what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

as400ftp.txt

as400ftp.txt
Posted Apr 17, 2005
Authored by Shalom Carmel

AS/400 servers suffer from a user account disclosure flaw due to a symbolic link vulnerability.

tags | advisory
SHA-256 | 56f7a4240acf2236ffb5d2182829895933929bdd93a94c2baa3c1456bf52cfc0

as400ftp.txt

Change Mirror Download
Disclosure of AS/400 user accounts via the FTP server

Overview
---------
AS/400 servers support FTP in two modes, legacy mode and IFS mode,
and supports switching between both modes by a special FTP command.
When in IFS mode, it is possible to create a special symbolic link
file and retrieve the full list of user accounts.

Details
--------
The iSeries FTP server supports two methods to looks at disk contents.
You can view and manipulate existing libraries and database files
inside the libraries in the traditional legacy mode,
or as part of the Integrated File System (IFS).

The iSeries FTP server can be instructed to change the mode
from legacy to IFS by special FTP commands.

The ADDLNK AS/400 utility creates a symbolic link file in IFS
that may act as a pointer to any AS/400 object, including
the QSYS library.

This utility can be executed from an FTP session by the special
RCMD FTP command.

When an FTP client connects to an AS/400 server, changes the
mode to IFS mode, and lists the contents of a symbolic link
pointing at the QSYS library, he receives the full list of
user accounts, including last log in date, and account authorities.



For full details and sample code please read the PDF file found at
http://www.venera.com/downloads.htm

Shalom Carmel



Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close