4 ms·
Some cloud providers got this right; some didn't exactly... Had a few Hetzner baremetal dell servers with iDrac/IPMI exposed to the world. It did have a good
by damm 8y ago
Some cloud providers got this right; some didn't exactly...
Had a few Hetzner baremetal dell servers with iDrac/IPMI exposed to the world. It did have a good password.
Softlayer/IBM makes me login to a VPN to get into IPMI
(at least for me)
Exposing IPMI on the internet is stupid easy; just as it is stupid. It's the lazyness of hey I need to be able to get into the KVM console and i'm working at home today...
For example.
- toast0 8y agoYou can hit the Softlayer IPMI from the private network on your other servers (which is way more convenient than the VPN, but also a little scary). Also, off topic, ipmitool pretty much works, including serial over lan if you configure your host os properly. After I got that setup, I can usually avoid the java ipmi viewer!
- vetrom 8y agoThe article does a poor job of explaining the threat model, but I think you hit on the exact problem here. OOB baseboard management should not have direct access to other OOB management nodes, lest you invite that as an attack vector. Unfortunately I'm going to bet a notable amount of networks conflate say routing layer and OOB management traffic and don't segregate the two (where often routing protocols need to cross communicate but OOB baseboard management does not.)