zlacker

[return to "Supermicro server motherboards can be infected with unremovable malware"]
1. temp08+a9b[view] [source] 2025-09-28 17:47:30
>>zdw+(OP)
My favorite supermicro facepalm will always be when you could set the IPMI encryption cipher to "none" (ipmitool -C0) and bypass actually needing any password at all. (Though I don't think this was unique to supermicro actually?)
◧◩
2. kj4ips+Esb[view] [source] 2025-09-28 20:09:11
>>temp08+a9b
Pretty much all of them allow unrestricted access from KMS from factory, tough all of them have a way to disable it once configured, and HPE even throws shade until it's limited. KMS only works from the host itself.
[go to top]