Hacking iSeries downloads page
Wikipedia Affiliate Button

Book Excerpts

"Hacking iSeries" book table of contents

General security whitepapers

Cross site scripting made easy with Apache reverse proxy Lotus Notes multiple password disclosures Malicious content in enterprise portals     

iSeries security Whitepapers

Setting up System i as ssh client      new!! SQL injection in terminal emulations Built-in backdoors in AS/400 emulations
IBM resolution for versions 5.2 and up. Fix irrelevant for non-IBM emulations, and previous versions still vulnerable.
AS/400 ldap user accounts disclosure Reverse shell using netcat on AS/400 Disclosure of AS/400 user accounts via the FTP server Enumeration of AS/400 users and their status via POP3
IBM resolution for versions 5.1 and up Previous versions still vulnerable.
Canonicalization and directory traversal in iSeries FTP security products iSeries DB2 stored procedures vulnerability

Publications

An article in Hakin9 Magazine (registration required)

Tools and utilities

REXX ping sweep tool Switching user profile written in REXX      new!!