[00:00.750 --> 00:03.590] I'm pleased to announce our next speaker. [00:04.470 --> 00:11.430] This is AS/400, Lifting the Veal of Obscurity by StankDawg and his colleague. [00:11.790 --> 00:12.710] Let's welcome him. [00:12.850 --> 00:13.130] Thank you. [00:18.800 --> 00:21.140] And my colleague, being ZeroDB, is going to help me out here. [00:22.420 --> 00:27.340] All right, first of all, I don't know how many people here have ever used or are familiar with an AS/400. [00:27.340 --> 00:29.480] Has anybody ever had any experience on an AS/400? [00:29.800 --> 00:30.760] A lot more than I thought. [00:32.800 --> 00:36.880] The thing is, those of you who have used it know that it's a pretty expensive system. [00:37.040 --> 00:39.080] It's a very heavy metal machine. [00:39.800 --> 00:40.760] It's very powerful. [00:40.980 --> 00:44.940] It's something you find at universities, large corporations, large companies. [00:45.100 --> 00:48.400] It's very expensive and I'm very poor. [00:48.640 --> 00:58.040] So, what I've got in this presentation today is some screenshots and some video capture that show it in lieu of being able to get one or have one here to demonstrate. [01:00.280 --> 01:04.840] So, what I'm basically going to do is just talk about generally what the AS/400 is about, how it works. [01:05.540 --> 01:08.320] Kind of familiarize you with the navigation of stuff like that. [01:08.520 --> 01:12.600] I worked in AS/400 shop for about five or six years for an advertising company. [01:13.960 --> 01:17.000] AS/400 is not something you can learn in a college or in school. [01:17.100 --> 01:18.160] They don't teach classes. [01:18.340 --> 01:20.000] Almost none that I've ever been to. [01:20.040 --> 01:21.240] And I've been to five different universities. [01:21.240 --> 01:26.460] I've never seen a single class offered on even basic AS/400s. [01:27.640 --> 01:33.540] So, basically I taught myself, starting in this job, working third shift operations, which I know some of you have been there too. [01:34.560 --> 01:38.760] Kind of just sat there late at night, going through tutorials, going through the help files, stuff like that. [01:38.860 --> 01:40.380] And I'm going to show you how to do some of that too. [01:41.300 --> 01:44.360] Learned about the security, taught myself some CL programming, stuff like that. [01:44.500 --> 01:49.540] So, that's my experience and that's what I'm going to try to share with you because, again, I know a lot of people might not have it. [01:49.540 --> 01:52.940] So, if you do get access to one, you know, after this is all over with... [01:52.940 --> 01:57.620] And if we go ahead, the next slide is about some of the goals of this. [01:57.720 --> 02:00.240] I want you to be able to recognize an AS/400 when you see it. [02:00.420 --> 02:03.760] As silly as it sounds, I know a lot of people say they have not seen an AS/400 before. [02:03.980 --> 02:11.880] So, we're going to show you what it looks like by these screenshots and how to navigate and some of the interface tools that you can use to connect to an AS/400. [02:12.300 --> 02:15.380] We're going to talk about Telnet and Telnet emulation, things like that. [02:16.560 --> 02:19.450] Familiarize you with navigating, get a basic grasp of processing. [02:20.240 --> 02:21.920] And this is the AS/400 strong point. [02:22.020 --> 02:26.740] It's very good at following processing start to finish in clear delineated steps. [02:27.020 --> 02:29.700] And that's something we're going to emphasize towards the end. [02:29.960 --> 02:37.640] And hopefully, by the end of this, you'll be interested enough that you will follow up or you'll want to follow up anyway and find out some more stuff about it. [02:37.720 --> 02:43.560] So, by the end of this, I hope you'll feel more comfortable and be able to find the answers on your own if you have it. [02:43.560 --> 02:45.140] So, we'll go through some of that also. [02:46.620 --> 02:47.020] Okay. [02:47.180 --> 02:49.420] Now, again, I mentioned it's a very obscure machine. [02:49.420 --> 02:55.620] It's not something you can just go into Best Buy or Fry's or whatever your assorted electronic stores are and just buy one. [02:55.840 --> 03:01.040] They do make what they refer to as a Baby 400, but even those are just thousands and thousands of dollars. [03:01.280 --> 03:04.220] So, again, we don't have one to demonstrate, so that's cool. [03:05.860 --> 03:12.480] Also, just kind of a general tip, it's a big faux pas if you ever refer to an AS/400 as a mainframe. [03:12.740 --> 03:13.980] It's not a mainframe. [03:14.040 --> 03:15.100] It's a mid-range system. [03:15.280 --> 03:23.420] If you ever go into an AS/400 shop or a company that has an AS/400 and call it a mainframe, they're going to call you a noob and they're going to laugh you out of the building. [03:23.660 --> 03:25.080] So, don't call it a mainframe. [03:25.100 --> 03:26.140] It's a mid-range system. [03:26.140 --> 03:31.120] But, basically, it's similar to what I'm sure a lot of people have experienced, like a Sun E10k. [03:31.320 --> 03:32.900] It's along that caliber of machine. [03:33.040 --> 03:35.360] It's a very powerful machine, an E10k, E15k. [03:38.520 --> 03:41.600] So, it's along those lines as far as the server and its compatibility. [03:41.780 --> 03:44.140] Now, it runs OS/400 natively. [03:44.800 --> 03:48.860] It's a proprietary operating system provided by IBM, and we're going to focus mostly on that. [03:49.000 --> 03:53.600] The new series of AS/400s, which is the i-series, the e-series, we've probably heard of. [03:53.600 --> 03:59.480] They will run UNIX, they will run Linux, and everybody knows IBM, you know, has been pretty good with their support for Linux, which is very cool. [04:00.220 --> 04:02.020] But, we're going to focus on O/S400. [04:02.640 --> 04:05.380] That's what they run natively, a very expensive license. [04:05.560 --> 04:10.460] But, along with that license, they support... they give you all the support. [04:10.560 --> 04:14.180] They give you cumulative patches, updates to the operating system, and all that kind of stuff. [04:14.420 --> 04:17.300] So, most companies stay with that and go with that. [04:17.360 --> 04:19.780] And I will show you how that is a very robust system. [04:20.660 --> 04:25.460] Again, big blue IBM, it's expensive licensing, constantly updating. [04:25.720 --> 04:28.120] It's, you know, they keep on top of that pretty well. [04:28.260 --> 04:31.600] Although, I could tell stories after the presentation how that doesn't always work right. [04:33.300 --> 04:36.420] And, the way you access an AS/400 is through Telnet. [04:36.760 --> 04:38.080] Now, there's this big misconception. [04:38.400 --> 04:42.240] It's like this little pet peeve of mine that people think Telnet is just Telnet. [04:42.420 --> 04:43.660] Well, Telnet is not just Telnet. [04:43.760 --> 04:47.340] There's different types of emulation that you need to connect to different types of machine. [04:47.340 --> 04:51.500] In the case of the AS/400, you have to be able to use 5250 emulation. [04:52.160 --> 04:57.640] So, in Linux, I don't know how many of you might be familiar, but there's something called the TN5250 project. [04:58.080 --> 05:01.880] You can find that at SourceForge, tn5250.sourceforge.net. [05:01.980 --> 05:03.560] You can download those packages and connect. [05:04.320 --> 05:06.920] There's so many Windows clients that it's too numerous to mention. [05:06.920 --> 05:10.620] Obviously, being a corporate system, they're all running Windows for the most part. [05:10.700 --> 05:11.480] So, there's tons of those. [05:11.600 --> 05:12.600] There's no point in going into them. [05:12.600 --> 05:14.440] But you can check out TN5250. [05:14.440 --> 05:16.740] It's a pretty good interface. [05:20.040 --> 05:22.940] And the sign-on screen is missing. [05:24.120 --> 05:25.480] Well, there we go. [05:25.600 --> 05:26.360] Sign-on screen. [05:26.680 --> 05:27.880] Took it a second to come up there. [05:28.260 --> 05:28.980] Sign-on screen. [05:29.220 --> 05:31.260] When I say recognize it, recognize it. [05:31.400 --> 05:33.980] That is what a sign-on screen to an AS/400 looks like. [05:34.240 --> 05:35.000] Very simple. [05:35.460 --> 05:36.600] Very obvious. [05:37.140 --> 05:39.780] When you see this, you can know right away that you're looking at an AS/400. [05:39.780 --> 05:47.780] Now, in the upper right-hand corner, to protect the innocent, or protect the system that this came from, and to protect me, I've blocked out the system name. [05:47.780 --> 05:50.560] And you'll see some stuff blurred occasionally during the presentation. [05:51.200 --> 05:53.520] But you'll notice there's a subsystem there and a display. [05:54.120 --> 05:57.060] This is in... when you sign-on, you're creating an interactive job. [05:57.180 --> 06:00.920] Just like when you log on to any box, you're working interactively with the machine. [06:02.380 --> 06:03.640] So, keep that in mind. [06:03.760 --> 06:07.980] And you'll notice later on some of the slides, you'll see that q-enter come back in the name of that display. [06:09.440 --> 06:16.900] Just kind of a little in-joke, for those of you who do know 400, you'll see that the username there is Q-SECOPER, which is the security officer password. [06:17.020 --> 06:18.700] That's equivalent to root on the AS/400. [06:19.080 --> 06:21.380] Now, we're not logged in as Q-SECOPER on any of these. [06:24.060 --> 06:25.280] Now, go ahead. [06:25.540 --> 06:30.560] And some of the default users, like I said, Q-SECOPER, which is the security officer. [06:30.720 --> 06:31.320] That is your root. [06:31.620 --> 06:32.980] That's your goal. [06:32.980 --> 06:34.700] You always want to get on this Q-SECOPERr. [06:35.080 --> 06:36.300] They're very tight about that. [06:36.460 --> 06:42.980] AS/400 shops, IBM really wants you to have a dedicated security officer in every installation. [06:42.980 --> 06:47.080] It's one of their requirements, one of the things they push for, they train and stuff like that, to have a security officer. [06:47.280 --> 06:54.640] But by default, and we all know that defaults are where a lot of holes, a lot of ways to get in systems exist, there is a Q-SYSOPER-ator, which is a system operator. [06:55.260 --> 06:59.340] System operators, usually these boxes are maintained 24-7 around the clock. [06:59.440 --> 07:02.360] They have an operator on call for problems and stuff like that. [07:02.360 --> 07:03.720] And they have a lot of authority, too. [07:04.080 --> 07:09.120] Security officer is the one who hands out roles, gives people authority to menus, to programs, stuff like that. [07:09.440 --> 07:15.620] But the system operator also has limited control, can manipulate jobs, end jobs, things like that, too. [07:15.760 --> 07:17.060] So there's a lot of power in that, too. [07:18.080 --> 07:19.320] QPGMR is programmer. [07:19.480 --> 07:26.060] That's like a default programmer role, programmer account that will bring you up to a programming menu, which, again, is going to come up in some screenshots soon. [07:27.100 --> 07:28.980] And that has a lot of power in it, as well. [07:29.300 --> 07:37.140] But they usually, surprisingly, lock down the QPG programmer, because I guess they're scared that the programmers slash hackers might be able to manipulate more things. [07:37.240 --> 07:38.880] So they actually lock that one down fairly well. [07:39.320 --> 07:41.320] And then, beyond those three, there are a couple others. [07:41.460 --> 07:46.480] There's some system-level sign-ons when you want to add hardware and stuff like that. [07:46.520 --> 07:52.100] They're usually only used by the IBM rep, so if you want to add, they come out and add hard drives or update hardware, things like that. [07:52.320 --> 07:56.660] Other than that, everything is going to be different from installation to installation. [07:57.500 --> 08:01.940] One installation's naming convention may be, you know, your last name to log in or whatever. [08:02.140 --> 08:04.940] And that's, you know, depends on one installation to another. [08:05.420 --> 08:11.300] And those usernames are going to be given access based on whatever role the security officer assigns to them. [08:11.540 --> 08:17.980] So if the security officer, for example, somebody works in, I don't know, the accounting office, they may only have access to log on. [08:17.980 --> 08:20.660] It'll come straight up to an accounting menu, something like that. [08:20.860 --> 08:22.540] And they'll only have access to certain things. [08:23.000 --> 08:25.840] Well, they're intended to only have access to certain things. [08:28.360 --> 08:32.280] When you sign on, each user has a default menu that will usually come up. [08:32.480 --> 08:34.280] For programmers, you get a programmer menu. [08:34.400 --> 08:37.140] Like I said, an accounting, cashiering, something like that. [08:37.240 --> 08:43.960] They may come directly up to a menu that only gives them three options, you know, print out, invoices, a purchase order or something like that. [08:44.820 --> 08:50.160] They are simplified forms of navigation, and they are trying to limit you to only the things they give you on that menu. [08:50.540 --> 08:52.720] What happens is they get kind of lazy sometimes. [08:53.020 --> 08:59.980] So the menu will give the options that they want you to have access to, but you may have access to a lot more. [09:00.100 --> 09:01.680] And there are some examples of that coming up too. [09:02.320 --> 09:08.440] No matter what menu you start in, if you can get command line access and you know the name of menus, you can start poking around. [09:08.440 --> 09:14.580] And this is where the fun of playing around in the AS/400 and seeing what you can find and what kind of holes you can find in the system. [09:14.680 --> 09:19.120] Don't never, in general, not even on the AS/400, but in general, never rely on menus. [09:19.600 --> 09:22.320] Menus are just a pretty way to dumb things down. [09:22.540 --> 09:28.640] You can get a command line on anything, you can usually get a lot farther than just using the menus that try to limit you to only certain things. [09:29.100 --> 09:33.060] And to get to menus in the AS/400, you use go and then the menu name generally. [09:33.060 --> 09:36.680] You can also execute them if you kind of trick it out a little bit. [09:36.680 --> 09:42.000] So, this is actually a quick little video that we are going to play. [09:42.140 --> 09:42.760] And you can go ahead and start. [09:43.000 --> 09:46.960] And this is basically just shows you logging in, shows you some basic menu systems. [09:47.140 --> 09:50.120] And again, what you see here is AS/400 sign on screen. [09:50.320 --> 09:52.160] Something we just showed you a minute ago in the screenshot. [09:52.540 --> 09:53.620] And I am going to log in. [09:53.700 --> 09:57.080] We created a disposable account just to demonstrate for this presentation. [09:57.700 --> 09:59.160] So, we are going to log in here. [09:59.360 --> 10:03.360] And notice that when I first log in, a menu system pops up immediately. [10:03.360 --> 10:07.380] Now, this menu is customized to each individual login. [10:07.540 --> 10:11.960] Different roles assigned to different user names as to what they can and cannot access. [10:12.300 --> 10:20.060] This particular account accesses a fairly general menu that has some operations stuff, some programming stuff, some general access to it. [10:20.060 --> 10:25.920] But, for example, a typical user in, say, the cashiering office or something like that. [10:26.020 --> 10:30.200] When they log on, they may be presented with only options to the cashiering menu. [10:30.780 --> 10:35.440] I can call that menu from this location right here by pressing one. [10:35.820 --> 10:39.600] Or, if I know the name of the menu, go directly to it. [10:39.820 --> 10:43.120] Now, when I push one, it's going to take me to that menu. [10:43.120 --> 10:49.360] A user whose role only allows them to access these functions will come straight to this menu when they sign in. [10:50.220 --> 10:56.820] Now, this menu, if you can see right there at the bottom, has its own password protection built into it. [10:56.880 --> 10:59.360] This is actually a package that sits on top of the 400. [10:59.560 --> 11:01.520] It is not built into the AS/400 itself. [11:01.640 --> 11:03.400] This is simply a program that is called. [11:04.100 --> 11:06.820] Now, I'm going to just log out of this, sign out of this. [11:06.820 --> 11:14.340] Now, since this is a custom menu, it's got a bug or a little of the way that's set up is it expects most users to go directly into this when they sign off. [11:14.580 --> 11:16.600] We'll sign them completely off of the 400. [11:16.960 --> 11:17.900] So, that's what it did. [11:17.980 --> 11:21.480] Now, I'm going to go back in and log in and show you that very first menu again. [11:21.880 --> 11:28.340] And notice that also this particular account has access to a programmer's menu, which is number six on the screen. [11:28.520 --> 11:30.260] And then this organizer menu. [11:30.440 --> 11:33.160] And it tells you to the right the name of said menu. [11:33.160 --> 11:37.000] Now, obviously, I have control or access to that menu. [11:37.000 --> 11:42.140] So, I can either take option 40, which will take me directly to it. [11:42.240 --> 11:47.000] This first menu will automatically make that function call or that screen call for me, that menu call. [11:47.860 --> 11:50.880] But by F3ing back out to this main menu, and these menus stack. [11:51.020 --> 11:57.620] The deeper you go in there, you're stacked and you can always go backwards to wherever you started off from and come back to this originally before you sign out. [11:57.960 --> 12:06.480] But since I obviously have access to that menu, not only can I type in 40, but because I have a command line here, I can type in go and then the name of the menu. [12:06.500 --> 12:08.520] So, P-C-O-M-N-U. [12:09.000 --> 12:10.940] And the exact same thing happens. [12:11.460 --> 12:16.020] Now, obviously, I had access to this menu, so it let me go through to this menu. [12:16.200 --> 12:18.660] And the same thing with the programmer's menu. [12:19.360 --> 12:20.700] I can type in the command. [12:20.700 --> 12:22.740] I can select option six, for example. [12:24.040 --> 12:29.520] Now, a programmer may come straight up to this menu and have only access to this menu. [12:29.520 --> 12:40.100] Now, this is where you kind of really need to think and stay with the thought process of here of knowing where menus exist and knowing if menus exist. [12:40.180 --> 12:41.320] And it's very, very important. [12:42.640 --> 12:46.720] You can see that from this menu here, which don't worry about all the stuff on the screen. [12:46.720 --> 12:48.480] I know there's a lot and it's not going to all sink in. [12:48.560 --> 12:54.920] But one of the things is the programmers do have the authority to run commands, simple commands. [12:54.920 --> 12:58.640] So by putting a five into this first menu, it tells them to run a command. [12:58.900 --> 13:03.040] And then going into this command, it tells me exactly what command do I want to run. [13:03.780 --> 13:10.300] So I can go, which is an AS/400 command, I can go to that very first menu that started up. [13:10.320 --> 13:13.920] And I don't know if you noticed in the upper left-hand corner, it was called ADM-MENU. [13:15.020 --> 13:24.020] So even though this programmer does not have this on their list, they can type in the command if they know the menu and have authority at the menu. [13:24.480 --> 13:26.580] And bam, they're right back to the menu. [13:27.540 --> 13:36.520] So you see here how you can keep going around and get through menu, through menu, through menu, if you know the names. [13:36.680 --> 13:38.400] Now if they're presented to you, that's great. [13:38.500 --> 13:40.100] You're obviously supposed to have access. [13:40.100 --> 13:45.480] But the problem is, what if you know the name of a menu that's not on any of these lists? [13:46.300 --> 13:49.760] That does not necessarily mean you don't have authority to it. [13:49.840 --> 13:50.620] You should not. [13:51.140 --> 13:57.260] But the problem is, many, many security officers and system administrators do not like their systems down tight enough. [13:57.500 --> 14:01.960] So for example, I know that there is a menu on this system called OP-Main. [14:02.700 --> 14:04.900] This is a menu for Q-SYSOPER. [14:04.980 --> 14:09.540] When Q-SYSOPER signs on, which is the system operator, they go directly to this menu. [14:09.540 --> 14:13.780] But this account should not have any authority whatsoever to go to that menu. [14:15.360 --> 14:16.240] Or does it? [14:17.280 --> 14:23.980] I just accessed the Q-SYSOPER menu, even though I am not logged in as Q-SYSOPER, which is a pretty powerful account. [14:24.720 --> 14:25.700] That's why everything is blurred. [14:25.720 --> 14:28.460] The system operator has authority to a lot of things, like you can see on the screen. [14:29.360 --> 14:30.680] Start some different backups. [14:30.680 --> 14:33.940] You can perform system startup, terminate programs. [14:34.380 --> 14:38.640] Lots of powerful things that you can do here from this menu. [14:38.880 --> 14:46.420] And if you have access to this menu, generally, you are going to have access to some of the functions within this menu, for example. [14:47.940 --> 14:50.300] Also, as I mentioned earlier, these menus stack. [14:50.440 --> 14:52.520] So you have been seeing me jump through menu through menu. [14:52.520 --> 14:55.600] Well, I am going to keep hitting Command 3, which is exit. [14:55.740 --> 15:00.260] F3 is the universal exit command on many, many heavy metal machines. [15:00.300 --> 15:09.520] But if I hit Command 3, what you will see is we will back up through the entire process, back to this menu that I called, to this one, back to this. [15:09.640 --> 15:13.120] The next one, of course, if you are following along backwards, would be the programmer menu. [15:13.540 --> 15:15.740] We are back here with the last command that we called. [15:15.740 --> 15:20.880] And even from this, Command 3 one more time, and this is actually where we started in the first place. [15:21.080 --> 15:30.440] So even though this is the menu presented to me, and there's only a couple other menus that I have access to, don't limit yourself to what you see. [15:30.600 --> 15:33.860] It's classic security through obscurity. [15:34.020 --> 15:37.120] It's the very definition of security through obscurity. [15:37.260 --> 15:49.300] Just because you don't know the name or don't have it placed in front of you, you can still access a whole lot of things on the AS/400 just by knowing how it works and knowing where to find. [15:51.720 --> 15:58.800] Alright, and now, again, I wish we had one here that I could kind of talk and demonstrate as we go along, but that's kind of the best way to describe some of that. [15:58.960 --> 16:05.500] But the real point of that is a programmer would have started directly in that programmer's menu in most installations. [16:05.500 --> 16:15.380] But you see, by knowing outside what's outside of those boundaries, you still can have a lot of authority, a lot of access to that, and execute things that you weren't meant to. [16:15.480 --> 16:21.060] I could have logged directly on as QPGMR, started in a programmer menu, and gone to all those things you saw as well. [16:21.380 --> 16:29.380] And as far as knowing the name of some of those menus, social engineering skills come into play, shoulder surfing comes into play, reading manuals comes into play. [16:29.380 --> 16:39.740] Everything's documented in companies that you can find all this information, because just like people write passwords on post-it notes on their computer, people write documentation and have it stored somewhere. [16:39.980 --> 16:42.060] So you can find a lot of that information in there. [16:43.340 --> 16:48.960] Now, as far as... I said, you know, that's menus, is basic navigation to move around, but you don't want to be reliant on menus. [16:49.040 --> 16:50.540] You want to get used to using commands. [16:50.760 --> 16:55.440] And on the AS/400, most commands, not all, but most of them are based on three character combinations. [16:56.160 --> 16:59.320] And in my opinion, they kind of make sense, they're kind of obvious. [16:59.560 --> 17:04.420] They're so obvious, in fact, that I really think you can guess a lot of them, if you wanted to do some of this stuff. [17:05.100 --> 17:08.640] DSP means display, W-R-K, work with, and et cetera, et cetera. [17:08.880 --> 17:11.400] You can combine these three-letter combinations. [17:11.400 --> 17:13.480] It's not just starting, it's along the way. [17:13.580 --> 17:17.620] And you can't completely just mix and match two from column A, one from column B. [17:17.780 --> 17:20.280] But in general, you can create a lot of commands going along there. [17:21.140 --> 17:22.840] Display system status is an example. [17:22.960 --> 17:24.340] You can do a display system status. [17:24.340 --> 17:27.560] You can't system work status or something like that. [17:27.700 --> 17:29.220] But that's something, again, you get used to. [17:29.460 --> 17:31.080] And again, the help tells you a lot about that. [17:31.240 --> 17:36.520] So just a few basic commands will get you a long way and give you a lot of access to an AS/400. [17:37.000 --> 17:42.180] And if you know program names, you can call those program names directly using the call command. [17:44.880 --> 17:50.180] And execute things, again, that may not be on a menu or that you know the name of, but you don't know what libraries, things like that. [17:50.180 --> 17:56.180] So you can get a command line on almost any system by issuing call QCMD. [17:56.860 --> 18:01.160] You do a call QCMD that will execute standard command line, which gives you... [18:01.700 --> 18:07.460] You saw at the bottom of some of the menus, if you were set up with a role that has the authority to command line, it will be at the bottom of the menu. [18:07.920 --> 18:10.980] People will have access to that same menu without a command line just as easily. [18:11.720 --> 18:14.000] But that's kind of... you only get to see one thing. [18:14.140 --> 18:19.100] If you go to a call QCMD, you'll get to see a list of all your historical commands and things like that. [18:19.160 --> 18:21.160] So it's a little bit... it's a little bit nicer. [18:25.820 --> 18:27.320] Now, some of the example command... [18:27.320 --> 18:34.620] First of all, access to them is limited by authority, whatever the security officer gives your authority to. [18:34.760 --> 18:41.700] So getting access to a higher account, getting access to a different user name or something like that will give you completely different authority to something else. [18:41.960 --> 18:44.060] However, like any other system... [18:44.600 --> 18:49.460] In general, a system is only secure as its administrator is competent. [18:50.380 --> 18:52.880] Anywhere, anytime, AS/400 is no exception to that. [18:53.120 --> 18:58.860] So you'll find a lot of security officers that are just in over their head and they don't bother putting proper securities. [18:59.300 --> 19:01.600] You know, that's common sense and you guys know that for any system. [19:01.680 --> 19:02.680] And it holds true on the AS/400. [19:03.080 --> 19:04.480] So I could, you know, sit here. [19:04.600 --> 19:09.380] There are thousands upon thousands upon thousands upon thousands of commands on the AS/400. [19:09.380 --> 19:10.800] You can guess at a lot of them. [19:10.880 --> 19:11.580] You can use the help system. [19:11.680 --> 19:13.380] So there's really no point in going through all of these. [19:13.520 --> 19:15.820] But these are some of the very common ones. [19:16.720 --> 19:17.600] Display job queue. [19:17.780 --> 19:20.240] We're going to go into some of these in very good detail in a few minutes, too. [19:20.560 --> 19:23.400] Display job queue, work active job, display out queue specifically. [19:23.840 --> 19:29.440] Those are all commands that we're going to go into very in-depth analysis in a few minutes. [19:29.760 --> 19:31.460] And change user profile. [19:31.780 --> 19:32.480] Does that make sense? [19:32.600 --> 19:35.200] C-H-G-U-S-R-P-R-F to change user profile. [19:35.300 --> 19:37.700] Now, that's something they usually don't give access to anybody. [19:40.340 --> 19:43.020] Now, again, we have... [19:43.020 --> 19:44.700] Well, I jumped ahead. [19:47.720 --> 19:48.240] Okay. [19:49.540 --> 19:50.380] Let's see here. [19:50.480 --> 19:51.900] The help has... [19:54.480 --> 19:57.360] It's very robust, very intuitive help system that it has. [19:57.440 --> 19:58.380] It has command assumption. [19:58.380 --> 20:00.480] If you don't know the command. [20:00.480 --> 20:02.800] If you don't know how it's going to... [20:03.380 --> 20:04.780] How the command... [20:06.880 --> 20:07.280] Finishes. [20:07.520 --> 20:08.660] You know it's displayed something. [20:08.980 --> 20:10.400] You can type in DSP asterisk. [20:11.320 --> 20:15.940] And it'll bring up a menu and show you all of the commands that are following that system. [20:16.140 --> 20:16.800] And the F keys. [20:16.940 --> 20:19.240] A lot of people, you know, take for granted those F keys. [20:19.240 --> 20:20.040] Those are all used. [20:20.040 --> 20:24.480] If you saw at the bottom of a lot of the menus, you'll see that you can use those F keys for help. [20:25.180 --> 20:27.240] And for other functions that are built behind it. [20:27.760 --> 20:30.160] So, command assumption. [20:30.440 --> 20:32.660] And there are documentation. [20:32.920 --> 20:34.400] IBM's famous for its documentation. [20:34.400 --> 20:37.260] They document everything like to the letter. [20:37.500 --> 20:39.440] So, you can always find documentation. [20:40.860 --> 20:41.960] Shelves upon shelves. [20:42.140 --> 20:42.820] Books this thick. [20:42.920 --> 20:44.160] They show every step that... [20:44.160 --> 20:48.520] Even somebody who's not computer proficient can sit down and follow directions profusely. [20:48.900 --> 20:50.280] Every little detail of it. [20:50.680 --> 20:53.540] And of course, like anything else, you can find a lot of support online. [20:54.160 --> 20:58.160] Just do a little Google search or whatever your search engine of choice happens to be. [21:00.440 --> 21:03.920] And next, we have command line. [21:04.320 --> 21:05.600] And this is... [21:05.600 --> 21:07.140] Again, this is a little video. [21:08.260 --> 21:10.220] So, just go ahead and start this. [21:10.360 --> 21:14.220] And basically, what this is happening is this is just giving you a little demonstration. [21:14.580 --> 21:17.420] Now, once again, we're at the main menu that you saw a few seconds ago. [21:17.880 --> 21:26.740] And you see it's kind of cluttered up because this menu has got some programming behind it that will basically execute these commands or call these menus, etc. [21:26.740 --> 21:29.640] And sometimes you don't want all that clutter in front of you. [21:29.900 --> 21:33.420] There is a screen that will give you just plain command line. [21:33.540 --> 21:35.340] Now, yes, I have command line access here. [21:35.400 --> 21:37.960] And it's pretty much universal if you've got the command line. [21:38.000 --> 21:39.740] You have access to a command line. [21:40.340 --> 21:43.200] It's going to work no matter whether it's in a menu or not. [21:43.260 --> 21:45.000] But there is another screen that I like. [21:45.400 --> 21:48.200] And you get to it by doing call QCMD. [21:48.620 --> 21:51.060] And this is just a dedicated command entry. [21:51.060 --> 21:56.600] And I like to kind of sit here and idle when I'm leaving my system up because I don't really need menus. [21:56.600 --> 22:01.140] And you probably should not be dependent on menus for kind of the reasons I showed you earlier. [22:01.160 --> 22:02.360] You know more about it. [22:02.420 --> 22:04.400] You don't become reliant on only what you see. [22:04.540 --> 22:05.260] You get out of that mindset. [22:05.600 --> 22:12.820] But it's also got some other things that are handy, like it will let you do multiple commands and do them right here from the command line. [22:13.920 --> 22:17.460] And if there's something that you do frequently, you can always... [22:17.460 --> 22:20.460] And I'm just throwing a couple commands at it just to show you what it looks like. [22:21.560 --> 22:24.800] You can also start chaining these things together. [22:24.800 --> 22:31.780] And if it's something you do frequently, you can go back to any one of them very easily by hitting the F9 key. [22:31.880 --> 22:35.020] And if the F9 key at the bottom of the screen you'll see says Retrieve. [22:35.380 --> 22:38.340] So if I press F9, it will bring up the previous command. [22:38.520 --> 22:40.640] Hit it again, it will be the command before that. [22:40.640 --> 22:43.020] And you see it kind of runs up the screen here. [22:43.180 --> 22:49.540] As I keep hitting F9, it will keep going to the previous command, including the system call that I made earlier. [22:51.160 --> 22:58.160] So if you do something repetitively, you can always do an F9, which is basically like the history in UNIX, where you can keep going back and forth. [22:58.520 --> 23:12.260] Another thing is if you don't... if it's way up at the top of the screen or 10, 20 commands ago, you can just take your cursor and move directly up to the command in question and hit F9, and it will bring it right down, and you can just hit Enter to re-execute that command. [23:12.420 --> 23:16.180] Now this particular one just shows you a little bit about the system information, so don't worry about that. [23:16.600 --> 23:20.500] But another thing I should point out is this menu system down here at the bottom. [23:20.980 --> 23:23.000] Every screen has this. [23:23.000 --> 23:25.760] It's standard on the AS/400, and they're fairly smart. [23:25.760 --> 23:32.300] They know, for the most part, what screen you are on, and it gives you options that are appropriate to that screen. [23:33.000 --> 23:39.720] So let me move the cursor out of the way here and basically show you that, like I said before, F3 is pretty universal on every screen. [23:40.560 --> 23:42.740] F12 cancels something you're in the middle of, that's fine too. [23:42.800 --> 23:44.020] F9 I just showed you retrieve. [23:45.160 --> 23:50.680] Now, going into every one of them is a little overkill, but F10, for example, just gives you a little bit more detailed information. [23:51.260 --> 23:54.940] What run level, the request level or run level everything was executed at. [23:54.940 --> 24:06.760] It throws the two in front of there, shows me a little bit more information in between all those commands, like what subsystem it's in, what authorities you may have, what libraries the programs you're calling may be in, etc. [24:07.080 --> 24:08.620] So sometimes you want to turn that on. [24:08.700 --> 24:11.100] That can be handy if you're trying to debug something. [24:12.120 --> 24:22.840] F24, you see if there's too many functions available in that menu, the F24 key, which is your shift and F12, will take you to the rest of the options that are in front of you. [24:22.840 --> 24:27.300] Now, again, we're not going to go through every one of them, but kind of watch as we go through the rest of the presentation. [24:27.360 --> 24:31.820] You'll see that they're different for every screen depending on what you're trying to do. [24:32.120 --> 24:37.560] And one last thing to show you about the commands is to show you how intelligent the commands are in the system. [24:38.080 --> 24:42.600] I can do a work out queue command, which we're going to go into more detail about later. [24:42.960 --> 24:50.080] Now, if I just hit enter, it's basically like executing a command on Linux or something like that with the defaults. [24:50.080 --> 24:51.940] It will work and it will do something. [24:52.300 --> 24:57.040] And basically, the default for this is to show you every, all output queues. [24:57.540 --> 25:01.900] Well, what you can also do is something called a prompt. [25:01.960 --> 25:06.440] And if you see F4 prompt down there, that is a very, very important and very powerful. [25:06.560 --> 25:15.180] No matter how much you know the system and how much you get memorized about it, you'll always find yourself prompting a lot of commands because you can't know every single option. [25:15.560 --> 25:22.240] And what that means is when you put in your command, it's a similar way if you want to think of it in UNIX as flags. [25:22.760 --> 25:33.740] Like if you wanted to do an ls-ls, those two flags that you put on there, the minus ls that you put on there, tell it two other things that you want that ls command to do. [25:33.740 --> 25:35.820] Well, you don't do flags on the ACE 400. [25:35.900 --> 25:37.240] What you do is you prompt it. [25:37.440 --> 25:45.480] And it will give you a list of all of the other options that are available to you, or excuse me, to this particular command. [25:45.480 --> 25:48.240] So anything else that you would want to fill in on such a command. [25:48.460 --> 25:51.080] And like I said, the default on this is star all. [25:51.080 --> 26:06.700] I could easily say, to only give me those cues that begin with a 0, or excuse me, an O, and a star being the asterisk being the wildcard, and leave the library blank, which also defaults to all, I could start looking only through specific libraries if I'm trying to isolate, [26:06.720 --> 26:08.700] say, a job log or something like that. [26:08.820 --> 26:10.720] And I can also change the output to print. [26:11.040 --> 26:13.180] By default, it goes straight to the screen. [26:13.380 --> 26:18.860] So I changed it to only O star this time, and it's only going to show me those two out cues that begin with the letter O. [26:19.400 --> 26:22.880] So this is a simple command to show you, but there are a lot of other... [26:22.880 --> 26:27.460] Like, for example, what if we were to do something like change user profile? [26:29.560 --> 26:31.760] This brings up one option. [26:31.760 --> 26:34.280] What is the name of the user profile you want to change? [26:34.580 --> 26:42.940] Well, we could put it in, and then press F10, which is additional parameters you see down there, and you will see all of the options that you have. [26:43.000 --> 26:46.820] And let's do Q-SECOPER here, just for demonstration purposes. [26:47.420 --> 26:50.960] And page through all the different parameters that are related. [26:51.160 --> 26:56.000] See, these could all be flags, and you could see how they could start to add up depending on what command you're working on. [26:56.420 --> 27:04.980] So, again, we're not going to go through every one of these, but you can tell, text description security officer, you can tell what library it runs to, what user class it is. [27:05.040 --> 27:06.900] And this is like roles, like we talked about earlier. [27:07.020 --> 27:08.300] You have system operator, et cetera. [27:08.840 --> 27:14.860] And within each one of these, you can F4 again to prompt and see what are the valid values that you can put in. [27:15.120 --> 27:17.660] These are the different roles that are set up on this system. [27:18.320 --> 27:25.560] So, when I command three out of that, it tells me that it did, but notice that it has all of these parameters on there placed in. [27:25.820 --> 27:28.040] Instead of doing them by flag, they're positional. [27:28.040 --> 27:37.820] I can bring that command back down here, and notice that usrprf, these are unique names, that when we F4, it will automatically plug back in. [27:38.020 --> 27:42.800] Any of the ones that have this right here next to it is something that we brought in. [27:43.120 --> 27:54.260] And if I ever wanted to bring that in myself, I know what those keywords are, and I can type in lmtcpb star the same, and I can do it all from command line without prompting it. [27:54.260 --> 28:00.880] But again, there's so many options on so many commands that it really gets kind of overkill at some point. [28:01.000 --> 28:06.300] So just get in the habit of prompting it and get used to some of your repetitive commands, and you'll do them a lot quicker from the command line. [28:06.500 --> 28:13.880] And of course, if we F3 out of this command line, which remembers a separate screen, we go back to our main menu, and we're done. [28:17.220 --> 28:21.260] Now again, the change user profile, had I hit enter, would not have done anything. [28:21.260 --> 28:23.660] I did not have authority to that, so... [28:24.960 --> 28:36.600] But, and again, I know this is a lot of dry technical material, and that's kind of why I was trying to keep it visual here, because you're seeing a lot of commands and a lot of options that even people who've worked on it for years and years don't memorize and don't know all those. [28:36.720 --> 28:43.500] But understand that by prompting it, you can bring up all those options for all those commands, and you can get help on each one of those and things like that. [28:43.600 --> 28:49.040] So just understand how it works and how the command line works, and then when you get on a system, you can play with it and get more comfortable with it. [28:49.040 --> 28:54.240] So I just wanted to demonstrate exactly how, and you don't have to worry about the details or memorizing a lot of the commands themselves. [28:56.000 --> 29:00.800] Now, this is a command assumption, which you can go ahead and... [29:03.290 --> 29:04.150] Did it play? [29:09.070 --> 29:11.170] Now, command assumption is what I was talking about earlier. [29:11.290 --> 29:14.770] If you don't know the command, you can just type in the first three letters of the command. [29:14.770 --> 29:18.010] You want to display, but you didn't know if it was display writer, display printer. [29:18.790 --> 29:21.030] Maybe you wanted to display a log of some sort, but you didn't know. [29:21.130 --> 29:22.170] You didn't want to see the history log. [29:22.290 --> 29:23.670] It was display job? [29:23.950 --> 29:24.610] Was it display? [29:25.010 --> 29:26.610] You know, you're not sure exactly what it was. [29:26.690 --> 29:32.550] You can do display DSP star or any command, put that star in there, and it'll automatically fill out the rest of it. [29:32.850 --> 29:36.890] It won't do command assumption like the tab key, like a lot of us get really in the habit of using. [29:37.190 --> 29:39.510] But you can at least get up a list of different ones. [29:39.510 --> 29:47.210] This particular one, you can see the command is given to you, display job, so that you could have typed it in directly, DSPJOB from the command line. [29:48.130 --> 29:53.070] Or you could have put the one next to it and executed it from this menu, which is also kind of handy. [29:53.210 --> 29:57.210] You're already in here, why not just type the one to make it go a little bit further. [29:57.410 --> 30:03.330] So, you can come back out here and type in any command directly, like the display log command. [30:03.530 --> 30:11.690] And we're going to talk about logging a lot, but let me just warn you up front that everything you do on the AS/400, and I mean everything, is logged on the AS/400. [30:12.250 --> 30:16.890] I'm going to reiterate that a lot towards the end of the presentation, but everything is logged. [30:17.090 --> 30:22.910] So, you can do a display job, you can do the display log command, and you'll see all this stuff in here and all these steps. [30:23.310 --> 30:30.270] So, by using the command assumption, again, that's another form of help, that's another way that you can learn to navigate on the system. [30:31.990 --> 30:35.690] And whether you do it through that menu or do it by just typing in, that's fine. [30:36.350 --> 30:41.310] The next form of help, besides command assumption, is context-sensitive help. [30:41.450 --> 30:44.510] On the next slide, if you play this, you can see... [30:44.510 --> 30:48.530] Now, again, this is another way that you can get help in the AS/400. [30:49.790 --> 30:52.890] Let's say that you're on a screen that you're not familiar with. [30:52.930 --> 30:53.730] You don't know it too well. [30:53.790 --> 30:57.610] You don't know what a lot of these things mean that are on the screen. [30:59.050 --> 31:03.510] And again, as somebody who has experience, you probably know a lot of this, but for the others, you see type. [31:03.670 --> 31:05.730] You don't know what type of job that is that you see running. [31:05.950 --> 31:09.210] You go over there, you put your cursor on what you want to find out about. [31:09.450 --> 31:14.410] And the AS/400 help is the most robust I've seen on any system that I've ever worked with. [31:14.630 --> 31:20.570] You put your F1 key, put your cursor there, hit F1, and it'll bring you up a list of all the possibilities for that field. [31:20.570 --> 31:22.470] Status, what is DEQW? [31:23.170 --> 31:24.770] You may not even have a clue. [31:25.050 --> 31:31.270] You go over to it, you can scroll down through the list, and right there it'll give you a description of what DEQW is. [31:31.490 --> 31:34.770] You can read up, you can, you know, it's just an example. [31:34.950 --> 31:38.750] And notice that that is tied to this Work Active Jobs menu. [31:39.050 --> 31:43.290] So, every other menu, anything provided by AS/400 has this built into it. [31:43.410 --> 31:45.170] You can go just about anywhere on the screen. [31:45.350 --> 31:48.410] You can maximize this up and fill the screen. [31:48.410 --> 31:52.450] And the funny thing is, you can get help on using the help. [31:52.690 --> 31:58.810] So, if you're inside of the help for that particular thing, you hit F1 again, you'll get the help on how to read the help menu that you just brought up. [31:59.550 --> 32:01.370] You can go other places on the screen. [32:01.550 --> 32:04.950] You'll get general menu help for the whole menu itself. [32:05.990 --> 32:11.430] And on the left-hand side, for example, things like CPU percentage, the subsystem and job name. [32:11.650 --> 32:13.410] Those are installation dependent. [32:13.570 --> 32:13.850] They're different. [32:13.970 --> 32:17.130] Those are actual names that are assigned to jobs and devices. [32:17.130 --> 32:19.270] You're not going to get help on something like that. [32:19.390 --> 32:21.350] But you will get help on what that column is. [32:21.470 --> 32:23.730] It'll tell you, this is a list of job names. [32:23.870 --> 32:26.630] And they are going to change from one installation to the other. [32:26.850 --> 32:30.750] So, whatever naming convention they've decided to use, that's what you're going to see there. [32:33.730 --> 32:38.530] Now, everybody's seen this since your first class in high school. [32:38.950 --> 32:41.250] They're teaching this in preschool now, I think it seems like. [32:41.410 --> 32:43.470] The good old-fashioned input processing and output. [32:43.470 --> 32:45.830] And that's as good as my artistic skill gets. [32:45.930 --> 32:47.590] I can draw squares and lines, that's about it. [32:48.050 --> 32:51.110] But, I mean, we're not going to, you know, I'm not going to talk down to you. [32:51.190 --> 32:52.670] Everybody knows input processing and output. [32:53.390 --> 33:00.790] Input can take the form, though, of feeding data files in, passing parameters to a program or a command, stuff like that. [33:01.030 --> 33:02.250] Processing is actually working. [33:02.530 --> 33:06.090] On most heavy metal systems, AS/400, they don't refer to them as programs. [33:06.090 --> 33:07.010] You'll call them jobs. [33:07.150 --> 33:07.870] Jobs are running. [33:08.330 --> 33:10.190] You can see them in that work active job screen. [33:10.310 --> 33:13.670] And when it goes out, it doesn't directly go to a printer. [33:13.790 --> 33:14.750] There's a queuing process. [33:14.990 --> 33:20.210] And I couldn't tell you exactly which issue, but I had an article in 2600. [33:20.350 --> 33:30.350] It was batch versus interactive that talked about, you know, the differences between the two and how when you submit a printout, there's a split second when you're actually submitting that printout that it's kind of in a limbo or it's being submitted. [33:30.550 --> 33:33.670] The AS/400, this is what it's really good about, and we're going to go into some detail. [33:33.670 --> 33:41.550] There's one more kind of long video that's going to talk about that, but basically show you the clear delineations of input, processing when it ends and begins, and the output. [33:41.750 --> 33:46.930] It goes to an output queue, and those queues can be tied to whatever printer, and you'll see that in a couple seconds. [33:47.110 --> 33:57.110] But this is just the best demonstration of... I wish they would show this as a demonstration in schools when they teach this because instead of memorizing this little diagram. [33:57.650 --> 33:59.750] So again, batch versus interactive jobs. [34:00.210 --> 34:05.750] When a program crashes on the AS/400, when a job crashes, they call it a halt, and the job will sit there. [34:05.930 --> 34:11.050] Sometimes the file that you're trying to write to or read or something like that may be locked by another user. [34:11.090 --> 34:12.710] Another programmer is using that same file. [34:13.230 --> 34:16.390] It'll try a couple times to access that file, then it'll lock. [34:16.510 --> 34:29.110] Instead of crashing completely, blue screen of death, spontaneously rebooting like some operating systems do, it'll halt, and it'll prompt usually the system operator, and that's why they're monitored 24-7, or the programmer obviously will be monitoring their job hopefully. [34:29.670 --> 34:38.450] Can go in there, read the error message by looking at the display job command I showed earlier, or, you know, there's lots of different ways for that, and see what the problem is. [34:38.510 --> 34:39.310] Why did the job halt? [34:39.390 --> 34:41.770] It may be fixed and shoot right in and continue running again. [34:42.810 --> 34:50.470] So, just the three steps of input, processing, and output on the S-400 are represented by the job queue for input. [34:50.670 --> 34:53.830] You input something to a job queue, and that's where it sits before it runs. [34:53.990 --> 34:57.810] When it runs, it goes onto the work active job screen, and when it's done, it goes to an output queue. [34:59.230 --> 35:02.030] Now, we do have some screenshots here. [35:02.110 --> 35:09.510] The job queue is, think of it as a library, a placeholder, a cup, whatever you want to call it, where your jobs get submitted into. [35:09.510 --> 35:12.530] And, again, this varies from installation to installation. [35:12.710 --> 35:15.410] The ones you see here are kind of some defaults that come with it. [35:15.510 --> 35:16.730] Q-I-N-T-E-R. [35:18.390 --> 35:21.510] Anybody remember that first sign-on screen up in the right-hand corner? [35:21.590 --> 35:22.350] I said it might come back. [35:22.830 --> 35:26.670] When you sign on, your interactive job is going to show up under... [35:26.670 --> 35:28.410] It's going to shoot through the Q-Enter job queue. [35:28.630 --> 35:30.750] When you go to the work active jobs, you'll see it. [35:30.850 --> 35:33.350] And go ahead to the next one is the work active job screen, I hope. [35:34.750 --> 35:44.010] And on the work active jobs, you'll see under Q-Enter, on the subsystem and job name, you'll see the name of those subsystem and job names. [35:44.270 --> 35:46.810] Q-P-A-D is just something it randomly assigns to it. [35:47.510 --> 35:51.290] And that's the job name of your interactive job, your interactive session. [35:51.470 --> 35:53.910] Again, batch jobs by default will go to Q-Batch. [35:54.270 --> 35:56.770] Most installations customize that and put them in different areas. [35:57.370 --> 35:58.690] And it shows you the username. [35:58.970 --> 36:00.930] Well, again, I can blur. [36:01.150 --> 36:01.890] I did a little creative Photoshopping. [36:02.490 --> 36:03.850] I had to blur out some usernames there. [36:05.390 --> 36:07.190] And you'll see, this is another... [36:07.190 --> 36:08.230] I didn't actually put this in my notes. [36:08.330 --> 36:09.630] I'm going to throw this off the hip. [36:09.710 --> 36:11.770] You'll see the function right there. [36:12.090 --> 36:13.270] Work active job command. [36:13.270 --> 36:14.630] You can see a list of all the jobs. [36:14.810 --> 36:18.330] You can see that that user is running work active job. [36:19.130 --> 36:20.750] I wonder who that could possibly be. [36:21.070 --> 36:22.850] You see someone else is running op main. [36:22.850 --> 36:24.450] Someone else is running APPL menu. [36:25.650 --> 36:28.930] If you know a menu name, you might be able to access it. [36:29.490 --> 36:30.910] I just found a menu name. [36:31.030 --> 36:32.210] This is how you find that kind of stuff. [36:32.590 --> 36:34.350] Backdoor your way into other menus that... [36:34.350 --> 36:35.350] Nobody told me that existed. [36:35.490 --> 36:36.410] Nobody knew that existed. [36:36.570 --> 36:40.070] But I found out because you know the architecture of the system. [36:40.730 --> 36:43.090] So after the active jobs, your job runs. [36:43.290 --> 36:44.330] Sometimes it'll be like that. [36:44.570 --> 36:45.050] Quick job. [36:45.530 --> 36:47.190] Interactive jobs, as long as you're logged in. [36:47.330 --> 36:48.430] You're SSHed into a box. [36:48.470 --> 36:49.570] You're running an interactive session. [36:49.750 --> 36:51.710] You're Telneted to an AS/400, whatever. [36:51.710 --> 36:52.730] You're logged into a session. [36:52.850 --> 36:53.670] You stay in the whole time. [36:53.790 --> 36:55.370] You may be on for hours at a time. [36:55.590 --> 36:57.610] You submit a quick little batch job to print something. [36:57.690 --> 36:58.990] It may shoot through the system like that. [36:59.530 --> 37:02.210] So when it does, you generate some sort of output. [37:02.350 --> 37:04.050] There's a job log generated for every job. [37:04.190 --> 37:06.310] That tells you everything that happened in that job. [37:06.450 --> 37:07.690] Interactive or batch or otherwise. [37:08.310 --> 37:09.510] Or you can send a printout. [37:09.670 --> 37:10.730] All these are forms of output. [37:10.850 --> 37:12.810] And they go into an output queue designated by... [37:12.810 --> 37:14.290] However your installation is set it up. [37:15.190 --> 37:16.230] And what I'm going to show... [37:16.230 --> 37:18.370] There's one more long video coming up here that's a little bit technical. [37:18.370 --> 37:22.910] And other than that, most of this is pretty straightforward. [37:23.490 --> 37:27.810] You'll see in these particular queue names, and they vary from installation, how many files are in there. [37:28.310 --> 37:32.910] That top one, the ADM01, you'll see there's 753 files in that. [37:33.210 --> 37:34.310] That's something they probably... [37:34.310 --> 37:36.370] I'm guessing they probably use to... [37:36.910 --> 37:37.730] They don't want them to print. [37:37.830 --> 37:41.230] That may be like job logs or crashes or something they want to analyze later. [37:41.430 --> 37:42.570] They just save them in the output queue. [37:42.570 --> 37:43.510] You don't have to print everything. [37:44.130 --> 37:47.170] You put in an output queue, and once it's there, you can do a lot of things with it. [37:47.290 --> 37:51.370] So, you can always go through output queues and find a lot of stuff. [37:51.970 --> 37:54.470] The best things that you'll find are in output queues. [37:54.570 --> 37:56.090] And they're very seldom locked down. [37:56.310 --> 37:58.870] Very seldom do they put proper security on output queues. [38:00.410 --> 38:05.590] Since you didn't just send this intangible magic print job to a printer, you can actually go in there. [38:05.690 --> 38:06.470] It's a file. [38:06.650 --> 38:09.710] Everything on the AS/400 is an object. [38:09.710 --> 38:12.150] And you can manipulate that object however you want. [38:12.350 --> 38:14.850] You can go in and reformat that output if you found a mistake. [38:14.990 --> 38:16.070] You can go in and edit that kind of stuff. [38:16.290 --> 38:17.770] You can copy it into a data file. [38:17.850 --> 38:19.450] You can use it as input to a second job. [38:19.610 --> 38:19.950] Pass it through. [38:20.050 --> 38:20.950] There's all kinds of stuff. [38:21.170 --> 38:22.370] Or you can simply reroute it. [38:22.430 --> 38:24.350] There are 753 in that particular queue. [38:24.750 --> 38:26.550] You want one to go to a printer. [38:26.730 --> 38:28.010] You go in and select that one and send it. [38:28.050 --> 38:29.050] You want it to go to your printer. [38:29.530 --> 38:31.890] It's in their output queue, but you want it to go to your printer. [38:32.370 --> 38:32.830] You know? [38:33.250 --> 38:33.790] Just saying. [38:36.750 --> 38:38.770] And delete printouts if you want it to really be... [38:38.770 --> 38:40.610] You know, there's a lot of stuff you can do when you get in there. [38:42.130 --> 38:43.810] And this is going to be a video. [38:43.930 --> 38:46.030] Now, this one's kind of long, and I know some of this is dry. [38:46.130 --> 38:47.770] This is the last video like this, I promise. [38:48.070 --> 38:51.750] This is going to do those three screens, those three steps that I just showed you. [38:51.870 --> 38:56.710] It's going to walk you through that input, process, and output on an AS/400 start to finish. [38:59.450 --> 39:10.410] Okay, now, we were just talking about the classic sequence of events that you're taught in even high school or even earlier about basic input, processing, and output. [39:10.610 --> 39:14.090] And the AS/400 is one of the most clear-cut, clean examples of that. [39:14.270 --> 39:16.670] So, I'm going to walk you through that quickly on the AS/400. [39:16.890 --> 39:20.290] Now, to save a little bit of time, I've already gone ahead and typed in some commands. [39:21.130 --> 39:25.650] SBM job, which is submit job, again, the three-letter combinations we talked about earlier. [39:26.350 --> 39:30.610] Submit job command that I've already typed in, and I'll go ahead and prompt it and show you the options. [39:31.090 --> 39:36.830] Basically, what I've done is I've chosen to submit a job, and that job is whatever I put in here. [39:36.830 --> 39:41.990] If I had a program name, I would put the program name in here, whatever parameters the program requires. [39:42.130 --> 39:46.510] Well, I just went ahead and did the display log command, which is just an AS/400 command. [39:47.190 --> 39:53.150] I can prompt it from within this prompted command, because everything is an object, and everything can just go deeper and deeper. [39:54.310 --> 39:57.710] And I didn't really change anything except say that we're going to print this out. [39:58.050 --> 40:00.990] I'm going to print all available current time from the history log. [40:01.410 --> 40:03.830] Now, instead of it going to the screen, I'm going to send it to print. [40:03.830 --> 40:12.650] And this job, this submit job command is going to tell it how to run, where to run, and the details of how and where the output is going to go, et cetera, et cetera. [40:12.970 --> 40:15.210] So I've named it a job called stank test. [40:15.390 --> 40:22.370] We're going to call it stank test, oh, I don't know, five, just for the heck of it, because I've been playing around, and I don't know how many others are out there. [40:22.490 --> 40:23.530] So stank test five. [40:23.990 --> 40:26.470] We're going to submit it into a job queue queue batch. [40:26.850 --> 40:29.470] That's just a default on this particular system. [40:29.470 --> 40:36.130] All systems are going to vary, but queue batch is pretty general and pretty much a standard batch submission job queue. [40:36.650 --> 40:40.950] And it's already set up to feed to a certain subsystem to run as an active job. [40:41.930 --> 40:45.990] Go down a little bit further, and again, you can see how many things are in these prompted commands. [40:46.110 --> 40:47.110] That's just too many to remember. [40:47.750 --> 40:50.870] I did create a special output queue called stank out queue. [40:50.870 --> 40:59.970] I created that earlier to make it easier to find our output when we're over and done with, because output tends to pile up on an AS for 100 and needs a lot of maintenance. [41:00.150 --> 41:04.950] So to make sure we didn't get it lost in a shuffle with thousands of other printouts, we put it in a separate out queue here. [41:05.170 --> 41:07.230] And the only other thing I changed was here. [41:07.390 --> 41:08.490] I'm going to put the job. [41:08.530 --> 41:10.450] I'm going to hold the job in the job queue. [41:10.530 --> 41:11.810] I'm not going to submit it right away. [41:11.970 --> 41:20.330] If I left this to no or to whatever the job default, what job description default is, it would probably have shot off right away and started running immediately. [41:20.330 --> 41:24.030] And it would be done practically by the time I exit it out of this screen. [41:24.030 --> 41:25.130] It's just that fast. [41:25.410 --> 41:30.590] So for demonstration purposes, I'm going to put it on star yes to hold this job when I'm done with it. [41:30.670 --> 41:32.630] So I hit enter to submit that job. [41:33.270 --> 41:44.050] And what you see here is that job gets assigned a number, the name, the user that submitted the job, and the name of the job itself tells you where it was submitted and what library it comes from. [41:44.810 --> 41:47.910] So everything about that job can be found there. [41:48.370 --> 41:52.070] Well, I know that I submitted it to job queue queue batch. [41:52.310 --> 41:55.730] So I'm going to use the command we talked about earlier, and that's work job queue. [41:56.830 --> 42:05.050] And I could type in queue batch to go only to that one, but just to show you, because it's on the first screen, queue batch is right here, and there are two jobs in there. [42:05.170 --> 42:06.730] Probably one where I was playing around earlier. [42:06.730 --> 42:08.570] I'm going to put a five to work with this. [42:09.190 --> 42:11.750] Working with that job queue, I see two things in here. [42:11.910 --> 42:16.670] I'm going to go ahead and end this one that I was playing around with earlier, and confirm that. [42:17.010 --> 42:19.950] And when I hit F5 to refresh the screen, it's gone. [42:20.250 --> 42:26.110] Now this one, I submitted it as held, and you'll see status held right there, which means it did not launch right away. [42:26.350 --> 42:31.690] I can put a six next to this, and the moment I do that, this job is going to launch and begin to execute. [42:32.830 --> 42:34.150] So I've done that now. [42:34.410 --> 42:37.550] Now again, this job is very fast, very, very quick. [42:37.570 --> 42:42.210] But what happens to this job is from the job queue, it goes into active processing. [42:42.650 --> 42:44.330] Now, it's already completed. [42:44.470 --> 42:47.470] Unfortunately, I don't have something handy that can take some time. [42:47.690 --> 42:58.450] But work active job command we talked about earlier, this job would have launched out here somewhere, probably into one of these subsystems, queue batch, which matches the queue batch job queue. [42:58.590 --> 42:59.330] Don't get them confused. [42:59.450 --> 43:00.190] It is a separate area. [43:00.290 --> 43:00.850] This is a subsystem. [43:01.390 --> 43:06.770] And any job submitted will run under queue batch, or whatever the assigned subsystem happens to be. [43:07.330 --> 43:10.010] My interactive job, you see right here, runs under queue enter. [43:10.350 --> 43:23.890] And as long as this job is active, job meaning this program, whether it's my interactive session, which is exactly what this is, or a job that I submitted via batch mode, which I just did a second ago, that job is already shot through the active job screen, [43:23.990 --> 43:25.650] is already sitting on the out queue. [43:26.090 --> 43:29.570] So we are going to do a work out queue, and where did I send it to a moment ago? [43:29.770 --> 43:31.830] Something called stank out queue. [43:32.690 --> 43:37.110] So we are going to go straight there, and you will see that there are some print outs in stank out queue. [43:37.350 --> 43:40.830] Now I am going to go down to the bottom one here, because this is probably the one I just submitted. [43:41.750 --> 43:46.350] Put a 5 next to it, and there is the output from the job that I submitted. [43:46.350 --> 43:49.290] The job, if you remember, was display log. [43:49.290 --> 43:49.670] Kind of looks like output. [43:49.930 --> 43:51.290] And that was the history log. [43:51.430 --> 43:52.870] We saw that earlier on the screen. [43:53.090 --> 43:57.010] Well, this time I submitted it to output to a print out. [43:57.110 --> 43:58.710] For some reason, let's say I wanted to look through it. [43:58.970 --> 44:02.370] A security officer may print this off for whatever reason. [44:02.390 --> 44:06.030] They want to look through it, find somebody who has infiltrated their system, for example. [44:07.490 --> 44:10.610] So anyway, I have printed this off and sent it to this output queue. [44:10.890 --> 44:13.370] Now this output queue, it is sitting there in a ready status. [44:14.610 --> 44:19.190] This output queue that I created, I created it because I have not assigned a printer to it. [44:19.530 --> 44:31.070] I can assign a printer by IP address, by name, set it up in the system, and this could have also immediately fired off and printed off to the local printer in my office if I set it up that way. [44:31.410 --> 44:43.070] Some check writing, if I was writing check programs to print off people's paychecks or purchase orders or something like that, I could send it over to someone else's office by IP address, send it remotely to wherever, and have it print immediately. [44:43.070 --> 44:46.810] Well, that's the reason I created this out queue, because I don't want this to print anywhere. [44:46.950 --> 44:48.090] I don't need this to print anywhere. [44:48.510 --> 45:00.390] So if you are submitting jobs on a system somewhere, be careful that you don't just start throwing things around, and they will automatically print to default settings, and all of a sudden whatever you're working on, prints in the security officer's printer, [45:00.650 --> 45:02.010] you could be in deep trouble. [45:02.010 --> 45:08.370] So what I'm going to do is delete these two printouts, because they were just for demonstrated purpose. [45:08.530 --> 45:10.490] You see that this out queue is now empty again. [45:11.870 --> 45:20.930] But you can look at the work out queue command with no parameters, and just look at all of them, and you can just see all the files that could possibly be backed up. [45:21.830 --> 45:23.310] 82 here, 2 there. [45:23.470 --> 45:26.690] These are all the different printers that are set up within this company. [45:26.690 --> 45:32.790] These are names and queues and writers assigned arbitrarily, whatever naming convention they've decided to use with this system. [45:33.230 --> 45:34.410] 96 here and there. [45:35.010 --> 45:38.830] And you can see that they get caught up in these queues either intentionally or unintentionally. [45:40.470 --> 45:42.750] And AS/400 operators sometimes have to go in. [45:42.810 --> 45:45.310] There could be a paper jam, and they're blocked, backed up. [45:45.850 --> 45:47.190] Printer could have run out of paper. [45:47.390 --> 45:48.910] They may want them saved in here. [45:49.010 --> 45:53.270] This one, for example, is an out queue that has 50 files in it, but there's no writer started. [45:53.490 --> 45:54.570] The writer could have failed. [45:54.630 --> 45:55.910] It could have been any number of reasons. [45:55.910 --> 46:02.590] But some of the best stuff that you may find in here is by scrolling through this output queue and look at something like this. [46:02.750 --> 46:07.630] You have 2,000 jobs in this output queue, 2,500 in this one. [46:08.030 --> 46:10.710] And when you start scrolling through them, look at this. [46:11.070 --> 46:11.550] Beware of blurring here. [46:11.550 --> 46:14.830] I don't know what this is, but if we take a look at this, there's a purchase order. [46:15.910 --> 46:18.390] $150 spent for instructional videotape. [46:19.190 --> 46:20.150] Chainsaw safety. [46:20.670 --> 46:23.270] You find some really fun and interesting stuff in here. [46:23.270 --> 46:24.110] I didn't go looking for it. [46:24.110 --> 46:30.470] And this is something that we really shouldn't, if the system is set up properly, have access to look at something like this. [46:30.510 --> 46:36.110] But here I am looking at thousands of dollars worth of invoices and purchase orders because of the way the system is set up. [46:36.110 --> 46:39.870] So I could scroll down through here and you'll find paycheck information. [46:39.890 --> 46:46.410] You'll find all kinds of interesting stuff that, if this, again, is set up properly, you should never, ever see. [46:46.550 --> 46:51.090] But the majority of the time, you will find that some of the best information, you don't have to... [46:51.090 --> 46:54.450] A lot of the stuff we showed you earlier is great and I hope you understand a lot of it. [46:54.550 --> 46:57.410] But if nothing else, you can get into output queues. [46:57.570 --> 46:59.910] You may find yourself with a wealth of information. [46:59.910 --> 47:01.370] You don't have to submit jobs. [47:01.510 --> 47:08.910] You don't have to write a program or inject a command or anything like that or create any of your own stuff. [47:09.910 --> 47:14.470] Those programs may already be created and all you've got to do is go in there and find that output. [47:14.750 --> 47:17.450] There are checks that are printed and going to a special check printer. [47:17.590 --> 47:19.370] They can have all the security in the world... [47:19.370 --> 47:19.870] I didn't say that. [47:19.890 --> 47:25.370] ...on that printer and they can have stamps and barcodes on it and watermarks and signatures and everything. [47:25.630 --> 47:32.450] But if you can go right here to this output and see exactly what's coming out of it, it kind of defeats the purpose of it. [47:32.450 --> 47:39.250] So anyway, you see three clear levels of input on that job queue when you submit a job. [47:39.470 --> 47:44.070] You see the active job itself with the work active job screen when it runs in a subsystem. [47:44.110 --> 47:52.630] If it's a long-running job, and I've had jobs that run for hours upon hours upon hours, compile stuff like that, that just run hours and hours and you can watch it. [47:52.790 --> 47:56.430] You can see if there are errors or job halts or something like that that you need to answer. [47:56.530 --> 47:58.050] It may have a lock on an object. [47:58.070 --> 48:00.190] You see that in that work active job screen. [48:00.190 --> 48:05.890] And when the job is finished and completed and successfully, it goes to whatever out queue you have set it up to go to. [48:06.110 --> 48:08.250] For my example, I didn't want it to print anywhere. [48:08.250 --> 48:13.050] I just wanted it to sit in a fake out queue so that I could browse it. [48:13.110 --> 48:15.750] If I wanted it to print, I would assign it to a printer, etc. [48:16.050 --> 48:20.190] So you see those three clear delineations of every step of processing. [48:20.410 --> 48:26.350] So when they teach you that in school and when you've seen that in every textbook, there is a reason for it and it makes perfect sense. [48:26.350 --> 48:36.190] And if you do understand where those clear delineations are, you can take advantage of exactly what each one is used for and you can see the holes and the chinks in the armor, so to speak. [48:36.190 --> 48:41.390] So make sure you at least remember that and take that from this presentation, if nothing else. [48:44.510 --> 48:47.130] I don't know who was talking that thing about the checks. [48:47.790 --> 48:48.930] I don't know how that got in there. [48:48.970 --> 48:49.510] I didn't say that. [48:51.130 --> 48:53.690] But that's very, very, very, very true. [48:54.150 --> 48:57.070] I had no idea what I was going to find when I was in there. [48:57.270 --> 49:00.230] I had to blur that out for obvious reasons. [49:00.230 --> 49:02.030] I did not make up. [49:02.170 --> 49:04.870] There was an invoice for a video on chainsaw safety. [49:05.050 --> 49:05.870] And it was $129. [49:06.130 --> 49:07.010] It seemed kind of expensive to me. [49:08.690 --> 49:11.050] But you find weird stuff like that. [49:11.150 --> 49:12.910] That's what you'll stumble across. [49:13.090 --> 49:26.470] The reason I blurted out was not because of the chainsaw, but because also in that data, that again, I'm certain they didn't want me to see, name, address, phone numbers, account numbers, the name of the items, prices. [49:26.470 --> 49:32.310] All of that was in a purchase order sitting in an out queue that I'm certain they don't want people to see. [49:32.650 --> 49:34.670] So, you'll find a lot of good stuff like that. [49:35.010 --> 49:37.630] Now, that's the last video like that, I promise. [49:39.230 --> 49:42.610] I said earlier, I'm going to emphasize this at the end, and I'm going to show you. [49:42.710 --> 49:43.310] Go ahead and play this. [49:43.390 --> 49:49.450] This is demonstrating and showing you that everything I just showed you, that's all well and good. [49:49.530 --> 49:53.350] But everything that you do on the H400 is logged. [49:53.870 --> 49:54.270] Everything. [49:54.270 --> 50:01.250] Look at the precision of how close, .001 seconds, .003 seconds. [50:01.430 --> 50:06.910] You get job numbers, you get the user name, you get the job name, tells you what subsystem it was in. [50:07.070 --> 50:10.570] You see everything that's happened, everybody that's connected to the system. [50:10.970 --> 50:11.910] So, be careful. [50:12.090 --> 50:12.770] Keep that in mind. [50:13.270 --> 50:20.230] Doesn't mean you can go out there, you know, after this presentation and go hacks or the Gibson or whatever, you know, go hacks or the AS/400. [50:20.570 --> 50:22.350] It's not, you're not going to be able to do that. [50:22.470 --> 50:26.910] And up front I said, that's one of the goals is to familiarize you with how this works. [50:27.330 --> 50:32.390] You can go, I was hitting F1 on there as I was joking around, and you can see the detail on that job. [50:32.570 --> 50:35.550] Once you have the job number, see that job number right there? [50:35.710 --> 50:38.090] You can then go into the individual job log. [50:38.230 --> 50:40.570] That was just a history log of who did what, when and where. [50:40.570 --> 50:50.250] You can go to the individual job log, number 10 right there, and you can see everything that happened from that user or by that job. [50:50.570 --> 50:58.550] Everything that you did, and if you kind of see that, that's a job log that I made while generating some of these videos and presentations. [50:58.550 --> 50:59.930] You'll see the commands that I did. [51:00.090 --> 51:05.250] So, every single thing will be found if they go looking for it. [51:06.030 --> 51:07.590] Don't let them get looking for it. [51:08.790 --> 51:12.590] So, yeah, again, this was to familiarize you with it. [51:12.870 --> 51:18.030] And kind of, as a summary here, just say that I wanted you to, A, recognize the system. [51:18.130 --> 51:19.930] You saw the sign-on screen, very distinctive. [51:20.230 --> 51:21.590] Very distinctive sign-on screen. [51:22.530 --> 51:27.670] Menu systems, which, how much is there to understanding a menu, but understand the commands behind them. [51:27.750 --> 51:30.530] Commands are just, or menus are just executing commands. [51:30.710 --> 51:34.750] So understand that and understand that you can go directly to the commands is much better to do that. [51:36.330 --> 51:40.570] To explain the connectivity and the software use, 5250 Telnet Emulation. [51:40.890 --> 51:46.510] Again, I'll be glad to re-give you the URL, but it's SourceForge, tm5250.sourceforge, for the Linux client. [51:46.650 --> 51:47.930] And Windows, just search. [51:48.050 --> 51:50.390] There's a billion of them, and most of them stink. [51:50.650 --> 51:54.150] But batch versus interactive processing. [51:54.550 --> 52:00.550] Like I showed you on the work active job screen, you were seeing menu names that you might write down, you might use later, go nosing into. [52:01.530 --> 52:07.810] You might be able to look at the job log of an interactive job and see what that person is doing live, while they're logged in. [52:08.250 --> 52:10.970] Now, what you saw on the work active job is that snapshot. [52:11.230 --> 52:12.030] What are they doing right then? [52:12.050 --> 52:13.610] You can keep refreshing it and watch it. [52:14.170 --> 52:19.550] If you have access, you can look at the job log and see everything they've been doing, just like I looked in my own historical job log on that. [52:20.290 --> 52:22.350] So, menus and command lines are very important. [52:22.490 --> 52:25.210] And again, everything is logged. [52:25.510 --> 52:26.490] Don't do anything stupid. [52:26.770 --> 52:28.190] You shouldn't be doing anything stupid. [52:28.310 --> 52:30.830] This is about learning the AS/400 and learning how to navigate it. [52:31.030 --> 52:40.410] And hopefully, when you sit down at one of these, after watching this, then you can actually have the skills that they don't teach you in school, that you usually learn on the job. [52:40.490 --> 52:43.790] You can sit down, hopefully, and jump into an AS/400 job. [52:43.790 --> 52:50.770] If somebody asks you to have AS/400 experience, you can sit down and you can confidently say, now, this really is the fundamentals of it. [52:51.090 --> 52:55.010] Even the best people who've been working in AS/400 for years don't memorize all those commands. [52:55.510 --> 53:00.530] And then you prompt each one of them and each command has 50 flags and 50 different things that you can change on it. [53:00.990 --> 53:02.150] Even the best don't know that. [53:02.250 --> 53:04.230] So, you are right there after this presentation. [53:04.610 --> 53:10.350] Really, you know enough fundamentals about the AS/400, probably more so than a lot of people that are professionals in it. [53:10.470 --> 53:12.850] So, that's really all there is to it. [53:13.430 --> 53:19.010] Thank you everybody from FL2600, my local 2600, and 2600 in general for putting this on. [53:19.450 --> 53:22.050] You know, this is a really cool event and it's a lot of trouble. [53:22.250 --> 53:23.910] So, really, I appreciate these guys. [53:24.070 --> 53:25.770] The AV guys, these guys do a lot too. [53:26.390 --> 53:27.610] Volunteers that do all this kind of stuff. [53:28.190 --> 53:30.670] Everybody in the DDP, they know who they are, thanks to them. [53:31.010 --> 53:34.450] Saito, my friend, helped me do a lot of this, the blurring, stuff like that. [53:34.530 --> 53:36.970] Slip mode was up with me, 6 o'clock this morning. [53:37.530 --> 53:40.230] Going through some video editing, stuff like that, not theory. [53:40.970 --> 53:44.510] Epiphany, DJ Sub Zero, these guys show me around New York because I'm a noob to New York. [53:45.690 --> 53:49.690] BinRev.com, support the Binary Revolution magazine, stuff like that. [53:49.750 --> 53:50.270] Go check it out. [53:50.350 --> 53:52.150] We have forums, lots of great information. [53:52.410 --> 53:57.990] All the articles that I've ever published in 2600 are available at that site and lots of other articles from other places. [53:57.990 --> 53:59.770] So, that's really it. [54:00.030 --> 54:07.190] Feel free to contact me, my email address, the websites, and out in the lobby, if you're interested in the magazine, come check it out. [54:07.330 --> 54:08.210] Or come browse through it. [54:08.570 --> 54:09.770] So, thank you very much for your time. [54:09.790 --> 54:10.390] I appreciate it. [54:10.390 --> 54:20.070] Thank you.