Close

BYOD Lab: Penetration Testing the Mainframe from Outside to In. Part 1 of 4

(TC)

Stream: The Courtyard
Time: 14:15 - 15:00


Presentation

Penetration Testing the Mainframe from Outside to In This four-part, hands-on workshop takes attendees through a realistic attack path, starting outside the organisation and working towards the mainframe’s most sensitive systems. Part 1 introduces penetration testing, network reconnaissance, OSINT, and the tactics, techniques, and procedures used by real attackers. Attendees will use tools such as `dig`, WHOIS, and Nmap to understand what can be discovered before directly interacting with the target. Part 2 scans the mainframe’s “fingers and toes”, probing the services and technologies that connect it to the wider enterprise. This includes APIs, TN3270, FTP, SSH, Tomcat, Db2, and other exposed network services. Part 3 moves into controlled exploitation and privilege escalation. We will examine password attacks, JES job submission, persistent backdoors, SURROGAT abuse, APF-related privilege escalation, RACF database exfiltration and password cracking, and an end-to-end attack path from an exposed API into Db2. Part 4 turns the exercise around. Attendees will examine SMF records, perform basic forensic analysis, and see how intrusion detection, threat intelligence, the master console, GIBSON Sentry, and tools such as IBM Security zSecure can help identify and investigate the activity. Using the free GIBSON Mainframe Simulator, attendees will work with Phosphor, curl, Nmap, TSh0cker, Metasploit, CICSPWN, John the Ripper, and Zniff. They will leave with practical experience of reconnaissance, exploitation, privilege escalation, detection, investigation, and mitigation within a safe and controlled mainframe environment. As mentioned, this is a hands-on workshop. It will require WiFi network access for the workshop and an internet connection (although if an internet connection was not possible I could work round that). Attendees will need a laptop on which they can install a virtual machine such as kali Linux (on Windows this can be WSL, or Virtualbox with a Kali VM - which can run on Windows, Linux or Mac. This penetration testing course is different as it does not start on the mainframe, but outside of it. I have run this course previously for two Universities in Scotland (4 hours).

Attachments

There is currently no attachment for BYOD Lab: Penetration Testing the Mainframe from Outside to In. Part 1 of 4

Speakers


  • Kev Milne at Neuro Training Ltd
  • Threat Intelligence Manager, Cyber Mentor, Penetration Tester, mainframe enthusiast, and author using my 30+ years of experience to pass on my knowledge as best I can! I've worked in financial services for 20 years and consultancy for the other 10, mostly in Offensive Cyber Security and Technical Risk Management. I started working with mainframes just under three years ago and I find them fascinating as well as vital. I'm currently writing on a book for No Starch Press and have ran Mainframe Pen testing courses.


    Email: kev.milne@offensivesec.org

  • Jonathan Prince at NVISO GmbH
  • Jonathan spends his time breaking the systems enterprises trust most but understand least. Specializing in IBM z/OS and IBM i security, he researches privilege escalation, authorization flaws, and attack paths on platforms the industry forgot to threat-model. He runs a home lab with two AS/400s and enterprise gear to test these ideas in practice. His work applies modern offensive security methods to legacy platforms, showing how the path from a compromised account to mainframe domination may be far shorter than most defenders want to believe.


    Email: jonathan.prince@nviso.eu

    Feedback

    Click here to give some Feedback so we can make it even better next year!