Punch Card Hacking – Exploring a Mainframe Attack Vector
ID: e98db267-e772-55fe-ad8e-6822f2cdcd97
STIX ID: report--e98db267-e772-55fe-ad8e-6822f2cdcd97
Feed Name: NVISO Labs
This article introduces entry-level mainframe penetration testing on IBM z/OS, covering core concepts (JCL, JES, z/OS UNIX/USS) and demonstrating how authenticated FTP access can be leveraged to submit jobs via 'site file=jes', check job status, and retrieve spool files for debugging. It outlines useful programs (e.g., IEFBR14, IKJEFT01, BPXBATCH), discusses potential privilege escalation through SURROGAT permissions (submitting jobs as another user), and notes DB2 interaction via 'site file=sql'. The piece emphasizes practical operator-like TTPs enabling execution of TSO/UNIX commands, dataset manipulation, and script execution, serving as a technique guide rather than reporting a specific incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
