Implant.ARM.iLOBleed.a
threats.amnpardaz.com
threats.amnpardaz.com
Quote:
The iLO5 chipset provides an unprecedented level of hardware security with its silicon root of trust. The silicon root of trust: - Is based in the silicon chip hardware itself - Is virtually impossible to alter - Enables firmware to be authenticated as far back as the supply chain - Provides a secure startup process
I've spent a lot of time trying to RE the firmware for these devices but never got past the encryption. Someone obviously has, very interesting to see what comes out in this space in future.
http://ramtin-amin.fr/#nvmepcie
http://ramtin-amin.fr/#nvmedma
Remains one of my favourite hacks, mostly because I can say I can (barely) actually understand it :D
I mention this because, if Apple can't get PCI-e right on the first go, ...
Same thing that happened here, the code signing works fine but it was used to sign code with trivial format vulnerabilities running in an environment (RTOS) that doesn't support any sort of isolation.
This is pretty much standard today (and has been for some years). See ARM security model and Trusted Firmware design documents.
https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
What gives?
The overall analysis is a bit on the shallow side there might be more things there that they didn’t uncover.
The odd thing is that the malware creates a file name basically called “fake firmware” that seems a bit too amateurish for the usual suspects…
Might be KSA’s NSA for hire level op.
Since HP do not make it easy to get iLO updates if you don't have a support contract with them. I suspect many machines are vulnerable to this.
Really? I'm certainly no big data center sheep dog, but even for the tiny handful of systems I manage IPMI/BMC always seemed to come with big, flashing red lights just from their mere description. They're enormously powerful and valuable tools, but seems pretty obvious that can work both ways. Beyond their own credentials (and it's a real shame so few support smartcards/hardware tokens for login), having them on their own isolated VLAN seemed about the bare minimum. If budget allows/there are enough systems flat out having their own 100% independent physical infrastructure isn't such a stretch either, not like a simple switch and console system or if necessary a decent minimal bastion is that big a price tag these days. In some cases may make the most sense to just use them to setup then disconnect them.
You may well be right but still, yeesh. It's remote super root access, should make any sysadmin treat it with healthy fear from just a description. Although what did give me the willies was how it seems common to have IPMI be hybrid with LAN1 by default rather then it's own physically independent port. I switched from HPE to SuperMicro kit because at our scale and application it made sense for a lot of reasons anyway, but that HPE wants a lot of extra money for a dedicated port and full fat features was a real factor.
Ironically, the more expensive ILO systems can be easier to exploit. Just throw a Linux live rescue image onto virtual media, reboot the machine, and you can grab everything sensitive fairly quickly.
Though maybe some of the blame really should be on the vendors themselves here. At least credentials are randomized now, but they could be much more aggressive about making it something that has to be actively turned on, always has it's own physically isolated port, and requires some level of secure setup (won't communicate untagged maybe?). Or these days making hardware token/smartcard usage required perhaps. There's clearly tradeoffs to be made in terms of security vs convenience/recovery from bad setups, and the balance has fallen fairly decisively in favor of the latter. Kind of depressing though the industry constantly has to do the same thing of ignoring security right up until it gets really, really bad.
Eh, no. You'd isolate it on a VLAN where only people who need access to ILO have access to. Now, lets zoom out for a moment, does the sales dept. need access to ILO? No. Does the CEO need access to ILO? No. So machines on these VLANs do not have access to that VLAN. And, if the machine of a sysadmin is compromised, you're into deep shit as it is.
Suppose you have 500 servers. You carefully put each of the 500 iLOs on the special iLO VLAN, you can enable 802.1x or MACSET or magical locked Ethernet jacks or whatever and make absolutely certain that only perfectly trustworthy IT admins using perfectly trustworthy computers can touch that network.
And you still lose! Because an attacker can compromise an unimportant sales computer, escalate to root (or SYSTEM), and compromise that computer’s iLO via the internal pretend-PCI transport as discussed in the OP. And now the attacker is on the supposedly secure iLO VLAN.
Replace iLO with any other BMC or BMC-like solution (AMT, for example), and the scope of this issue should be apparent.
To mitigate this, either proper hardware rooted security for BMCs is needed (giving a strong zero-trust model) or a very carefully configured network that isolates all hosts from each other. Or, preferably, both.
[0] Windows Server, Citrix, etc are real. Just because it has an old fashioned GUI doesn’t mean it doesn’t have rack ears and a management port.