logo

Punch Card Hacking – Exploring a Mainframe Attack Vector

ID: e98db267-e772-55fe-ad8e-6822f2cdcd97

STIX ID: report--e98db267-e772-55fe-ad8e-6822f2cdcd97

Feed Name: NVISO Labs

Date Published: 2024-07-16

Date Updated: 2026-04-28

Author: Jonathan Prince

...
...

This article introduces entry-level mainframe penetration testing on IBM z/OS, covering core concepts (JCL, JES, z/OS UNIX/USS) and demonstrating how authenticated FTP access can be leveraged to submit jobs via 'site file=jes', check job status, and retrieve spool files for debugging. It outlines useful programs (e.g., IEFBR14, IKJEFT01, BPXBATCH), discusses potential privilege escalation through SURROGAT permissions (submitting jobs as another user), and notes DB2 interaction via 'site file=sql'. The piece emphasizes practical operator-like TTPs enabling execution of TSO/UNIX commands, dataset manipulation, and script execution, serving as a technique guide rather than reporting a specific incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.