Explore the hidden world of mainframe security in this Black Hat USA 2013 conference talk. Delve into the often-overlooked realm of mainframe systems that power critical infrastructure across governments, military, airlines, and banks. Uncover the security implications of these powerful machines, addressing the knowledge gap between IT security professionals and mainframe experts. Learn about mainframe security implementation, including configuration file locations, access methods, networking commands, and file structures. Gain insights into TSO, JCL, REXX, and other mainframe-specific technologies. Discover how to navigate the mainframe environment, understand resource access control, and explore potential vulnerabilities. Examine topics such as password hashes, FTP servers, and low-level capabilities. Investigate tools and techniques for mainframe security testing, including Nessus and Metasploit. Consider the implications of running Linux on mainframes and methods for searching sensitive data. Bridge the gap between modern IT security practices and the enduring world of mainframe computing in this comprehensive exploration of a often-misunderstood technology landscape.
Read more