home.social

#bmc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bmc, aggregated by home.social.

fetched live
  1. In the beginning, there was #TTY and serial ports, and verily did #sysadmins have text-based console access to fix a server falling over. And it was good. Not efficient, and scaled poorly, but for the 80s, it was good.

    Then came addon boards and it was…ok. Then upon the world did come Baseboard Management Controller (#BMC), a dedicated, soldered on chip that changed server management from manual, physical troubleshooting to automated, isolated remote control. And it seemed pretty good.

    And then pen testers and red teams started reporting flaws and vulnerabilities. For decades. Have those flaws been fixed in all those years?

    No, don’t be ridiculous. Where’s the ROI for the MBA?

    That said, if your bmc is exposed to the internet, you probably have way bigger #infosec issues.

    arstechnica.com/security/2026/

  2. In the beginning, there was #TTY and serial ports, and verily did #sysadmins have text-based console access to fix a server falling over. And it was good. Not efficient, and scaled poorly, but for the 80s, it was good.

    Then came addon boards and it was…ok. Then upon the world did come Baseboard Management Controller (#BMC), a dedicated, soldered on chip that changed server management from manual, physical troubleshooting to automated, isolated remote control. And it seemed pretty good.

    And then pen testers and red teams started reporting flaws and vulnerabilities. For decades. Have those flaws been fixed in all those years?

    No, don’t be ridiculous. Where’s the ROI for the MBA?

    That said, if your bmc is exposed to the internet, you probably have way bigger #infosec issues.

    arstechnica.com/security/2026/

  3. In the beginning, there was #TTY and serial ports, and verily did #sysadmins have text-based console access to fix a server falling over. And it was good. Not efficient, and scaled poorly, but for the 80s, it was good.

    Then came addon boards and it was…ok. Then upon the world did come Baseboard Management Controller (#BMC), a dedicated, soldered on chip that changed server management from manual, physical troubleshooting to automated, isolated remote control. And it seemed pretty good.

    And then pen testers and red teams started reporting flaws and vulnerabilities. For decades. Have those flaws been fixed in all those years?

    No, don’t be ridiculous. Where’s the ROI for the MBA?

    That said, if your bmc is exposed to the internet, you probably have way bigger #infosec issues.

    arstechnica.com/security/2026/

  4. In the beginning, there was #TTY and serial ports, and verily did #sysadmins have text-based console access to fix a server falling over. And it was good. Not efficient, and scaled poorly, but for the 80s, it was good.

    Then came addon boards and it was…ok. Then upon the world did come Baseboard Management Controller (#BMC), a dedicated, soldered on chip that changed server management from manual, physical troubleshooting to automated, isolated remote control. And it seemed pretty good.

    And then pen testers and red teams started reporting flaws and vulnerabilities. For decades. Have those flaws been fixed in all those years?

    No, don’t be ridiculous. Where’s the ROI for the MBA?

    That said, if your bmc is exposed to the internet, you probably have way bigger #infosec issues.

    arstechnica.com/security/2026/

  5. In the beginning, there was #TTY and serial ports, and verily did #sysadmins have text-based console access to fix a server falling over. And it was good. Not efficient, and scaled poorly, but for the 80s, it was good.

    Then came addon boards and it was…ok. Then upon the world did come Baseboard Management Controller (#BMC), a dedicated, soldered on chip that changed server management from manual, physical troubleshooting to automated, isolated remote control. And it seemed pretty good.

    And then pen testers and red teams started reporting flaws and vulnerabilities. For decades. Have those flaws been fixed in all those years?

    No, don’t be ridiculous. Where’s the ROI for the MBA?

    That said, if your bmc is exposed to the internet, you probably have way bigger #infosec issues.

    arstechnica.com/security/2026/

  6. Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

    @gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

    borncity.com/blog/2026/08/01/m

    #sicherheit #security

  7. Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

    @gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

    borncity.com/blog/2026/08/01/m

    #sicherheit #security

  8. Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

    @gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

    borncity.com/blog/2026/08/01/m

    #sicherheit #security

  9. Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

    @gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

    borncity.com/blog/2026/08/01/m

    #sicherheit #security

  10. Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

    @gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

    borncity.com/blog/2026/08/01/m

    #sicherheit #security

  11. Jemand einen #Server mit #BMC im Einsatz, der per Internet erreichbar ist? Im vom Baseboard Management Controller (BMC)-Interface verwendeten IPMI 2.0-Protokoll gibt es eine Authentifizierungsschwachstelle (CVE-2013-4786). In Deutschland sind ~3.200 Systeme betroffen.

    borncity.com/blog/2026/08/01/m

  12. Jemand einen #Server mit #BMC im Einsatz, der per Internet erreichbar ist? Im vom Baseboard Management Controller (BMC)-Interface verwendeten IPMI 2.0-Protokoll gibt es eine Authentifizierungsschwachstelle (CVE-2013-4786). In Deutschland sind ~3.200 Systeme betroffen.

    borncity.com/blog/2026/08/01/m

  13. Jemand einen #Server mit #BMC im Einsatz, der per Internet erreichbar ist? Im vom Baseboard Management Controller (BMC)-Interface verwendeten IPMI 2.0-Protokoll gibt es eine Authentifizierungsschwachstelle (CVE-2013-4786). In Deutschland sind ~3.200 Systeme betroffen.

    borncity.com/blog/2026/08/01/m

  14. Jemand einen #Server mit #BMC im Einsatz, der per Internet erreichbar ist? Im vom Baseboard Management Controller (BMC)-Interface verwendeten IPMI 2.0-Protokoll gibt es eine Authentifizierungsschwachstelle (CVE-2013-4786). In Deutschland sind ~3.200 Systeme betroffen.

    borncity.com/blog/2026/08/01/m

  15. Jemand einen #Server mit #BMC im Einsatz, der per Internet erreichbar ist? Im vom Baseboard Management Controller (BMC)-Interface verwendeten IPMI 2.0-Protokoll gibt es eine Authentifizierungsschwachstelle (CVE-2013-4786). In Deutschland sind ~3.200 Systeme betroffen.

    borncity.com/blog/2026/08/01/m

  16. 📢 36 872 interfaces BMC exposées sur Internet : CVE-2013-4786 toujours exploitable en 2026
    📝 ## 🔍 Contexte

    Publié le 29 juillet 2026 par Michael Katchinskiy sur lavahq.io, cet article de recherche documente une campagne de scan et d'analyse m...
    📖 cyberveille : cyberveille.ch/posts/2026-07-2
    🌐 source : lavahq.io/research/bmc-exposur
    #BMC #CVE_2013_4786 #Cyberveille

  17. Wer stellt denn sein #ipmi / #bmc mitm nackten Ar*** ins Internet?! Sind die denn alle komplett lobotomiert?!

    golem.de/news/passwort-hashes-

    Da fällt mir nix mehr zu ein. Ausser das man da keine KI für braucht, die Komplexität der Passwörter dürfte proportional zu den itsec-Skills der Betreibenen laufen. :mastomindblown:

    #ITSecurity #seinenJobauchberuflichausüben

  18. Wer stellt denn sein #ipmi / #bmc mitm nackten Ar*** ins Internet?! Sind die denn alle komplett lobotomiert?!

    golem.de/news/passwort-hashes-

    Da fällt mir nix mehr zu ein. Ausser das man da keine KI für braucht, die Komplexität der Passwörter dürfte proportional zu den itsec-Skills der Betreibenen laufen. :mastomindblown:

    #ITSecurity #seinenJobauchberuflichausüben

  19. Wer stellt denn sein #ipmi / #bmc mitm nackten Ar*** ins Internet?! Sind die denn alle komplett lobotomiert?!

    golem.de/news/passwort-hashes-

    Da fällt mir nix mehr zu ein. Ausser das man da keine KI für braucht, die Komplexität der Passwörter dürfte proportional zu den itsec-Skills der Betreibenen laufen. :mastomindblown:

    #ITSecurity #seinenJobauchberuflichausüben

  20. Wer stellt denn sein #ipmi / #bmc mitm nackten Ar*** ins Internet?! Sind die denn alle komplett lobotomiert?!

    golem.de/news/passwort-hashes-

    Da fällt mir nix mehr zu ein. Ausser das man da keine KI für braucht, die Komplexität der Passwörter dürfte proportional zu den itsec-Skills der Betreibenen laufen. :mastomindblown:

    #ITSecurity #seinenJobauchberuflichausüben

  21. Wer stellt denn sein #ipmi / #bmc mitm nackten Ar*** ins Internet?! Sind die denn alle komplett lobotomiert?!

    golem.de/news/passwort-hashes-

    Da fällt mir nix mehr zu ein. Ausser das man da keine KI für braucht, die Komplexität der Passwörter dürfte proportional zu den itsec-Skills der Betreibenen laufen. :mastomindblown:

    #ITSecurity #seinenJobauchberuflichausüben

  22. 📣🚨 A 22-year-old flaw in IPMI 2.0 is still putting servers at risk.

    Researchers found 24,650 public BMC interfaces exposing authentication data that can be used for offline password cracking, with weak and factory credentials among those recovered.

    Listen/Read: hackread.com/ipmi-flaw-exposes

  23. 📣🚨 A 22-year-old flaw in IPMI 2.0 is still putting servers at risk.

    Researchers found 24,650 public BMC interfaces exposing authentication data that can be used for offline password cracking, with weak and factory credentials among those recovered.

    Listen/Read: hackread.com/ipmi-flaw-exposes

    #Cybersecurity #IPMI #InfoSec #Vulnerability #BMC

  24. 📣🚨 A 22-year-old flaw in IPMI 2.0 is still putting servers at risk.

    Researchers found 24,650 public BMC interfaces exposing authentication data that can be used for offline password cracking, with weak and factory credentials among those recovered.

    Listen/Read: hackread.com/ipmi-flaw-exposes

    #Cybersecurity #IPMI #InfoSec #Vulnerability #BMC

  25. 📣🚨 A 22-year-old flaw in IPMI 2.0 is still putting servers at risk.

    Researchers found 24,650 public BMC interfaces exposing authentication data that can be used for offline password cracking, with weak and factory credentials among those recovered.

    Listen/Read: hackread.com/ipmi-flaw-exposes

    #Cybersecurity #IPMI #InfoSec #Vulnerability #BMC

  26. 📣🚨 A 22-year-old flaw in IPMI 2.0 is still putting servers at risk.

    Researchers found 24,650 public BMC interfaces exposing authentication data that can be used for offline password cracking, with weak and factory credentials among those recovered.

    Listen/Read: hackread.com/ipmi-flaw-exposes

    #Cybersecurity #IPMI #InfoSec #Vulnerability #BMC

  27. Decades-Old BMC Flaw Exposes 24,000 Servers to Password Cracking

    A decades-old security flaw in Baseboard Management Controller (BMC) interfaces is putting over 24,000 internet-exposed servers at risk of password cracking, thanks to a vulnerability that allows attackers to capture and crack authentication responses. This two-decade-old weakness, tracked as CVE-2013-4786, is a pressing concern for server…

    osintsights.com/decades-old-bm

    #Bmc #Cve20134786 #Ipmi20 #PasswordCracking #ServerSecurity

  28. Electric scooter or e-bike on 20th floor of a Northampton Street high rise bursts into flames, causing a two-alarm fire
    universalhub.com/2026/electric

    #Boston #SouthEnd #BMC

  29. Electric scooter or e-bike on 20th floor of a Northampton Street high rise bursts into flames, causing a two-alarm fire
    universalhub.com/2026/electric

    #Boston #SouthEnd #BMC

  30. Electric scooter or e-bike on 20th floor of a Northampton Street high rise bursts into flames, causing a two-alarm fire
    universalhub.com/2026/electric

    #Boston #SouthEnd #BMC

  31. Electric scooter or e-bike on 20th floor of a Northampton Street high rise bursts into flames, causing a two-alarm fire
    universalhub.com/2026/electric

    #Boston #SouthEnd #BMC

  32. Electric scooter or e-bike on 20th floor of a Northampton Street high rise bursts into flames, causing a two-alarm fire
    universalhub.com/2026/electric

    #Boston #SouthEnd #BMC

  33. Ich erwäge, den Server nachts abzuschalten und morgens zu starten. Leider gibt es bislang Probleme beim Reboot, wenn das System ein paar Tage gelaufen ist. Ganz zu schweigen davon, dass ich wohl #Podman Quadlets meistern und die automatisierte LUKS-Entschlüsselung sauber hinbekommen müsste. Aber eins nach dem anderen...

    Also versuche ich, ob ein UEFI-Upgrade hilft. Also zuerst mal #BMC für #IPMI konfiguriert und darüber das Upgrade gemacht. So weit, so gut. ✅

    Hab jetzt rausgefunden, dass man das Upgrade von #UEFI bei #SuperMicro wohl am Besten via Webinterface aktualisiert. Jetzt scheitere ich daran, dass ein Product Key verlangt wird. Erst mal schauen, wo ich den wieder her bekomme.

    Und was habt Ihr heute so gemacht?

    #Upgrade #Hardware #Firmware #Energiesparen #Stromsparen

  34. Ich erwäge, den Server nachts abzuschalten und morgens zu starten. Leider gibt es bislang Probleme beim Reboot, wenn das System ein paar Tage gelaufen ist. Ganz zu schweigen davon, dass ich wohl #Podman Quadlets meistern und die automatisierte LUKS-Entschlüsselung sauber hinbekommen müsste. Aber eins nach dem anderen...

    Also versuche ich, ob ein UEFI-Upgrade hilft. Also zuerst mal #BMC für #IPMI konfiguriert und darüber das Upgrade gemacht. So weit, so gut. ✅

    Hab jetzt rausgefunden, dass man das Upgrade von #UEFI bei #SuperMicro wohl am Besten via Webinterface aktualisiert. Jetzt scheitere ich daran, dass ein Product Key verlangt wird. Erst mal schauen, wo ich den wieder her bekomme.

    Und was habt Ihr heute so gemacht?

    #Upgrade #Hardware #Firmware #Energiesparen #Stromsparen

  35. Ich erwäge, den Server nachts abzuschalten und morgens zu starten. Leider gibt es bislang Probleme beim Reboot, wenn das System ein paar Tage gelaufen ist. Ganz zu schweigen davon, dass ich wohl #Podman Quadlets meistern und die automatisierte LUKS-Entschlüsselung sauber hinbekommen müsste. Aber eins nach dem anderen...

    Also versuche ich, ob ein UEFI-Upgrade hilft. Also zuerst mal #BMC für #IPMI konfiguriert und darüber das Upgrade gemacht. So weit, so gut. ✅

    Hab jetzt rausgefunden, dass man das Upgrade von #UEFI bei #SuperMicro wohl am Besten via Webinterface aktualisiert. Jetzt scheitere ich daran, dass ein Product Key verlangt wird. Erst mal schauen, wo ich den wieder her bekomme.

    Und was habt Ihr heute so gemacht?

    #Upgrade #Hardware #Firmware #Energiesparen #Stromsparen

  36. Ich erwäge, den Server nachts abzuschalten und morgens zu starten. Leider gibt es bislang Probleme beim Reboot, wenn das System ein paar Tage gelaufen ist. Ganz zu schweigen davon, dass ich wohl #Podman Quadlets meistern und die automatisierte LUKS-Entschlüsselung sauber hinbekommen müsste. Aber eins nach dem anderen...

    Also versuche ich, ob ein UEFI-Upgrade hilft. Also zuerst mal #BMC für #IPMI konfiguriert und darüber das Upgrade gemacht. So weit, so gut. ✅

    Hab jetzt rausgefunden, dass man das Upgrade von #UEFI bei #SuperMicro wohl am Besten via Webinterface aktualisiert. Jetzt scheitere ich daran, dass ein Product Key verlangt wird. Erst mal schauen, wo ich den wieder her bekomme.

    Und was habt Ihr heute so gemacht?

    #Upgrade #Hardware #Firmware #Energiesparen #Stromsparen

  37. Veel gemeenten geven aan dat ze te weinig capaciteit hebben om de energietransitie verder te brengen. Tegelijkertijd doen gemeenten wel al heel veel. Maar die inzet staat vaak niet in verhouding tot wat er daadwerkelijk wordt bereikt.

    rzondervan.eu/grip-op-de-energ

    #energietransitie #gemeente #lokaalbestuur #publiekesector #BMC

  38. Veel gemeenten geven aan dat ze te weinig capaciteit hebben om de energietransitie verder te brengen. Tegelijkertijd doen gemeenten wel al heel veel. Maar die inzet staat vaak niet in verhouding tot wat er daadwerkelijk wordt bereikt.

    rzondervan.eu/grip-op-de-energ

    #energietransitie #gemeente #lokaalbestuur #publiekesector #BMC