Library QUSER38

CL programs of type CLP38 pose another potential security exposure.

All unqualified commands contained in a CLP38 program will first search the library QUSER38 for that command and then secondly QSYS38 library before the QSYS library is searched. .

IBOD


QUSER38:

IBOD (an Individual Bent On Destruction) could place a command into either of these libraries with the command processing program (CCP) performing a completely different function than the function suggested by the command name. But IBOD could also execute the intended function by qualifying the intended command (for example QSYS/DSPMSG) after he has executed his own nefarious function and thereby disguising his dastardly deed.

There are two simple remedies to protect against intrusion through this back-door.

Firstly, since QUSER38 is not shipped with the iSeries, create it and apply *PUBLIC authority *USE (not *CHANGE) to it. Similarly, change the *PUBLIC authority to QSYS38 library to *USE.

The second remedy is not to allow programs of type CLP38 onto your production system.

Home | Software Solutions | iSeries Security | Tips & Techniques | Consulting | About us | Contact Us



Sentinex Inc.

Telephone: (800) 822 1004
E-Mail: info@sentinex.com
Mail: Sentinex Inc. 379 Hamilton Drive
Stewartsville, NJ, 08886