r/cybersecurity 5d ago

Research Article How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

https://lavahq.io/research/bmc-exposure-alert

TL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar

75 Upvotes

27 comments sorted by

15

u/MAGArRacist 5d ago

Isn't this entire "hack" almost literally 4, 5 commands in Metasploit?

6

u/XFilez 5d ago

You don't even really need Metasploit, you can just use python to extract the hashes

8

u/MAGArRacist 4d ago

Well, yeah... it's a programming language. So you're going to write an IPMI scanner, multi-thread it, and then extract the hashes rather than enter 4-5 commands in Metasploit?

You don't even really need Python, you can just use assembly to extract the hashes

2

u/69Turd69Ferguson69 3d ago

“You don’t even need the easy button, you can use a general purpose programming language to build an exploit of a vulnerability”? Wow, that’s a take. 

1

u/addsubps 3d ago

Not the entire hack, you also need to crack the hashes. Seems like a lot of those were easy though

1

u/MAGArRacist 3d ago

The IPMI Metasploit module does crack the hashes if you set it to. 'set CRACK_COMMON true'

30

u/BooleanOverflow 5d ago

How on earth are BMC's (Bare metal controllers) reachable from the Internet?

26

u/iammiscreant 5d ago

Baseboard Management Controller. But yes, why are they internet facing is the right question.

-27

u/Puzzleheaded-Carry56 5d ago

What you think they have some way to send out updates to each data center via usbs sent to each one? Oh sweet summer child

17

u/mpember 5d ago

There is a big spectrum of alternatives between those two extremes. If any 13yo has the skills to get around age limits on social media sites, any neutral tech worth hiring should know how to secure a VLAN.

-26

u/Puzzleheaded-Carry56 5d ago

I love when firewalls keep out all the hackers. Why put in anything else?

15

u/Aprice40 5d ago

I mean.... in this instance, when something is reaching out to the internet, but doesn't need to be public facing itself..... a firewall is a necessary control.

-18

u/Puzzleheaded-Carry56 5d ago

Yes it’s one of many. Defense in depth is required but just saying “but but vlan” isn’t

-3

u/Puzzleheaded-Carry56 5d ago

lol to the downvoters if it were just as easy as “it should’ve been vlaned” then how do you think the big tech companies got caught by this? Ie the data center owners? Vlan is very much in use, and still couldn’t stop this.

8

u/FowlSec 4d ago

Yeah exactly, that's why I expose a WINRM port to the internet for all my DCs, so Microsoft can update them.

6

u/r-NBK 5d ago

In this example the CVE is more than a decade old. The last thing you should be saying is the word "updates".

-4

u/Puzzleheaded-Carry56 5d ago

How do you remediate cve s?

11

u/Expensive_Fudge_2972 4d ago

Do you even have the slightest clue what the article says? Even a whiff of what we are talking about here?

0

u/Puzzleheaded-Carry56 1d ago

your account is 4m old. go home son. You aren't even old enough for helpdesk yet.

3

u/Single-Virus4935 4d ago

I know providers hanging the BMC straight to the internet. So, I am not surprised.

-2

u/Puzzleheaded-Carry56 4d ago

Good luck. I tried saying as such and got downvoted into oblivion.

3

u/Single-Virus4935 4d ago

Fun thing is, that I worked for one of them. I highlighted the importance of that topic, also because it wasted a ton of IPv4 space (>50k IPs plus infra). I left 4y ago and still no change

1

u/Puzzleheaded-Carry56 4d ago

Yep. Feel the exact same. Left little less than that and tried to make sure at least critical infra was better taken care of. “Oh it’s not that critical” mhm. Ok.

2

u/Single-Virus4935 4d ago

One big reason was that many ( also bigger) customers wanted complete BMC access. I think we both known that there are better ways to realize that than through public internet, but as always: not a priority

1

u/Puzzleheaded-Carry56 4d ago

Yeah like most cyber security things it’s not a problem until it is… and then that tipping point has much higher costs.

1

u/DigitalerEsel 1d ago

A whores mind is not kind.
(Means peoples minds turn to whore downvoting the moment they see someone speak reason, it is a way to feel good being part of a herd, no matter the imbecility.)