the IBM platform will ... * All operating system versions running on an IBM server prior to OS ...
      (Securiteam)
    • IBM AIX: Buffer Overflow Vulnerabilities in lpd
      ... IBM Global Services ... IBM Managed Security Services with access to the security advisories ... The Line Printer daemon, lpd, shipped with AIX contains several ...
      (Bugtraq)
    • Re: Integrated security - why not?
      ... Let me explain why we seldom use Integrated Security for Internet asp.net ... how could we setup accounts for them? ... !server to the public network with services such as SQL Server (remember SQL ... The DC at the ISP is not for our own use. ...
      (microsoft.public.dotnet.framework.aspnet.security)

  • Quantcast