Thousands of servers can be backdoored by exploiting buggy motherboard controllers

2. A failure of IPMI to enforce integrity and encryption protections in-session. “The device decides whether to authenticate and decrypt each packet from that attacker’s own header, and not from the algorithms the session negotiated, so an unsigned, unencrypted command is accepted on a secured session,” Moore said. A proof-of-concept exploit Moore developed uses such bugs to “chain otherwise-unexploitable issues into full sessions.” Affected vendors include HPE, Supermicro, and Intel (legacy).

3. Predictable session identifiers. Session tokens are generated from counters or from a clock rather than secure random sources. This allows an attacker to predict and take over another user’s live BMC session across both the IPMI service

→ Continue reading at Ars Technica

Share article

All Categories