TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Mainframes connected to the Internet

118 pointsby dannersalmost 10 years ago

7 comments

mattzitoalmost 10 years ago
Random mainframe anecdote: I remember a client in the early 2000s who had a non-IBM mainframe that when originally implemented and designed predated the wide availability of Ethernet and TCP&#x2F;IP. Everyone knew it was a piece of junk by the time I got involved, but their whole manufacturing system ran on it.<p>In order to bring it up to some semblance of modernity and allow it to print to their shop printers, which were IP-driven, they had to get a third-party to procure and install (or build?) an ethernet interface for the machine, and fired up the TCP&#x2F;IP stack. It kept crashing when they put it on the network, until they finally figured out that the issue was that the TCP&#x2F;IP stack didn&#x27;t understand multicast packets, and so whenever a stray multicast packet hit the interface, the whole thing threw up its hands and gave up.<p>The solution was to keep the mainframe on a private network segment behind a firewall, not for security&#x27;s sake, but because it was the only way to insure no multicast packets would hit it and halt production in three different factories
评论 #10079091 未加载
dannersalmost 10 years ago
Interesting article &#x2F; post about how to scan for mainframes:<p><a href="https:&#x2F;&#x2F;isc.sans.edu&#x2F;forums&#x2F;diary&#x2F;The+80s+called+They+Want+Their+Mainframe+Back&#x2F;14869&#x2F;" rel="nofollow">https:&#x2F;&#x2F;isc.sans.edu&#x2F;forums&#x2F;diary&#x2F;The+80s+called+They+Want+T...</a>
aus_almost 10 years ago
For the security researchers out there, mainframes are really under-researched. There just aren&#x27;t many people that have the expertise in the platform required for security research. And most of the people who do have expertise in the platform are often oblivious to technologies outside of the mainframe. (If you&#x27;ve ever dealt with mainframe people, you might know what I am talking about.) It&#x27;s unfortunate, but too often true. Our best mainframe guy is brilliant. I&#x27;ve never met anyone more technically skilled in his platform. But ask him a basic Windows or a Linux question? Forget it.<p>With today&#x27;s complex stack of multiple platforms in most enterprises, a good security researcher, IMHO, should be fluent with both worlds. Mainframes are where some of our most critical data is stored. When you pull up your account balance through your bank&#x27;s website, there&#x27;s a good chance that value was read off a mainframe.<p>Mainframers are old-school. They don&#x27;t believe in public disclosure or open security models or public audits. If you go through the DEFCON and BlackHat archives, there&#x27;s not much mainframe research out there. There&#x27;s just a small community of mainframers on the Internet, but it&#x27;s a significant part of the world&#x27;s infrastructure. The mainframe world is a crazy alternate reality. (I know, because it&#x27;s my day job.)<p>Phillip Young, the guy who owns this Tumblr project, has made some waves in this community. His talks are a great place to start. Here&#x27;s a few resources to get you started:<p>[0]: <a href="http:&#x2F;&#x2F;mainframed767.tumblr.com&#x2F;" rel="nofollow">http:&#x2F;&#x2F;mainframed767.tumblr.com&#x2F;</a><p>[1]: <a href="http:&#x2F;&#x2F;bigendiansmalls.tumblr.com&#x2F;" rel="nofollow">http:&#x2F;&#x2F;bigendiansmalls.tumblr.com&#x2F;</a><p>[2]: <a href="https:&#x2F;&#x2F;media.blackhat.com&#x2F;us-13&#x2F;US-13-Young-Mainframes-The-Past-Will-Come-Back-to-Haunt-You-Slides.pdf" rel="nofollow">https:&#x2F;&#x2F;media.blackhat.com&#x2F;us-13&#x2F;US-13-Young-Mainframes-The-...</a><p>[3]: <a href="http:&#x2F;&#x2F;www.slideshare.net&#x2F;bigendiansmalls&#x2F;security-necromancy-publish" rel="nofollow">http:&#x2F;&#x2F;www.slideshare.net&#x2F;bigendiansmalls&#x2F;security-necromanc...</a><p>[4]: <a href="https:&#x2F;&#x2F;defcon.org&#x2F;images&#x2F;defcon-22&#x2F;dc-22-presentations&#x2F;Young&#x2F;DEFCON-22-Philip-Young-From-root-to-SPECIAL-Hacking-IBM-Mainframes-Updated.pdf" rel="nofollow">https:&#x2F;&#x2F;defcon.org&#x2F;images&#x2F;defcon-22&#x2F;dc-22-presentations&#x2F;Youn...</a><p>[5]: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=Xfl4spvM5DI" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=Xfl4spvM5DI</a><p>[6]: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=5Ra4Ehmifh4" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=5Ra4Ehmifh4</a><p>Also, IBM.com has a wealth of documentation. (They have terrible SEO though.) Checkout the z&#x2F;OS RedBooks and manauls there.
评论 #10080031 未加载
评论 #10081422 未加载
评论 #10084621 未加载
评论 #10080027 未加载
joeshawalmost 10 years ago
On a related note, there are an alarmingly large number of hosts listening on port 23 (unencrypted telnet) on the internet: <a href="https:&#x2F;&#x2F;www.shodan.io&#x2F;search?query=port%3A23" rel="nofollow">https:&#x2F;&#x2F;www.shodan.io&#x2F;search?query=port%3A23</a><p>Most of them seem to be interfaces to network switches.
hellbanneralmost 10 years ago
How do I connect to one of these on linux or OSX?
评论 #10080445 未加载
评论 #10079777 未加载
ExpiredLinkalmost 10 years ago
BTW, if someone wants to professionally connect Mainframes and Internet: <a href="http:&#x2F;&#x2F;www.softwareag.com&#x2F;corporate&#x2F;products&#x2F;adabas_natural&#x2F;appl_mod&#x2F;products&#x2F;applinx&#x2F;overview&#x2F;default.asp" rel="nofollow">http:&#x2F;&#x2F;www.softwareag.com&#x2F;corporate&#x2F;products&#x2F;adabas_natural&#x2F;...</a>
yarrelalmost 10 years ago
No Gibsons?
评论 #10080513 未加载
评论 #10080890 未加载