Mainframe Cybersecurity & Compliance

 View Only
Expand all | Collapse all

ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a way

  • 1.  ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a way

    Posted Dec 03, 2014 01:36 PM

    ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a way to reduce the information returned from an invalid signon?


    #ACF2


  • 2.  Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Posted Dec 03, 2014 04:37 PM

    FYI this is an issue in Top Secret as well, and it is not just CICS. These different error messages come up in other Multi-User Address spaces as well.

     

    I too would like to see this changed, but I am not sure if this is CA's todo or IBM, as it might be an inherent problem with SAF Signon processing.

     



    #ACF2


  • 3.  Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Posted Dec 04, 2014 01:08 PM

    CICS returns this message at the bottom of the CESN screen for either invalid userid or password and thus does it correctly:

    DFHCE3530 Your userid or password is invalid. Please retype both.

     

    So I think it's CA's responsibility to match that behavior.


    #ACF2


  • 4.  Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Posted Dec 04, 2014 03:50 PM

    Also consider message "ACF01013 LOGONID <logonid> SUSPENDED BECAUSE OF PASSWORD VIOLATIONS".

     

    From looking in CAI.CAX1MAC1(ACFAEUSC), I think CAI makes it very clear that the presentation of the messages from ACF2 is a customer responsibility. So change ACFAEUSC to produce a message that does not give away the knowledge of whether the user entered an invalid logonid or an invalid password (implying a valid logonid). Out of the box, ACFAEUSC helps the user figure out what prevented the signon.


    #ACF2


  • 5.  Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Posted Dec 04, 2014 03:58 PM

    Thanks Bruce, I'll run this past our CICS folks and have them review it.


    #ACF2


  • 6.  Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Posted Dec 08, 2014 10:29 AM

    It appears that there has already been an enhancement opened for this.

     

    ACF Username enumeration messages

     

    I'm not sure it does any good, but I'd recommend voting for this enhamcement.


    #ACF2


  • 7.  Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Posted Dec 08, 2014 11:50 AM

    It has my vote, as we'll try multiple avenues to address the auditing request.


    #ACF2


  • 8.  RE: Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Posted 14 days ago

    Was this ever implemented?  Where is the doc?




  • 9.  RE: Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Broadcom Employee
    Posted 11 days ago
    Hi Barry,
    See MSGOPTS GSO record in the ACF2 Techdocs Administration

    *Jerry Alan Scott*
    Client Services Consultant | Mainframe Division

    Broadcom Software

    mobile: 636 697-5412
    jerry.scott2@broadcom.com <first.last@broadcom.com> | broadcom.com

    --
    This electronic communication and the information and any files transmitted
    with it, or attached to it, are confidential and are intended solely for
    the use of the individual or entity to whom it is addressed and may contain
    information that is confidential, legally privileged, protected by privacy
    laws, or otherwise restricted from disclosure to anyone else. If you are
    not the intended recipient or the person responsible for delivering the
    e-mail to the intended recipient, you are hereby notified that any use,
    copying, distributing, dissemination, forwarding, printing, or copying of
    this e-mail is strictly prohibited. If you received this e-mail in error,
    please return the e-mail to the sender, delete it from your computer, and
    destroy any printed copy of it.




  • 10.  RE: Re: ACF2 (and similarly in RACF) CICS signon with an invalid user returns a different message than with a valid user (ACF01004 LOGONID lid NOT FOUND or ACF01012 PASSWORD NOT MATCHED) , which could validate for an attacker that the ID is valid. Is there a

    Broadcom Employee
    Posted 11 days ago

    See the Generic Message Options (MSGOPTS) topic in the ACF2 doc on Techdocs. Let us know if this doesn't answer your concern. 

    Thank you.



    ------------------------------
    Laura Fletcher
    Principal Technical Writer
    Broadcom
    Illinois
    ------------------------------