logo

Approach to mainframe penetration testing on z/OS. Deep dive into RACF

ID: 0b2c27b8-5a3c-5675-88ec-5519d695db89

STIX ID: report--0b2c27b8-5a3c-5675-88ec-5519d695db89

Feed Name: Securelist by Kaspersky

Threat Score
60/100

Date Published: 2025-07-08

Date Updated: 2026-04-29

Author: Denis Stepanov, Alexander Korotin

...
...

This article analyzes IBM RACF internals and database structure, introduces racfudit — a cross-version offline RACF DB analysis tool — and demonstrates how extracted profile relationships and password material (DES and KDFAES-based) can be used to identify misconfigurations and privilege escalation paths on z/OS mainframes. The authors describe extracting password and passphrase values, mapping explicit and implicit profile relationships (e.g., group-SPECIAL, group-OPERATIONS), SQL queries for finding risky settings (UACC, owners), and outline how these findings can lead to full system compromise, while recommending mitigations such as KDFAES adoption, UACC control, and regular relationship audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.