3 ms·
It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then thr
by rphlx 8y ago
It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack.
And I believe that once you control the BIOS image you control the boot chain of trust.
- etcet 8y agoYou can update the BIOS via SuperMicro's IPMI. It's actually a feature you have to pay extra for: https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/SMBU.png https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/S...
- dboreham 8y agoGetting them to take your money in exchange for that utility turns out to be hard. I seem to recall figuring out a way to work around the lack of it, but details have been paved out. I think it involved building the OS-based BIOS flashing tool from source.
- dboreham 8y agoYou can flash the BIOS from BMC on some SuperMicro motherboards. But wait..you can flash the bios from the OS on many machines so why is this a new more dangerous attack vector? Because SM can sign their own BIOS image?