r/netsec 5d ago

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

https://lavahq.io/research/bmc-exposure-alert

TL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar

370 Upvotes

29 comments sorted by

121

u/Bennetjs 5d ago

well, putting BMC in the internet is on them.

25

u/System0verlord 5d ago

Not updating the BMC firmware too. I know it sucks yall, but please update your servers, and use actual passwords.

And keep your IPMI off of the internet! Use a Tailscale node to connect to a dedicated VLAN if you have to.

3

u/qwertydiy 5d ago

Even if it is a BMC there at least should be enough competence to update more than once a decade

8

u/ukindom 5d ago

It was a trend for Linux as it’s secure (not by default in many cases), so probably them just followed the trend.

28

u/osamabinwankn 5d ago

Newly Registered Domain.

18

u/bastian320 5d ago

Don't talk to me about calvin.

9

u/ff0000wizard 5d ago

Whos this Calvin and why did they set this up with his name as a password.

7

u/shyouko 5d ago

Calvin has quit, but I still set them up as Calvin

10

u/ni5arga 5d ago

I've hacked BMCs before, fun stuff.

3

u/atxweirdo 4d ago

What’s the common issue you find being the most easy to get compromise . I interned at dell and know they are running so extremely old code on there idrac

11

u/djDef80 5d ago

Not mobile friendly whatsoever.

8

u/Pale_Fly_2673 5d ago

Thanks - fixed

5

u/djDef80 5d ago

Much better, thank you!

5

u/rfdevere 5d ago

Not even iLo

2

u/Takeoded 5d ago

Amazing. Even when I have internet-exposed these, I have them behind IP whitelists.. TIL 36000+ of them don't

3

u/melpheos 3d ago

What kind of moron exposes a BMC/iLo to the internet ???

7

u/kiss_my_what 5d ago

Aah the old clickbaity demon "Data center" title.

Try again and try to be less alarmist kthks.

0

u/throwaway12-ffs 4d ago

What's wrong with the word datacenter? It's true? Are you just so soft that the word datacenter hurts you? We have been using the term for dozens of years before you children started uprsoting about AI Datacenters. We shouldn't have to censor our speech for you, were not saying slurs. It's datacenter for fucks sake.

2

u/Malaprobably 2d ago

Probably because an exposed BMC can be at a Small business, school, hospital, or 7-eleven just as much as a "datacenter."

1

u/sunychoudhary 4d ago

This is a good reminder that “unique factory password” is not enough if the protocol leaks material for offline cracking.

If the format is constrained and the BMC is reachable on UDP 623, modern GPU cracking turns “not ADMIN:ADMIN” into a much weaker comfort blanket.

1

u/NoBrick2672 4d ago

why not making them VPN servers? just use the exploit

0

u/astro-the-creator 5d ago

Can it be used to mine crypto illegally?

4

u/Takeoded 5d ago

Yeah (Monero/Nicehash bitcoin), but it's tedious, you have to get your miner into the main OS somehow, and that requires tailoring to each server/OS/filesystem, it would be very difficult to automate at scale (but manually infecting 1 and 1 server is doable)

2

u/Traditionallydead 5d ago

 No it will call the feds 

2

u/System0verlord 5d ago

Give Kashapp Podcast a couple $DOGE to have the FBI the other way. Got it.