- Apr 25, 2013
- 5,354
Thousands of Supermicro baseboard management controllers (BMCs) continue to spit administrator passwords in cleartext after a patch described as unsuitable was not applied.
Accessing the machines could be dead simple for the tech savvy; vulnerable boxes would pop during a net or Shodan scan for port 49152. Any of the roughly 3296 exposed BMCs could be accessed with the hardware's default password. The worlds' worst access code - 'password' - would grant access to plenty of others.
Baseboard management controllers were an element of motherboards that were the central component of Intelligent Platform Management Interfaces (IPMI) which provided remote access over UDP to sysadmins for physical state monitoring of machine fleets. Late last year, HD Moore of metasploit fame warned that Supermicro had a problem. Fixes seem not to have been very effective, leaving Carinet Security Incident Response Team security engineer Zachary Wikholm "blown away" by the Supermicro flaw.
"This means at the point of this writing, there are 31,964 systems that have their passwords available on the open market, Wikholm wrote on web host Carinet's security incident response team blog.
The bungle was noted by Tony Carothers of the SANS Internet Storm Centre which verified the flaw.
"The vulnerability involves a plaintext password file available for download simply by connecting to the specific port, 49152," Carothers said in a handlers' note.
"One of our team has tested this vulnerability, and it works like a champ, so let’s add another log to the fire and spread the good word."
Admins would need reflash their systems with a new IPMI BIOS issued by Supermicro as a fix, but this was not possible for some admins, Wikholm said. He offered an alternative work-around that he said did the trick for those unable to reflash.
Full Article
Accessing the machines could be dead simple for the tech savvy; vulnerable boxes would pop during a net or Shodan scan for port 49152. Any of the roughly 3296 exposed BMCs could be accessed with the hardware's default password. The worlds' worst access code - 'password' - would grant access to plenty of others.
Baseboard management controllers were an element of motherboards that were the central component of Intelligent Platform Management Interfaces (IPMI) which provided remote access over UDP to sysadmins for physical state monitoring of machine fleets. Late last year, HD Moore of metasploit fame warned that Supermicro had a problem. Fixes seem not to have been very effective, leaving Carinet Security Incident Response Team security engineer Zachary Wikholm "blown away" by the Supermicro flaw.
"This means at the point of this writing, there are 31,964 systems that have their passwords available on the open market, Wikholm wrote on web host Carinet's security incident response team blog.
The bungle was noted by Tony Carothers of the SANS Internet Storm Centre which verified the flaw.
"The vulnerability involves a plaintext password file available for download simply by connecting to the specific port, 49152," Carothers said in a handlers' note.
"One of our team has tested this vulnerability, and it works like a champ, so let’s add another log to the fire and spread the good word."
Admins would need reflash their systems with a new IPMI BIOS issued by Supermicro as a fix, but this was not possible for some admins, Wikholm said. He offered an alternative work-around that he said did the trick for those unable to reflash.
Full Article