|
Yeah, it's a "Feature"! I think that one's been around since the
dawn of AS400. I learned this one from MC or one of the other
magazines, way back when. Look at Security Reference 4.3.1 and
4.3.2.
Eric DeLong
______________________________ Reply Separator _________________________________
Subject: Anomaly or Working as Designed
Author: <MIDRANGE-L@midrange.com > at INET_WACO
Date: 9/14/98 8:30 AM
I'm sure everybody have seen this before:
You put in a number in front of your user profile e.g. 3XCORP
and this message pops up ---- CPF1120 - User Q3XCORP does not exist
I'm ok with this so far, I got a couple of minutes on my hands and decide
to explore.
I create a user profile Q3XCORP with password of Q3XCORP. Ok but I hate
putting a "Q" in front of a
users profile. Next I go to my signon screen and for the user-id I put
3XCORP and the password is 3XCORP.
Expected Results???? I get signed on. OK now I'm really confused, but
wait it gets better.
Next I try Q3XCORP and pswd of 3XCORP. That works too, as does 3XCORP and
Q3XCORP
Is this working as designed? I have tried this on v3r2, v3r7 thru v4r2. I
know it has something to do with
the number first, but in this age of security awareness I think this is not
good.
Questions/comments???
Bryan Dietz
3X Corp.
Columbus OH
+---
| This is the Midrange System Mailing List!
| To submit a new message, send your mail to MIDRANGE-L@midrange.com.
| To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com.
| To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com.
| Questions should be directed to the list owner/operator: david@midrange.com
+---
+---
| This is the Midrange System Mailing List!
| To submit a new message, send your mail to MIDRANGE-L@midrange.com.
| To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com.
| To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com.
| Questions should be directed to the list owner/operator: david@midrange.com
+---
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2025 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.