How Secure is your AS400 ?
Here are some points you may wish to consider
Run the AS400 command ANZDFTPWD - this will produce a report of all User Profiles that have the
password set the same as the user Id. This in itself is a major weakness, any un-set passwords must be corrected.
Run the AS400 command WRKTCPSTS OPTION(*CNN) - is your ftp server running - this should be the 1st entry using port 21.
If the ftp server is running any users with restricted access can bypass that by using the ftp server with their User Id and password.
Here is an example
Using "Quote" you can literally enter any AS400 command. What is more worrying is that files or libraries can be deleted without trace.
Without additional security software or some very complicated API programming your only option is to switch off ftp which may not be the solution.
Click here for a free demonstration of Bsafe.
Back to the main page.
|