5 ms·
Sounds like an iDRAC exploit (assuming Dell servers). But, yes, remote management is pretty common in datacenters. The fact that NordVPN wasn't aware of them j
by CiPHPerCoder 7y ago
Sounds like an iDRAC exploit (assuming Dell servers).
But, yes, remote management is pretty common in datacenters. The fact that NordVPN wasn't aware of them just shows incompetence.
- lucb1e 7y agoDepends on what kind. In case of idrac, yes; but it's weird that it was insecure by default in the first place. Usually credentials are configured and provided to the customer. Makes me think there might have been some other interface. Clarification is definitely needed.
- CiPHPerCoder 7y agoIt could have been something like https://www.zdnet.com/article/vulnerabilities-found-in-the-remote-management-interface-of-supermicro-servers https://www.zdnet.com/article/vulnerabilities-found-in-the-r... There were many IPMI/iDRAC/etc. exploits published in the past few years. Throw a dart at a list of them, and you'll probably find one that was unpatched in most systems as of March 2018.
- LennyWhiteJr 7y agoHow the hell do you pwn a server with iDRAC?
- berbec 7y agoIn certain configurations, iDRAC gives you an rdp connection. If idrac is left at default, windows admin login not being changed isn't too much of a stretch.
- zeta0134 7y agoIf you can reboot it without anyone noticing? Really, really easily: iDRAC gives you access to the local console, like a remote KVM. Reboot into single user mode, change a password, done.
- notyourday 7y agoOh, IPMI and friends are a total mess. Some implementations allow one to take control of a running server remotely especially if they use a shared ethernet for management ( popular in supermicros ). I once had our security geek demonstrate it by taking over the running server, rebooting it using network emulated USB stick, adding a file into /etc and rebooting the server again. In secure environments one pulls IPMI module from the server or only uses the modules that have their own dedicated NICs that have to be wired to their own management network.
- tonyarkles 7y agoThe first time I booted a server using a virtual CD-ROM (iso on my laptop shows up as a hardware CD-ROM on the server) over IPMI I was simultaneously relieved (because I could fix the machine remotely) and absolutely totally horrified.
- kevin_b_er 7y agoiDRAC is a full onboard whitehat rootkit manufactured and supported by Dell. It runs independently of any OS and has control over the system. It is intended to be a substitute for physical access.
- luch 7y agoiDrac have a default password : https://danblee.com/dell-idrac-default-username-and-password/ https://danblee.com/dell-idrac-default-username-and-password... There also quite a number of sysadmins that connect idrac's to the "regular" network, instead of the sysadmin VLAN ...
- _wldu 7y agoUser root, password calvin. That's the default. And, if I had a dime for every time I've seen one of these in a data center, I'd be a rich man. I have literally begged sys admins to change the default password, but they say, "Why... we're behind a firewall using RFC 1918 addresses. No one can get to these." The rest, as they say, is history.
- WrtCdEvrydy 7y ago> we're behind a firewall This is the dumbest thing I've ever seen... unless your firewall is between your host versus every other host and there's no multi-tenancy, this will suck.
- allset_ 7y agoIn well maintained networks the management interface (IDRAC, etc.) for each server is placed on a separate VLAN which the servers cannot access. This isn't to say that cheap providers actually do this, or that the VLAN can't be accessed by a compromised technician's workstation/laptop.
- fulafel 7y agoSo it's a fail-open design, given the rarity of well maintained networks, and the lability and inobservability of said state. Never trust the network.
- jeltz 7y agoYes, this kind of firewall is always supposed to be between the management hosts and everything else. Only the sysadmins at the data center a very limited set of applications is supposed to be able to access it. The very real risk is misconfiguration.
- pm7 7y agoHPE iLO also had critical vulnerability: CVE-2017-12542.
- ryanlol 7y agoI’d guess that the DC got owned, no need for iDRAC exploits when lazy VPN company staff never changed the pws.
- atmosx 7y agoPointing fingers without having the details at hand is not competent either.