Those 'invisible' servers could open your network to hackers

FREE

Become An Insider

Sign up now and get free access to hundreds of Insider articles, guides, reviews, interviews, blogs, and other premium content from the best tech brands on the Internet: CIO, CSO, Computerworld, InfoWorld, IT World and Network World Learn more.

Slew of vulnerabilities in IPMI standard for disaster-recovery access leaves unpatched implementations at severe risk

I've written before about the huge benefits you can reap if you plan for large sitewide outages by giving yourself access to all the troubleshooting tools you'll need ahead of time. These days, that almost always includes access to a bevy of embedded management interfaces. These interfaces are common on devices like uninterruptible power supplies, network-attached power distribution units, blade chassis, and server hardware in the form of baseboard management controllers (BMCs). They can be an enormous help when you've had a full site failure or are remotely troubleshooting a huge range of problems.

However, they also can present an enormous risk if not protected properly.

Recently, US-CERT released a security advisory that explains the risks inherent with exposing Intelligent Platform Management Interface (IPMI) interfaces to unsecured networks. IPMI is an API standard maintained by Intel that describes a platform-independent method of interacting with the BMCs on servers. This advisory followed the release of numerous vulnerabilities in the IPMI 1.5 and 2.0 standards discovered by independent security consultant Dan Farmer while working on a DARPA grant.

Effectively, the vulnerabilities Farmer discovered allow unfettered access to the most basic functions of any server with an exposed and unpatched IPMI interface. Given that more than 200 server manufacturers have adopted Intel's standard (Hewlett-Packard, Dell, SuperMicro, IBM, you name it) and implemented it in their own BMCs, chances are your data center is full of enabled and accessible IPMI devices. Effectively, a hacker with full access to an IPMI interface might as well be physically sitting in front of the server -- that's the point of these interfaces.

To continue reading, please begin the free registration process or sign in to your Insider account by entering your email address:
From CIO: 8 Free Online Courses to Grow Your Tech Skills
View Comments
You Might Like
Join the discussion
Be the first to comment on this article. Our Commenting Policies