4 ms·
This is a little bit overblown--the security failings are unfortunate but not surprising and realistically it's on a separate physical port for a reason. Have
by bcoates 11y ago
This is a little bit overblown--the security failings are unfortunate but not surprising and realistically it's on a separate physical port for a reason.
Have an administrative VLAN for your physical box control plane and maintain physical-level control of the ports with access to it and you're way ahead of the game. Treat it like you would an unauthenticated KVM-over-IP device because that's pretty much what it is. (you should change away from the default username/password, but if you're horrified about the idea of not doing that, evaluate why because that's the real issue)
That said, 300k IPMI devices on the public Internet is a travesty. Don't be one of those guys.
- citrin_ru 11y agoDedicated port/VLAN is must have for servers with own network infrastructure. But if you use dedicated hosting service with network infrastructure provided by hosting provider exposing IPMI IP to public Internet usually is only option (besides disabling IPMI and leaving server unmanageable).
- dredmorbius 11y agoBastion hosts are your alternative.
- skuhn 11y agoIt's pretty telling that 20% of the public IPMI hosts are Supermicro. I suspect that a lot of that is completely unintentional. Supermicro has a completely brain dead default behavior, where if you connect power to the machine and the management Ethernet port doesn't have a link, it migrates the IPMI interface to the first host Ethernet port. You can only fix this by power cycling the BMC. Since it will just ask DHCP for an IP address and might wind up on the production VLAN, bad things can happen in environments that aren't prepared for that.
- bcoates 11y agoWow. That's bad. I did not know that, thanks.