Тёмный

DEF CON 31 - Breaking BMC The Forgotten Key to the Kingdom - Alex Tereshkin, Adam Zabrocki 

DEFCONConference
Подписаться 293 тыс.
Просмотров 5 тыс.
50% 1

The Baseboard Management Controller (BMC) is a specialized microcontroller embedded on the motherboard, typically used in servers and other enterprise-level hardware. The security of the BMC is critical to the overall security of the system, as it provides a privileged level of access and control over the hardware components of the system, including the ability to perform firmware updates, and even power the system on and off remotely.
When the internal offensive security research team was analyzing one of the NVIDIA hardware, they detected several remotely exploitable bugs in AMI MegaRAC BMC. Moreover, various elevations of privileges and "change of scope" bugs have been identified, many of which may be chained together resulting in a highest severity security issue. During this talk we would like to take you on the journey of the whole attack sequence: from having zero knowledge about a remote AMI BMC with enabled IPMI (yeah, right) to flashing a persistent firmware implant to the server SPI flash. The chain will be about a dozen bugs long, so buckle up.

Наука

Опубликовано:

 

28 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 6   
@rogo7330
@rogo7330 11 месяцев назад
It is strange people often forget to do path-sanitization, or just avoid it by completly deniying it or trying to solve problem with `chroot` or something like that. It's like one function that cuts out '/../' and '/./' and then compresses '//' strings, you don't even need to allocate any more memory for that.
@null4624
@null4624 11 месяцев назад
LOL. Great work
@dandeeteeyem2170
@dandeeteeyem2170 11 месяцев назад
😮
@HardcoreMatrix
@HardcoreMatrix 11 месяцев назад
👍👍
@metaforest
@metaforest 11 месяцев назад
oopsec🤭
@iwuvu5940
@iwuvu5940 4 месяца назад
Lol
Далее
СЕРЕГА ПИРАТ - TEAM SPIRIT
02:37
Просмотров 351 тыс.
The real world truth about AI Hacking
40:08
Просмотров 43 тыс.
Breaking Managed Data Services in the Cloud
39:34
Просмотров 2,2 тыс.
Самый дорогой телефон 2000х
0:54