加载中... --°C -- · --% · --
|
加载中... --°C -- · --% · --

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Thousands of servers can be backdoored by exploiting buggy motherboard controllers
摘要

研究人员发现,全球主要服务器制造商生产的数千台联网服务器可被远程植入后门,其根源在于主板中基板管理控制器(BMC)存在的严重漏洞,部分漏洞已存在超过十年。BMC是嵌入服务器主板的小型计算机,拥有独立操作系统、网络栈和IP地址,用于远程监控和管理服务器,即使主机关机或无响应也能工作。自2013年起,安全专家便警告BMC为黑客提供了深入且持久访问数据中心的“黄金

Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.

Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive.

A “pervasive, under-monitored, under-patched parallel attack surface”

Researchers have warned since at least 2013 that BMCs present a golden opportunity for hackers looking for ways to gain deep and persistent access to datacenters. The chief culprit was IPMI, the protocol that allows BMCs to operate independently of servers and to perform administrative tasks. Vulnerabilities in this firmware made it possible for attackers to remotely execute malicious code on the controllers and, from there, infect the servers they manage.

Read full article

Comments

转载信息
原文: Thousands of servers can be backdoored by exploiting buggy motherboard controllers (2026-08-05T22:35:20)
作者: Dan Goodin 分类: 科技
评论 (0)
登录 后发表评论

暂无评论,来留下第一条评论吧