4 ms·
I've worked in a dozen or so Fortune 500 companies IT departments and I've never seen any incompetent enough to connect a BMC/management network to any type of
by illumin8 8y ago
I've worked in a dozen or so Fortune 500 companies IT departments and I've never seen any incompetent enough to connect a BMC/management network to any type of Internet connected firewall, router, or egress gateway.
I've seen many that use flat management networks, which is a bad security practice, but connecting it to the Internet would require a new level of stupidity.
- greglindahl 8y agoSure, I've always segregated BMC dedicated ports to a non-connected network. But the BMC can also talk on the regular ethernet ports whenever it feels like it.
- angry_octet 8y agoIt can usually only vampire onto the first ethernet port. Depends on the motherboard, whether both ports are e.g. Intel, or one Intel, the other something else. Also, usually only 1000base-T not 10G.
- yellowapple 8y agoI'm sure even 10baseT is more than enough to phone home.
- angry_octet 8y agoThe 1000base-T ports are often not connected to the production network, only the 10G.
- angry_octet 8y agoFFS downvote if I call you a Trumptard, but don't downvote if I'm right. Page 1-4: https://www.supermicro.com/manuals/other/IPMI_Users_Guide.pdf https://www.supermicro.com/manuals/other/IPMI_Users_Guide.pd...
- dsl 8y agoThe IPMI module can do DMA. It would be trivial to shim into the running kernel and talk to any interface the host has.
- angry_octet 8y agoBut that means the implant has to be active on every server, actively patching the kernel (and how long would that patch work with kernel changes). It would cause bugs, and be likely to be discovered. Maybe an option on a specific machine that you knew was being used by the target.
- amluto 8y agoIf someone compromises even a single internet-connected machine and can use it to compromise its own BMC, the BMC network is now internet-connected.
- angry_octet 8y agoCompetent network security groups will configure the management network VLAN with filters that only allow traffic to/from the switchport & IP range of the management servers, i.e. no inter-machine traffic on the mgmt vlan. Good shops will also disable all IPMI port traffic (623) on general vlans, as part of wider edge filtering (no egress of 1-1024, with exceptions for specific mgmt protocols like remote assistance, but only from specific origins). In summary, BMC has long been considered a potential backdoor and been severely restricted for a decade. It is certainly one of the least interesting things you could choose to compromise if you were building a motherboard implant. More interesting things would include: RF antennas built into the PCB or ethernet PHY, but with plausible deniability, i.e. could be parasitic.
- EB66 8y agoI've worked with mostly smaller to mid-size companies and they often connect the dedicated BMC ethernet port to a network that is firewalled but still has egress connectivity. That's why I disagree with the author's assertion that this type of attack vector is completely implausible. It's entirely plausible if the network operator has not firewalled egress connectivity.