All posts by FreeNews

United States: Canadian Man Pleads Guilty To Hacking U.S. Cloud Storage Provider And Extorting Its Customers For Millions

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims. “Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the […]

United States: Secretary Mullin Tours Border Wall, Meets Border Patrol Agents In Texas

Yesterday, United States Department of Homeland Security (DHS) Secretary Markwayne Mullin toured the southern border in Brownsville, Texas, marking his first visit to the border as Secretary. While at the border, Secretary Mullin toured the southern border wall, visited Camp Monument, toured an autonomous surveillance tower, and met with U.S. Coast Guard personnel and U.S. Border […]

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.

Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive.

A “pervasive, under-monitored, under-patched parallel attack surface”

Researchers have warned since at least 2013 that BMCs present a golden opportunity for hackers looking for ways to gain deep and persistent access to datacenters. The chief culprit was IPMI, the protocol that allows BMCs to operate independently of servers and to perform administrative tasks. Vulnerabilities in this firmware made it possible for attackers to remotely execute malicious code on the controllers and, from there, infect the servers they manage.

Read full article

Comments