Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.
Baseboard management controllers are m...
根据周三发表的研究,全球最大制造商销售的数千台联网服务器可以通过利用 critical 漏洞——其中一些已有十多年历史——被远程植入后门,这些漏洞潜伏在系统主板深处。
基板管理控制器是嵌入 virtually 每台企业服务器主板中的微型计算机。这些微控制器,通常缩写为BMC,运行自己的操作系统固件、网络栈和IP地址。管理员 rely on 它们来监控大型服务器 fleet 的物理状态,并执行各种任务, including 重启机器、安装更新,甚至重新安装操作系统。BMC提供所谓的" lights out "和" out-of-band "管理,因为即使它们 attached to 的服务器关闭或无响应,它们也能工作。
一个"普遍、监控不足、修补不足的并行攻击面"
研究人员自2013年以来一直警告,BMC为黑客寻找获得深度和持久数据中心访问的方式提供了 golden 机会。罪魁祸首是IPMI——允许BMC独立于服务器运行并执行管理任务的协议。该固件中的漏洞使攻击者能够在控制器上远程执行恶意代码,然后从那里感染它们管理的服务器。
This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology.
Flock is tightening its rules in response to a growing surveillance backlash
The police-tech giant Flock is changing officers’ access to its nationwide netw...
In 2017, Deanne Taylor attended a presentation at the University of Pennsylvania, just a short walk from her office. A researcher was there to unveil the Human Cell Atlas, an ambitious project that aimed to map every cell in the human body. Taylor was floored, and then concerned. As details emerged,...