
DEF CON 33 - SSH-nanigans - Busting Open the Mainframes Iron Fortress through Unix - Philip Young
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 46:24
Phil Young (Soldier of Fortran) presents on mainframe security vulnerabilities and penetration testing techniques 0:14. Mainframes are still critical infrastructure used by banks, airlines, and other enterprises despite being considered outdated technology 5:13.
Key Takeaways:
• Mainframes use External Security Managers (RACF, Top Secret, ACF2) that control access permissions, with "special" and "operations" attributes providing complete system control 7:00
• Z/OS Unix provides a familiar Linux-like environment for attackers, making it an entry point for mainframe compromise 10:05
• Attackers can escalate privileges by obtaining APF authorization, which allows programs to run in supervisor state with elevated privileges 24:47
• Common vulnerabilities include improper file permissions, weak password storage, and insufficient monitoring of security-sensitive commands 39:01
The presentation demonstrates how attackers can exploit mainframe vulnerabilities through practical examples and provides defensive recommendations 38:44.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right. You may have heard of mainframe pen testing and exploitation mainly from our next speaker. I defcon, please give a welcome to the soldier of fortree. Wow, that was awesome. The other room cheered for me. That was great. Um, morning everybody. I really appreciate youall coming to a Sunday morning talk at Defcon. Uh, front row, I'm going to need your help. I can't see anybody else. And if my hand starts to drop and you can't hear me anymore, can you guys just be like, "Hey, >> we got you." >> Thank you. Thank you. Thank you so much. All right. So, for those who don't know, um, my name is Phil Young. I'm the director of We're just waiting for them to calm down. I don't know what's going on over there. Um, so I'm the director of mainframe pen testing at Net Spy. You might also know …