webterm/3270

3270 · 5250 · SSH

A mainframe terminal, and a security toolkit, in a browser tab.

Point WebTerm/3270 at a host and you get a real green screen: TN3270 and TN3270E for z/OS and VM, TN5250 for IBM i, SSH for everything around them. No emulator to install, no Java, no HOD profile to hand around. The full tier adds passive ESM fingerprinting and a stack of mainframe recon and probe tools, built into the same client.

The WebTerm/3270 client running in a browser tab: session profiles down the left, the PF-key bar across the top, a live TN3270 session on the shipped mock z/OS LPAR sitting at the TSO/E logon panel, and the settings panel open on the right.
The client on the shipped z/OS mock LPAR — TSO/E logon, PF-key bar, session profiles, live OIA.

what it is

One client for the whole IBM stack.

Most shops still run a fat desktop emulator per person, each with its own keyboard map and its own copy of the host list. WebTerm/3270 is that emulator, moved to the server and reached over the web.

Nothing local

The client is a web page. No install, no Java runtime, no per-machine config. Works the same on a locked-down laptop as on your own.

Real datastream

Field attributes, extended colour and highlighting, structured fields, GDDM graphics, the OIA. It renders what the host actually sends, not an approximation.

Shared, not scattered

Session profiles, macros and SSH host lists live with the account. New teammate, one login, same connections.

how a session works

Sign in, pick a host, you're on.

01

Sign in and open the client.
The terminal loads in the tab. Your saved session profiles are already in the list.

02

Choose 3270, 5250 or SSH and connect.
The bridge dials the host, negotiates the protocol, and streams the screen back over one WebSocket. Every connect is written to an audit row.

03

Work the screen.
Full keyboard map with PF and PA keys, record and replay, macros, file transfer. Close the tab when you're done.

security tooling

A mainframe security toolkit, built into the terminal.

The full tier turns the client into an assessment tool. It reads what the host already puts on the wire, runs recon from an ordinary login, and probes where you have permission to, on z/OS, z/VM, CICS, DB2, z/TPF and IBM i.

Authorized use only. Everything below is for systems you own or are explicitly permitted to test. The full tier is gated behind an authorized-use acceptance and a manual account review.

Identify, passively

  • ESM fingerprint. RACF, ACF2 or Top Secret, read off the message-ID prefixes and banners already on screen. Weighted score, evidence trail, sends nothing to the host.
  • Session crypto. TLS version, cipher and certificate per live session; flags plaintext, weak ciphers, self-signed or expired certs, and a missing TN3270E negotiation.
  • Plaintext exposure. An unencrypted session is shown alongside its captured screen bytes, exactly what an on-path attacker sees. IND$FILE transfers are flagged one by one.

Recon from a normal login

  • z/OS, from TSO READY. RACF policy analysis, user and group enumeration, dataset discovery. APF library RACF coverage (LISTAPF + LISTDSD), SYS1.PARMLIB read-access test, DFSMS at-rest encryption audit.
  • IBM i. System values (WRKSYSVAL), user and Q* profiles, object authority, network attributes (DSPNETA: JOBACN(*FILE), DDMACC(*ALL)), job descriptions, authorization lists, active jobs.
  • Subsystems. SDSF STARTED-class profile gaps and DB2 subsystem and authority scanning, both from a READY prompt.

Probe, when you're cleared to

  • Credential probe. A wordlist against TSO, z/VM, CICS, z/TPF and IBM i logon screens, with a per-attempt delay and stop-on-match or keep-going.
  • CICS transaction scan. DFHAC2001 "not authorized" confirms a transaction is defined, even when you can't run it.
  • Protocol fuzzer. Mutated 3270 AID records, host responses classified as screen, no-response or disconnect.

Datastream-level exposure

  • Field-length disclosure. The MDT and buffer-address deltas reveal how many characters went into a masked nondisplay field, even though the characters stay hidden.
  • Cross-session buffer bleed. A pooled LU's controller buffer surviving into the next session before the fresh Erase/Write.
  • VM minidisk password. A LINK password typed at the CP READ prompt renders in cleartext, CP has no masked input for command arguments.

Drive it from an AI assistant. The same tooling is exposed as an MCP server, sixteen tools over the bridge's WebSocket, so an assistant can connect, read screens and field maps, send keys, run macros headless, and pull the ESM fingerprint. v1 is loopback-trust.

tiers

Three tiers, same client.

Every tier is the full terminal. What changes is what you can point it at and which tooling comes with it. Current pricing shows when you create an account.

Base The terminal client.
  • 3270, 5250 and SSH to any host you can reach
  • Session profiles, macros, record & replay
  • Per-account isolation and connection audit
Training Base, plus practice systems.
  • Everything in Base
  • Shipped mock LPARs: z/OS, TSO/ISPF, CICS, DB2, IBM i
  • A place to learn the keys without touching production
Full Training, plus the security toolkit.
  • Everything in Training
  • Passive ESM fingerprint and session-crypto analysis
  • RACF / IBM i recon, credential and CICS probes, protocol fuzzer
  • Datastream exposure checks and the MCP tool surface

Authorized use only. Gated behind an acceptance and manual review.

who runs it

A small US company.

WebTerm/3270 is built and operated by Two Women and an Acre LLC.

It does one job and is kept deliberately small. Support is a person answering email, not a ticket queue, and the people who answer are the people who wrote it.

questions

Before you sign up.

What do I need to install?

Nothing. WebTerm/3270 runs in the browser. There is no desktop emulator, no Java runtime, and no HOD or PCOMM-style local configuration. You sign in and the session opens in a tab.

Which protocols does it speak?

TN3270 and TN3270E for z/OS and VM, TN5250 for IBM i, and SSH for the surrounding Linux and USS work. One client, one keyboard map, all three.

Can it reach a mainframe on a private network?

The hosted service can reach any internet-facing host. A private, on-premise system needs a connector running inside your own network, which is on the roadmap. Systems with a public endpoint work today.

What security tooling does the full tier include?

Passive ESM fingerprinting and session-crypto analysis; RACF policy, user, group and dataset recon from a TSO READY prompt; APF library and SYS1.PARMLIB exposure checks; a full IBM i assessment across system values, profiles, object authority, network attributes and authorization lists; a credential probe and a CICS transaction scanner; a 3270 protocol fuzzer; datastream checks for field-length disclosure, cross-session buffer bleed and VM minidisk password exposure; and an MCP surface so an AI assistant can drive it.

Is the security tooling legal to use?

It is for testing systems you own or are explicitly authorized to test. The full tier is gated behind an authorized-use acceptance and a manual account review, every connection the service makes is written to an append-only audit row with the account, client IP and target, and using it against a system without authorization is a misuse of the service.

Who is behind it?

WebTerm/3270 is operated by Two Women and an Acre LLC, a small US company. Support is a real person answering email.

Open a session in about a minute.

Create an account