"A lot of devices and services we have seen during our research should never be connected to the public Internet at all. As a rule of thumb, if you believe that "nobody would connect that to the Internet, really nobody", there are at least 1000 people who did. Whenever you think "that shouldn't be on the Internet but will probably be found a few times" it's there a few hundred thousand times. Like half a million printers, or a Million Webcams, or devices that have root as a root password."
Um, like web is in the name. Othewise, good points
I once connected a server to a network and it wouldn't take the room's VGA KVM, so I started a dhcp server on my laptop to get onto the ipmi
63 leases were given out in a few seconds -- the lights-out (ilo, ipmi) that were on that network had never been configured, were just sat sending out dhcp requests and getting no response. The servers themselves were all statics, but nobody had bothered setting up the ilos. Most were of the age of a default password (ADMIN/ADMIN for supermicro for example)
Now this is on a private network with internet via a proxy, so fairly bad, but not catastrophic. It shows how easy it is to connect something to the internet accidently though.
Personally I put ilos on a dedicated vlan with an ACL blocking access to anywhere other than the management servers, it's not just incoming connections from the internet or from compromised machines behind your firewall, it's outgoing connections from the ilo too.
https://threatpost.com/plaintext-supermicro-ipmi-credentials...
Here's a search for some of them (requires a Shodan account):
Supermicros default to using the dedicated nic for IPMI, but they also default to using the piggyback if there is no link on the dedicated nic. :(