E-Ink News Daily

Back to list

The Cipher Behind QSYRUPWD: Reconstructing IBM i Password Hashes

This article analyzes the QSYRUPWD API on IBM i systems and reveals discrepancies between its output and John the Ripper's password cracking formats for modern password levels (2–4). It highlights how IBM's transition from DES to SHA-1 and PBKDF2-based hashing affects compatibility with existing tools, posing challenges for penetration testers and security researchers.

Background

IBM i is a long-standing enterprise platform used in critical business applications, with evolving password security mechanisms over time. The QSYRUPWD API allows authorized retrieval of encrypted password data, but its implementation has introduced complexities for external security tools.

Source
Lobsters
Published
Jul 29, 2026 at 03:13 AM
Score
7.0 / 10