Mainframe Security Misconceptions
Summary
Debunk four mainframe security misconceptions and learn why mainframe penetration testing is important.
- Published
- Collected
Related coverage
blog ·
netspi.com
Unix Underworld: Tales from the Dark Side of z/OS
NetSPI's Black Hat and DEF CON research shows z/OS Unix is an overlooked mainframe attack surface, with paths from authenticated user to APF-authorized code execution and UID 0.
blog ·
netspi.com
Mainframe State of the Platform: 2025 Security Assessment
Based on dozens of mainframe assessments, NetSPI's 2025 State of the Platform report covers MFA adoption, DES-to-AES cryptographic modernization, and persistent security gaps in enterprise mainframes.
blog ·
netspi.com
NetSPI Wins First Place at SHARE Mainframe Capture the Flag Event
NetSPI's mainframe pentesting team won first place at SHARE's inaugural Capture the Flag event sponsored by Broadcom, solving z/OS challenges while presenting on blackbox pentesting and OMVS attacks.
blog ·
netspi.com
Hacking CICS: 7 Ways to Defeat Mainframe Applications
Over 90% of mainframes run CICS for transaction management. This article walks through seven practical testing approaches for uncovering common vulnerabilities in mainframe CICS and IMS applications.
blog ·
netspi.com
Mapping Mainframe Memory Made Easy
When pentesters can't run TSO commands like PARMLIB, in-memory control blocks still reveal authorized command tables. A REXX script walks the CVT pointer chain to dump z/OS TSO configuration data.
blog ·
netspi.com
Mission for Mainframe | Part 1: Relevant Today
Mainframes still process up to one trillion web transactions daily, anchoring banking, government, and healthcare. Part one explains why their reliability and availability keep them relevant today.
Skip to content