NetSPI   »   Presentations

Web Based Penetration Testing

Over the years, mainframe developers have seen fit to make almost everything a web app. From Abend Aid to z/OSMF, there’s no avoiding web apps on your mainframe. Even internally as companies modernize their mainframe, they’re opening up web APIs and web pages for other systems to consume. With the growing presence of web applications on mainframes comes new risks. Unfortunately the threats that exist for these web-based environments may be lurking in the shadows of the unexamined mainframe.

The purpose of this talk is to walk through some examples of vulnerable web applications, exploring well-established approaches to web application penetration testing methodology, covering several of the most frequently seen vulnerabilities, and how these vulnerabilities can potentially lead to a compromise of your z/OS environment. Vulnerabilities covered in this talk will be based on OWASP top 10 vulnerabilities but with a z/OS twist.