Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.folklore.computers > #212172

Re: Early mainframe security

From David Wade <g4ugm@dave.invalid>
Newsgroups alt.folklore.computers
Subject Re: Early mainframe security
Date 2020-06-30 22:39 +0100
Organization A noiseless patient Spider
Message-ID <rdgbdv$cej$1@dont-email.me> (permalink)
References <rddjkg$ffe$1@z-news.wcss.wroc.pl> <rddo9i$ujo$1@dont-email.me> <rde0tn$n2b$1@z-news.wcss.wroc.pl> <1059423417.615215094.695315.peter_flass-yahoo.com@news.eternal-september.org> <rdfgjs$ii5$1@z-news.wcss.wroc.pl>

Show all headers | View raw


On 30/06/2020 15:01, antispam@math.uni.wroc.pl wrote:
> Peter Flass <peter_flass@yahoo.com> wrote:
>> <antispam@math.uni.wroc.pl> wrote:
>>>
>>> That is part I want to understand.  It seems that access macros set
>>> up control blocks in user space.  So user could tamper those control
>>> blocks in arbitrary way.
>>
>> No, the DEBs were in an area with the system key.
>>
>>> It is not entirely clear to me how system
>>> ensured that access method will do its job.
>>
>> As I said, the supervisor ensured that any user I/O operation was limited
>> to one cylinder at a time, verified and enforced by the hardware.
> 
> Yes, thanks.  What you (and David Wade) wrote explains this
> part, without knowing about such limit it looked like a hole...
> 
There were security holes, sometimes installed by the local site. So 
there might be "secret" SVCs that allowed you to issue arbitrary IOs to 
any device or do other privileged actions without checks,

Then I well remember having some what heated arguments because I changed 
the password from the default on the Customer Engineer account.

Sometimes I remember silly things. So I used to work on networking 
software for VM. The machines were connected to the UK university X25 
network so no fire walls, no address blocks. The software ran 
privileged. It did this so if users submitted transfers with invalid 
passwords it could reset the "bad password" count and it didn't killed.

Most sites just installed what I sent, so had I wished I could have 
popped a back door in the software that could have done anything on the 
system from my office.

However when things went wrong, they often refused to let me see the 
main console, in case I did anything I shouldn't.......

Dave

Back to alt.folklore.computers | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Early mainframe security antispam@math.uni.wroc.pl - 2020-06-29 20:40 +0000
  Re: Early mainframe security Peter Flass <peter_flass@yahoo.com> - 2020-06-29 13:49 -0700
  Re: Early mainframe security Dan Espen <dan1espen@gmail.com> - 2020-06-29 16:53 -0400
    Re: Early mainframe security antispam@math.uni.wroc.pl - 2020-06-29 23:59 +0000
      Re: Early mainframe security Peter Flass <peter_flass@yahoo.com> - 2020-06-29 17:24 -0700
        Re: Early mainframe security Thomas Koenig <tkoenig@netcologne.de> - 2020-06-30 07:57 +0000
        Re: Early mainframe security "Kerr-Mudd,John" <notsaying@invalid.org> - 2020-06-30 08:21 +0000
  Re: Early mainframe security Douglas Miller <durgadas311@gmail.com> - 2020-06-29 13:55 -0700
    Re: Early mainframe security J. Clarke <jclarke.873638@gmail.com> - 2020-06-29 17:40 -0400
    Re: Early mainframe security scott@slp53.sl.home (Scott Lurndal) - 2020-06-30 00:08 +0000
      Re: Early mainframe security timcaffrey420@gmail.com - 2020-07-01 07:38 -0700
        Re: Early mainframe security scott@slp53.sl.home (Scott Lurndal) - 2020-07-01 15:14 +0000
          Re: Early mainframe security timcaffrey420@gmail.com - 2020-07-01 13:03 -0700
            Re: Early mainframe security scott@slp53.sl.home (Scott Lurndal) - 2020-07-02 00:52 +0000
              Re: Early mainframe security timcaffrey420@gmail.com - 2020-07-11 18:04 -0700
                Re: Early mainframe security Grant Taylor <gtaylor@tnetconsulting.net> - 2020-07-11 19:10 -0600
                Re: Early mainframe security John Levine <johnl@taugh.com> - 2020-07-12 02:50 +0000
                Re: Early mainframe security timcaffrey420@gmail.com - 2020-07-13 14:26 -0700
  Re: Early mainframe security David Wade <g4ugm@dave.invalid> - 2020-06-29 23:00 +0100
    Re: Early mainframe security antispam@math.uni.wroc.pl - 2020-06-30 00:27 +0000
      Re: Early mainframe security and channel programs John Levine <johnl@taugh.com> - 2020-06-30 02:58 +0000
      Re: Early mainframe security David Wade <g4ugm@dave.invalid> - 2020-06-30 11:34 +0100
      Re: Early mainframe security Peter Flass <peter_flass@yahoo.com> - 2020-06-30 06:15 -0700
        Re: Early mainframe security antispam@math.uni.wroc.pl - 2020-06-30 14:01 +0000
          Re: Early mainframe security David Wade <g4ugm@dave.invalid> - 2020-06-30 22:39 +0100
      Re: Early mainframe security Jon Elson <elson@pico-systems.com> - 2020-06-30 19:37 -0500
  Re: Early mainframe security John Levine <johnl@taugh.com> - 2020-06-29 22:18 +0000
    Re: Early mainframe security Peter Flass <peter_flass@yahoo.com> - 2020-06-29 15:49 -0700
    Re: Early mainframe security Grant Taylor <gtaylor@tnetconsulting.net> - 2020-06-29 18:28 -0600
      Re: Early mainframe security Quadibloc <jsavard@ecn.ab.ca> - 2020-06-29 21:11 -0700
      Re: Early mainframe security David Wade <g4ugm@dave.invalid> - 2020-06-30 11:35 +0100
        Re: Early mainframe security Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2020-06-30 22:18 +0000
          Re: Early mainframe security scott@slp53.sl.home (Scott Lurndal) - 2020-07-01 15:08 +0000
    Re: Early mainframe security Thomas Koenig <tkoenig@netcologne.de> - 2020-06-30 07:51 +0000
      Re: Early mainframe security Bob Eager <news0073@eager.cx> - 2020-06-30 08:49 +0000
  Re: Early mainframe security Ahem A Rivet's Shot <steveo@eircom.net> - 2020-06-30 09:43 +0100
  Re: Early mainframe security Jon Elson <elson@pico-systems.com> - 2020-06-30 19:23 -0500
    Re: Early mainframe security Peter Flass <peter_flass@yahoo.com> - 2020-06-30 18:03 -0700
      Re: Early mainframe security J. Clarke <jclarke.873638@gmail.com> - 2020-06-30 22:32 -0400
        Re: Early mainframe security John Levine <johnl@taugh.com> - 2020-07-01 03:21 +0000
          Re: Early mainframe security J. Clarke <jclarke.873638@gmail.com> - 2020-06-30 23:52 -0400
          Re: Early mainframe security Dan Espen <dan1espen@gmail.com> - 2020-06-30 23:56 -0400
      Re: Early mainframe security Jon Elson <elson@pico-systems.com> - 2020-07-01 22:21 -0500
  Re: Early mainframe security timcaffrey420@gmail.com - 2020-07-01 07:33 -0700
  Re: Early mainframe security Anne & Lynn Wheeler <lynn@garlic.com> - 2020-08-03 12:25 -1000
    Re: Early mainframe security Anne & Lynn Wheeler <lynn@garlic.com> - 2020-08-03 12:58 -1000

csiph-web