Logo Background

» 2014 » June » 20

  • Supermicro Fails At IPMI, Leaks Admin Passwords
    By on June 20, 2014 | Comments Off  Comments


    drinkypoo writes: Zachary Wikholm of Security Incident Response Team (CARISIRT) has publicly announced a serious failure in IPMI BMC (management controller) security on at least 31,964 public-facing systems with motherboards made by SuperMicro: “Supermicro had created the password file PSBlock in plain text and left it open to the world on port 49152.” These BMCs are running Linux 2.6.17 on a Nuvoton WPCM450 chip. An exploit will be rolled into metasploit (more…)