Feeds

32,000 motherboards spit passwords in CLEARTEXT!

Supermicro's cure wasn't much better than the disease

Choosing a cloud hosting partner with confidence

Thousands of Supermicro baseboard management controllers (BMCs) continue to spit administrator passwords in cleartext after a patch described as unsuitable was not applied by admins.

Accessing the machines could be dead simple for the tech savvy; vulnerable boxes would pop during a net or Shodan scan for port 49152. Any of the roughly 3296 exposed BMCs could be accessed with the hardware's default password. The world's worst access code – "password" – would grant access to plenty of others.

Baseboard management controllers were an element of motherboards that were the central component of Intelligent Platform Management Interfaces (IPMI) which provided remote access over UDP to sysadmins for physical state monitoring of machine fleets. Late last year, HD Moore of metasploit fame warned that Supermicro had a problem. Fixes seem not to have been very effective, leaving Carinet Security Incident Response Team security engineer Zachary Wikholm "blown away" by the Supermicro flaw.

"This means at the point of this writing, there are 31,964 systems that have their passwords available on the open market, Wikholm wrote on web host Carinet's security incident response team blog.

The bungle was noted by Tony Carothers of the SANS Internet Storm Centre which verified the flaw.

"The vulnerability involves a plaintext password file available for download simply by connecting to the specific port, 49152," Carothers said in a handlers' note.

"One of our team has tested this vulnerability, and it works like a champ, so let’s add another log to the fire and spread the good word."

Admins would need reflash their systems with a new IPMI BIOS issued by Supermicro as a fix, but this was not possible for some admins, Wikholm said. He offered an alternative work-around that he said did the trick for those unable to reflash.

The Shodan scan run by the sites proprietor John Matherly returned 9.8 million replies for HTTP GET requests from a scattering of devices running on port 49152, many of which ran embedded Linux platforms and broadcasted their kernel and hardware architectures.

Some 6.4 million of these were AT&T U-Verse web media boxes and did not spew critical data.

For the Supermicro controller subset, information on kernel versions could be matched against Shodan to help identify embedded host information.

Many of the total pool ran old Linux kernel versions: 23,380 operated on 2.4.31.x, 112,883 on 2.4.30.x kernel, and 710,046 systems maintained 2.4.19.x.

The news follows revelations last week that 207,000 BMCs exposed to the public internet could be exploited via a handful of basic configuration and protocol weaknesses.

Access to BMCs permitted attackers to compromise the host server as well as other BMCs within its management group which shared common passwords, the researchers said at the time. ®

Security for virtualized datacentres

More from The Register

next story
It's Big, it's Blue... it's simply FABLESS! IBM's chip-free future
Or why the reversal of globalisation ain't gonna 'appen
'Hmm, why CAN'T I run a water pipe through that rack of media servers?'
Leaving Las Vegas for Armenia kludging and Dubai dune bashing
Bitcasa bins $10-a-month Infinite storage offer
Firm cites 'low demand' plus 'abusers'
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
Pssst. Want to buy a timeshare in the clouds?
The Google dilemma — controller or spreader of knowledge?
CAGE MATCH: Microsoft, Dell open co-located bit barns in Oz
Whole new species of XaaS spawning in the antipodes
Microsoft and Dell’s cloud in a box: Instant Azure for the data centre
A less painful way to run Microsoft’s private cloud
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.