4 ms·
Are there any resources that talk about the specific concerns of the bmc having outbound Internet access?
by BuildTheRobots 4y ago
Are there any resources that talk about the specific concerns of the bmc having outbound Internet access?
- infotogivenm 4y agoIt is general advice across most server application deployments to limit internet egress (see for example NIST NIST SP 800-190, section 4.4.2 “Unbounded network access from containers”) . A machine that can talk out to the internet usually provides an attacker more avenues to compromise it and control/exfiltrate data from it post-compromise. A classic example is a SSRF bug, like how the recent log4j/log4shell bug used an attacked-instigated outbound LDAP call to a malicious internet host to achieve RCE.
- toast0 4y agoYou remember those Bloomberg articles about SuperMicro servers being bugged? The details they came up with for how the bugs were inserted were kind of out there, but the scenarios for what could be done line up with a compromised BMC. If you assume something will get remote execution on your BMC, it's likely going to get full access to the BMC, because no updates. Then, what does your BMC have access to? DMA to the host, ability to monitor and trigger lots of exciting things, etc. It's pretty scary if you think about it, but IPMI replaces serial concentrators and remote access PDUs with zero rack space and not much security, so yay?
- rcxdude 4y agoBut if the BMC is compromised, then basically all the protections you put in place to seperate its connection from the host are useless anyway, since the BMC can easily masquerade as the host. I can see why it's a good idea to restrict access to the BMC itself, since it's a likely quite soft target for exploits, but once it's exploited, there's not really much benefit to restrictions which target the BMC specifically.
- toast0 4y agoIf you can restrict access to the BMC before it's comrpomised, you might have a chance at a secure environment... You definitely want it to always use its dedicated port, preferably with no factory way to use the host nics (although, once it gets compromised, dma says it can use the host nic if it's sneaky)