Servers can be backdoored by exploiting buggy motherboard controll

(arstechnica.com)

16 points | by joozio 7 hours ago ago

6 comments

  • sillywalk 5 hours ago ago

    *controllers

    Too bad Oxide's non-BMC[0] service processor or something similar isn't available on all servers.

    [0] https://oxide.computer/faq-friday/is-the-oxide-service-proce...

    • inigyou 4 hours ago ago

      If you just don't plug in the BMC network port, you effectively have this. But people do plug in the BMC network port because it's extremely useful.

  • burnt-resistor 5 hours ago ago

    Reasonable environments don't allow BMC access from the normal LAN, and instead have a protected LAN segment for the BMC's NIC, so the risk typically minimal as it requires breaching a secure control network. It's bad to have insecure hardware, but defense-in-depth and proper network design makes compromise from it much more unlikely.

    • inigyou 3 hours ago ago

      There is a a server I have whose host provides a VPN for customers onto the BMC network. I don't know if they are checking which IP address I access through the VPN, and I don't really want to find out lest I get terminated.

      There's another one from a host that just has it open to the internet. I bet you'd find a bunch by scanning the internet.

    • hollow-moe 3 hours ago ago

      > defense-in-depth and proper network design Damn, we're all doomed then

  • preisschild 4 hours ago ago

    Thats why I just want upstream OpenBMC support and redfish