IBM's System i computers -- formerly known as the AS/400 and iSeries servers -- have long enjoyed a reputation for rock-solid reliability. But poor security practices by those who manage these systems are making them dangerously vulnerable to compromise, according to a recent study.
The report by security firm, The PowerTech Group, is based on the results of 188 system audits at 177 System i sites over the past year. The results show that many owners of System i computers are not putting enough internal controls in place to adequately protect data on the systems, said John Earl, chief technology officer at PowerTech.
For instance, more than 90 percent of the surveyed systems had no controls for preventing or auditing changes to the underlying data via an external PC. In addition, 95 percent of the systems had at least 10 users with complete root-access authority, and 43 percent had as many 30 users with root authority. Also, 77 percent of the systems had more than 20 users with passwords that were the same as their usernames.
The results are not much different from two earlier surveys PowerTech conducted of the System i user base. It shows a continuing lack of attention to security, Earl said.
"The platform has always had a great reputation for security and deservedly so," Earl said. "It has some of the best native security tools bundled into the box. But the community out there for a number of reasons has not stepped up to the plate and done their due diligence [around security]. Too often, projects involving security on the System i are not given the proper priority because the system is assumed to be secure."
The System i is a proprietary midrange IBM server that for several years now has powered critical enterprise resource planning, finance and human resources software at both large and small companies. It was first introduced as the AS/400 in 1988 and was originally based almost entirely on a previous-generation IBM midrange system called the System 38. Since then, the platform has gone through several major changes.
Among the most significant of those changes is the inclusion of support for services such as file transfer protocol (FTP), Open Database Connectivity (ODBC) and Java Database Connectivity (JDBC) that have allowed data on System i computers to be accessible to other computers on enterprise networks.
"In the initial days, the box was very proprietary, and people didn't worry about outsiders getting into the data within these systems," said Robin Tatam, senior System i security engineer at MSI Systems Integrators. "Over the years, customers have screamed for more open access through FTP and ODBC, and IBM has delivered on these."
But that openness, coupled with an absence of proper controls, has also made the System i more vulnerable to compromises, he said.
For example, with previous generation "green-screen" AS/400 systems, it didn't much matter if most users had administrator-level access because they were limited in what they could do, Tatam said.
But that has changed with the support for services such as FTP and ODBC, which allow anyone with a profile on the system to access the database on a System i from a PC, he said. As a result, "it is very, very important that enterprises get a handle on the level of access that people have on these systems," Tatam said.
"Open access rights to the data and convenient tools to access the data from a PC make a troublesome combination," the PowerTech report noted. But few companies have put in place controls for limiting or monitoring this access, it said.
Much of the current attitude towards security on the System I has been shaped by user experiences of the past, said Al Barsa, president of Barsa Consulting Group. "Keep in mind there are a lot of users who came from the S/38, which allowed you to be real sloppy with security," Barsa said. "It was a very simplistic computer to use" from a security standpoint, and early implementations often didn't even require passwords, he added.
"A lot of those practices carried over to the AS/400" and have persisted to this day, Barsa said. "Historically, this platform has been so robust that people have been able to get away with a lot of bad [security] practices."
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Your organisation may well have devised and implemented an Acceptable Use Policy (AUP) some time ago in order to guard against the risks of inappropriate use of computer systems by your workers, but are you confident that your AUP remains 'fit for purpose'? Read on to discover how you can enhance the effectiveness of your AUP.












