Menu

The Cipher Behind QSYRUPWD: Reconstructing IBM i Password Hashes
📰
16

The Cipher Behind QSYRUPWD: Reconstructing IBM i Password Hashes

#cfmir#crciphr#crcipher#cipher#bytes#offset
Reading 0:00
15s threshold

Intro QSYRUPWD (Retrieve Encrypted User Password) is an IBM i API that returns password-related data for a specified user profile in encrypted form to authorized callers. IBM i is IBM’s integrated enterprise platform, originating from the AS/400 line, and is still widely used for business-critical workloads such as ERP, finance, logistics, and manufacturing. The API primarily exists to support system functions such as password synchronization, migration, replication, and other administrative scenarios where password material must be transferred without exposing the cleartext password. IBM documents QSYRUPWD as part of its security-related API set for handling encrypted password data. During one of our IBM i penetration tests, I noticed that the client’s server was configured with QPWDLVL = 2 . On IBM i, the QPWDLVL system value determines both the password rules accepted by the operating system and the verifier formats maintained for authentication compatibility.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More