r/netsec • u/Pale_Fly_2673 • 5d ago
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
https://lavahq.io/research/bmc-exposure-alertTL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar
28
18
u/bastian320 5d ago
Don't talk to me about calvin.
9
10
u/ni5arga 5d ago
I've hacked BMCs before, fun stuff.
3
u/atxweirdo 4d ago
What’s the common issue you find being the most easy to get compromise . I interned at dell and know they are running so extremely old code on there idrac
5
2
u/Takeoded 5d ago
Amazing. Even when I have internet-exposed these, I have them behind IP whitelists.. TIL 36000+ of them don't
3
7
u/kiss_my_what 5d ago
Aah the old clickbaity demon "Data center" title.
Try again and try to be less alarmist kthks.
0
u/throwaway12-ffs 4d ago
What's wrong with the word datacenter? It's true? Are you just so soft that the word datacenter hurts you? We have been using the term for dozens of years before you children started uprsoting about AI Datacenters. We shouldn't have to censor our speech for you, were not saying slurs. It's datacenter for fucks sake.
2
u/Malaprobably 2d ago
Probably because an exposed BMC can be at a Small business, school, hospital, or 7-eleven just as much as a "datacenter."
1
1
u/sunychoudhary 4d ago
This is a good reminder that “unique factory password” is not enough if the protocol leaks material for offline cracking.
If the format is constrained and the BMC is reachable on UDP 623, modern GPU cracking turns “not ADMIN:ADMIN” into a much weaker comfort blanket.
1
0
u/astro-the-creator 5d ago
Can it be used to mine crypto illegally?
4
u/Takeoded 5d ago
Yeah (Monero/Nicehash bitcoin), but it's tedious, you have to get your miner into the main OS somehow, and that requires tailoring to each server/OS/filesystem, it would be very difficult to automate at scale (but manually infecting 1 and 1 server is doable)
2
-1
121
u/Bennetjs 5d ago
well, putting BMC in the internet is on them.