SUMMARYResearchers found that thousands of Internet-connected enterprise servers can be remotely backdoored by exploiting long-standing vulnerabilities in motherboard baseboard management controllers. These miniature computers, embedded in server motherboards, handle out-of-band management tasks such as rebooting machines, installing updates, and reinstalling operating systems. The flaws expose a deep attack surface in datacenter infrastructure through the IPMI protocol and related firmware.

A data center corridor lined with rows of locked glass server racks filled with blinking electronic network equipment.
Getty Images
arstechnica.com
A data center corridor lined with rows of locked glass server racks filled with blinking electronic network equipment.

Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.

Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive.

A “pervasive, under-monitored, under-patched parallel attack surface”

Researchers have warned since at least 2013 that BMCs present a golden opportunity for hackers looking for ways to gain deep and persistent access to datacenters. The chief culprit was IPMI, the protocol that allows BMCs to operate independently of servers and to perform administrative tasks. Vulnerabilities in this firmware made it possible for attackers to remotely execute malicious code on the controllers and, from there, infect the servers they manage.

Read full article