posted in Technology

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/
Ars TechnicaThousands of servers can be backdoored by exploiting buggy motherboard controllersBaseboard management controllers from the world's biggest manufacturers are a security mess.

Replying to @⁨stoy@lemmy.zip⁩

As someone who bought a Supermicro board 6 weeks ago and was super happy to learn about IPMI: oh no.

I flashed the latest bmc firmware and bios the day I got it running (also fuck paywalling the bmc UI for bios updates), but… 😬

E: holy shit it truncates passwords to 19 characters. One of my weakest passwords, in the bottom 10 of like 450 passwords.

E2: I can’t disable KCS, I can’t disable the IPMI (short of unplugging the ethernet cable), I can’t disable the default user or limit the privileges, so I had delete my user, login as the default, then change the username and password to my user creds. Like, wow.