5 ms·
> That first part starting with “telling the device…” is nonsensical. If you are in the industry or read our Basic BMC and IPMI Management Security Practices pi
by EB66 8y ago
> That first part starting with “telling the device…” is nonsensical. If you are in the industry or read our Basic BMC and IPMI Management Security Practices piece, you would know that this is false.
Based on my experience in the industry, I'd say this isn't quite accurate.
Yes, the author is correct in his assertion that BMCs are typically provisioned on private networks that are only accessible to outside users via a VPN. He is also correct that you cannot "tell" the BMC to do anything without access to that private network.
However, the author assumes that the operator has disabled egress connectivity on the private network setup for OOB BMC access. In reality, that happens less often than you'd think. Many firewalls by default do not block egress requests and without egress filtering, the BMC can still make outbound requests to the public world. A compromised BMC could easily "phone home" and receive instructions from a command and control server.
- illumin8 8y agoI've worked in a dozen or so Fortune 500 companies IT departments and I've never seen any incompetent enough to connect a BMC/management network to any type of Internet connected firewall, router, or egress gateway. I've seen many that use flat management networks, which is a bad security practice, but connecting it to the Internet would require a new level of stupidity.
- greglindahl 8y agoSure, I've always segregated BMC dedicated ports to a non-connected network. But the BMC can also talk on the regular ethernet ports whenever it feels like it.
- angry_octet 8y agoIt can usually only vampire onto the first ethernet port. Depends on the motherboard, whether both ports are e.g. Intel, or one Intel, the other something else. Also, usually only 1000base-T not 10G.
- yellowapple 8y agoI'm sure even 10baseT is more than enough to phone home.
- angry_octet 8y agoThe 1000base-T ports are often not connected to the production network, only the 10G.
- angry_octet 8y agoFFS downvote if I call you a Trumptard, but don't downvote if I'm right. Page 1-4: https://www.supermicro.com/manuals/other/IPMI_Users_Guide.pdf https://www.supermicro.com/manuals/other/IPMI_Users_Guide.pd...
- dsl 8y agoThe IPMI module can do DMA. It would be trivial to shim into the running kernel and talk to any interface the host has.
- angry_octet 8y agoBut that means the implant has to be active on every server, actively patching the kernel (and how long would that patch work with kernel changes). It would cause bugs, and be likely to be discovered. Maybe an option on a specific machine that you knew was being used by the target.
- amluto 8y agoIf someone compromises even a single internet-connected machine and can use it to compromise its own BMC, the BMC network is now internet-connected.
- angry_octet 8y agoCompetent network security groups will configure the management network VLAN with filters that only allow traffic to/from the switchport & IP range of the management servers, i.e. no inter-machine traffic on the mgmt vlan. Good shops will also disable all IPMI port traffic (623) on general vlans, as part of wider edge filtering (no egress of 1-1024, with exceptions for specific mgmt protocols like remote assistance, but only from specific origins). In summary, BMC has long been considered a potential backdoor and been severely restricted for a decade. It is certainly one of the least interesting things you could choose to compromise if you were building a motherboard implant. More interesting things would include: RF antennas built into the PCB or ethernet PHY, but with plausible deniability, i.e. could be parasitic.
- EB66 8y agoI've worked with mostly smaller to mid-size companies and they often connect the dedicated BMC ethernet port to a network that is firewalled but still has egress connectivity. That's why I disagree with the author's assertion that this type of attack vector is completely implausible. It's entirely plausible if the network operator has not firewalled egress connectivity.
- pronoiac 8y agoI think you might be confusing, say, an intranet at work, with how servers should be set up. My workstation should have pretty broad network access. Servers, largely, shouldn't, unless they have a specific reason for it, and in my experience they'll be blocked from the internet at large.
- EB66 8y agoNope, I'm talking about the dedicated ethernet port used for BMC access on a server. You would be surprised how often those BMC ethernet ports are connected to networks that are behind firewalls, but still have egress connectivity to the public Internet.
- bigp3t3 8y agoDell servers with iDRAC(Dell's brand of BMC management) support online updates via https /ftp. Ours are firewalled but I've seen many that aren't.
- angry_octet 8y agoThat is truly ghastly. Dell (and others) keep adding this kind of rubbish and don't seem to pay a penalty for it -- presumably because medium/large corporate customers (not cloud scale) keep asking for it? For HP iLO you have to pay for Advanced Premium Security Edition to get security features like firmware validation. You have to manage a fleet of licence entitlements otherwise your security stops working. Just managing that much licencing is a full time job. iLO also has user scripts that can be downloaded to the controller -- what could go wrong ¯\_(ツ)_/¯. Lots of hardcoded credentials in the example scripts. It does at least have https, but managing the certificates is another big job.
- detaro 8y agoAlso, it's quite common that the BMC has a dedicated NIC, but also can use the main system NICs alternatively. A competent admin will turn that off (or not enable it, not sure what the defaults are), but why would code that has infected the BMC respect that setting? I don't see how it is enforced in a way the BMC can't circumvent.
- dsl 8y agoPeople also assume just because the management network is isolated, that attackers can't get to it. The Snodwen leaks showed us that NSA uses radio transmitters to jump to hosts that relay packets to and from the network. Someone with the sophistication to drop a chip onto a motherboard during manufacturing (which I don't doubt) and get it to the right customer could most likely slip a more advanced implant to bridge networks into a workstation headed to the NOC.
- quickben 8y ago"Based on my experience in the industry, I'd say this isn't quite accurate." I am genuinely curious, development or non development?
- EB66 8y agoIn this capacity, network engineering and operations -- mostly non-development. But you don't need to be a network engineer to observe these problems out in the wild. Have you ever bought a dedicated server from a small ISP, asked for IPMI connectivity and they replied with a public IP address? Or the BMC was able to mount ISOs hosted externally on public shares?
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]