DEF CON 31 - Breaking BMC The Forgotten Key to the Kingdom - Alex Tereshkin, Adam Zabrocki

  Рет қаралды 4,811

DEFCONConference

DEFCONConference

8 ай бұрын

The Baseboard Management Controller (BMC) is a specialized microcontroller embedded on the motherboard, typically used in servers and other enterprise-level hardware. The security of the BMC is critical to the overall security of the system, as it provides a privileged level of access and control over the hardware components of the system, including the ability to perform firmware updates, and even power the system on and off remotely.
When the internal offensive security research team was analyzing one of the NVIDIA hardware, they detected several remotely exploitable bugs in AMI MegaRAC BMC. Moreover, various elevations of privileges and "change of scope" bugs have been identified, many of which may be chained together resulting in a highest severity security issue. During this talk we would like to take you on the journey of the whole attack sequence: from having zero knowledge about a remote AMI BMC with enabled IPMI (yeah, right) to flashing a persistent firmware implant to the server SPI flash. The chain will be about a dozen bugs long, so buckle up.

Пікірлер: 6
@rogo7330
@rogo7330 8 ай бұрын
It is strange people often forget to do path-sanitization, or just avoid it by completly deniying it or trying to solve problem with `chroot` or something like that. It's like one function that cuts out '/../' and '/./' and then compresses '//' strings, you don't even need to allocate any more memory for that.
@null4624
@null4624 8 ай бұрын
LOL. Great work
@dandeeteeyem2170
@dandeeteeyem2170 8 ай бұрын
😮
@HardcoreMatrix
@HardcoreMatrix 8 ай бұрын
👍👍
@metaforest
@metaforest 8 ай бұрын
oopsec🤭
@iwuvu5940
@iwuvu5940 2 ай бұрын
Lol
DEF CON 31 - Terminally Owned - 60 Years of Escaping - David Leadbeater
47:34
Omega Boy Past 3 #funny #viral #comedy
00:22
CRAZY GREAPA
Рет қаралды 36 МЛН
Why You Should Always Help Others ❤️
00:40
Alan Chikin Chow
Рет қаралды 71 МЛН
Intro to the Zig Programming Language • Andrew Kelley • GOTO 2022
50:14
37C3 -  SMTP Smuggling - Spoofing E-Mails Worldwide
31:40
media.ccc.de
Рет қаралды 40 М.
Here's What Happens When an 18 Year Old Buys a Mainframe
45:12
SHARE Association
Рет қаралды 3,2 МЛН
Apple watch hidden camera
0:34
_vector_
Рет қаралды 57 МЛН
Will the battery emit smoke if it rotates rapidly?
0:11
Meaningful Cartoons 183
Рет қаралды 6 МЛН
Где раздвижные смартфоны ?
0:49
Не шарю!
Рет қаралды 670 М.
Main filter..
0:15
CikoYt
Рет қаралды 1,8 МЛН
С ноутбуком придется попрощаться
0:18
Up Your Brains
Рет қаралды 385 М.