3 ms·
Yeah they are utter garbage. For years you had to use Java 6 with absolutely every modern security measure turned off in both the JVM runtime itself and your br
by jdwithit 3y ago
Yeah they are utter garbage. For years you had to use Java 6 with absolutely every modern security measure turned off in both the JVM runtime itself and your browser to access Dell DRACs. Accept expired certs, run unsigned code, I'm sure this is all fine ...
I mostly work in the cloud now but when I last had to manage a bunch of physical machines we had a physically separate network accessed via its own VPN to get onto the BMCs. Because yeah, the security situation was a joke.
- hsbauauvhabzb 3y agoI found that if you leave your bmc unplugged on a super micro, it’ll conveniently bridge it to whatever other Ethernet is plugged in, meaning an outage of your management network may roll over to another network unintentionally. Id put money on there being preauth vulnerabilities in those things, judging by the engineering quality.
- neilv 3y agoThat sounds like showstopper for many sites. On a much less-important note, it might explain some weirdness I'm seeing lately with one of my home Supermicro servers. (The docs say the BMC should only listen on one port, but the switch still sees some degree of responsiveness on the normal non-management port when "off".)
- tryauuum 3y agoI believe you can override this behavior in BMC settings