Case Study — AS/400 (IBM i) Core Banking Penetration Testing
Green screen, modern risk. One
*ALLOBJprofile = full core read/write without touching the branch.
Client Context
Large private bank — AS/400 (IBM i V7R4) core with 600+ branches, DB2/400, 5250 apps, MQ bridge to payment switch & BI-RTGS. Requirement: pre-migration & OJK audit assurance without downtime.
Challenge
AS/400 is assumed “secure by obscurity” — but legacy *ALLOBJ, *JOBCTL, weak profile mgmt, TN5250 & DB2 ODBC create privilege escalation to core tables. Internal network → core pivot was untested for 5 years.
Scope — Snipeyes Internal Assumed-Breach Pen-Test (CREST)
- Internal VLAN → AS/400: TN5250/Telnet, FTP, ODBC, MQ, job queue & spool, adopted authority
- Profile & authority review:
*ALLOBJ/*SECADM/*JOBCTL, default QSECOFR, password policy, exit programs - DB2/400 & application layer: SQL injection via 5250 wrapper, direct
UPDATEto account/ledger via ODBC with over-privileged service account - Lateral to payment switch: assumed-breach to SWIFT/MQ gateway via job submitter
Key Findings (redacted)
- CRITICAL: Service account with
*ALLOBJ+ unencrypted ODBC creds in.ini→ directUPDATEtoACCTBAL(PoC: +Rp 1 in UAT, rolled back) - HIGH: QSECOFR not disabled, 6 profiles with
*JOBCTLshared via group — pass-the-job toQSYSOPR - HIGH: TN5250 without TLS + no exit program — user enumeration + session hijack on LAN
- 21 findings: 1 Critical, 4 High, 7 Medium, 9 Low — mapped to ISO 27001 A.8, SOC 2 CC6.1, PCI DSS 4.0 Req 7/8
Outcome
*ALLOBJrevoked, service account vaulted + TLS on TN5250 + exit program + job queue ACL — retest closed 100% critical in 48h, no go-live delay- Auditor accepted; hardening baseline for IBM i adopted bank-wide (600 branches)
- Now continuous: quarterly internal retest + SCAP-style IBM i checklist for next OJK cycle
Relevance for you: If you still run AS/400 / IBM i core, we test green-screen to DB2 as attackers see it — internal assumed-breach, retest included.