NonStop Looting: How to Steal from the Mainframe You’ve (likely) Never Heard Of

HPE NonStop systems support critical environments such as ATMs and transaction processing, yet their security model is often misunderstood, under-assessed, and susceptible to exploitation. In this talk, we will explore the unique NonStop architecture, its approach to security, and all the quirks that make it feel like a mainframe. From there, we will talk about common misconfigurations and design patterns that create unintended exposure. Finally, drawing on real-world assessment experience, we will walk through real-life case studies that demonstrate how seemingly small gaps can escalate into full system control, enabling an attacker to navigate the system with ease to steal some of the most valuable data available.


HPE NonStop systems are involved in some of the most critical aspects of our modern economies, yet many security professionals are unfamiliar with them and do not have sufficient knowledge to assess them effectively. For example, if you’ve used an ATM, then while you’ve not seen it directly, it is very likely that you’ve interacted with a NonStop system.

This talk provides an introduction to NonStop systems for attendees with no prior knowledge. It aims to give a basic understanding of how the platform works, how security is implemented, and how common weaknesses can be exploited. At a high level, the talk will utilise the following structure:

  • HPE NonStop introduction/overview
    • What is HPE NonStop
    • Where is it used
    • Common systems and terminology within the platform
  • High-level overview of the system’s security model
    • Safeguard/Guardian
    • Users/Groups
    • Underlying UNIX subsystem
  • Attack surface & common security weaknesses (with real-life examples)
    • Safeguard/guardian misconfigurations
    • Pathway/Batch
    • TACLLOCL
    • Third-party security software (XYGATE)
    • Combining issues into full system control
  • Core security assessment methodology and approach
  • Summary/further reading
The speaker's profile picture
JBoorman

James Boorman is a security consultant specialising in mainframe security. Over the past several years, James has spent his time untangling the web that is mainframe security within large, international organisations, delivering assessments and training to identify the hidden risks within these overlooked but undoubtedly critical platforms driving global economies.