Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
DEAL: For $25 - Add A Second Phone Number To Your Smartphone for life! Use promo code SLASHDOT25. Also, Slashdot's Facebook page has a chat bot now. Message it for stories and more. Check out the new SourceForge HTML5 internet speed test! ×

Submission + - Vulnerabilities in IPMI, BMCs Put Servers at Risk (threatpost.com)

msm1267 writes: Baseboard management controllers, embedded computers present in most servers, are vulnerable to a half dozen critical vulnerabilities that could enable an attacker to gain remote control over the host machine.

The vulnerabilities are in the Intelligent Platform Management Interface (IPMI) protocol specification that describes how BMCs communicate locally and across networks. The issues range from the ability to bypass authentication mechanisms, steal password hashes that can be brute-forced offline, to UPnP-based vulnerabilities that cannot be disabled and could lead to remote root compromises.

Dan Farmer, creator of the SATAN vulnerability scanner, discovered the vulnerabilities while conducting research under a DARPA Cyber Fast Track grant that was completed in January. Metasploit creator and Rapid7 CSO HD Moore then collaborated with Farmer by conducting an Internet-wide scan of the IPMI protocol to discover the breadth of the issue.

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Vulnerabilities in IPMI, BMCs Put Servers at Risk

Comments Filter:

The only possible interpretation of any research whatever in the `social sciences' is: some do, some don't. -- Ernest Rutherford

Working...