Case Study — AS/400 (IBM i) Core Banking Penetration Testing

Green screen, modern risk. One *ALLOBJ profile = full core read/write without touching the branch.

Client Context

Large private bank — AS/400 (IBM i V7R4) core with 600+ branches, DB2/400, 5250 apps, MQ bridge to payment switch & BI-RTGS. Requirement: pre-migration & OJK audit assurance without downtime.

Challenge

AS/400 is assumed “secure by obscurity” — but legacy *ALLOBJ, *JOBCTL, weak profile mgmt, TN5250 & DB2 ODBC create privilege escalation to core tables. Internal network → core pivot was untested for 5 years.

Scope — Snipeyes Internal Assumed-Breach Pen-Test (CREST)

  • Internal VLAN → AS/400: TN5250/Telnet, FTP, ODBC, MQ, job queue & spool, adopted authority
  • Profile & authority review: *ALLOBJ/*SECADM/*JOBCTL, default QSECOFR, password policy, exit programs
  • DB2/400 & application layer: SQL injection via 5250 wrapper, direct UPDATE to account/ledger via ODBC with over-privileged service account
  • Lateral to payment switch: assumed-breach to SWIFT/MQ gateway via job submitter

Key Findings (redacted)

  • CRITICAL: Service account with *ALLOBJ + unencrypted ODBC creds in .ini → direct UPDATE to ACCTBAL (PoC: +Rp 1 in UAT, rolled back)
  • HIGH: QSECOFR not disabled, 6 profiles with *JOBCTL shared via group — pass-the-job to QSYSOPR
  • HIGH: TN5250 without TLS + no exit program — user enumeration + session hijack on LAN
  • 21 findings: 1 Critical, 4 High, 7 Medium, 9 Low — mapped to ISO 27001 A.8, SOC 2 CC6.1, PCI DSS 4.0 Req 7/8

Outcome

  • *ALLOBJ revoked, service account vaulted + TLS on TN5250 + exit program + job queue ACL — retest closed 100% critical in 48h, no go-live delay
  • Auditor accepted; hardening baseline for IBM i adopted bank-wide (600 branches)
  • Now continuous: quarterly internal retest + SCAP-style IBM i checklist for next OJK cycle

Relevance for you: If you still run AS/400 / IBM i core, we test green-screen to DB2 as attackers see it — internal assumed-breach, retest included.

Request AS/400 Core Proposal → · See Banking Security →