![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Registered User
Industry Role:
Join Date: Jan 2011
Posts: 84
|
Supermicro IPMI exploit - still vulnerable
An exploit against Supermicro IPMI that allows pulling a plain text list of users and passwords using a simple Get command to a specific port from back in November 2013 was not actually fixed in the firmware updates supplied by Supermicro, apparently.
http://arstechnica.com/security/2014...dvisory-warns/ There are a couple of more effective options for your server admins that are not being discussed: 1. Limit IPMI connections to specific IPs 2. Put IPMI behind a VPN / firewall. 3. Disable Telnet connections. I've only seen one datacenter post an advisory on this and their solution is to helpfully null route your IPMI connection IPs. ![]()
__________________
-= Software / Systems Architect and Server Geek =- |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Industry Role:
Join Date: Sep 2007
Location: Los Angeles
Posts: 2,706
|
Here is a detailed explanation and tips: http://blog.quadranet.com/supermicro...in-plain-text/
They are nullrouting temporarily and also filtering the effected port at their border routers to limit the effect as best as possible. Users (idiots) all over the Internet however have had their hard drives WIPED, DATA STOLEN, and more however. I know first hand people who have had multiple servers wiped (and who knows what else with the data before being wiped), all because they wanted and whined about having their IPMI on public IP addresses. The real solution is upgrading your firmware AND moving IPMI _OFF_ public access internet. Only newbs want their IPMI on public, and only newb companys dont have a VPN tunnel service to the IPMI so its fully secure. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 | |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
Confirmed User
Industry Role:
Join Date: Sep 2007
Location: Los Angeles
Posts: 2,706
|
Quote:
I just looked up the IP of addtrades.com and yeah, I agree with your thoughts on them ![]() I know who they are ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |