norden.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Moin! Dies ist die Mastodon-Instanz für Nordlichter, Schnacker und alles dazwischen. Folge dem Leuchtturm.

Administered by:

Server stats:

3.4K
active users

#bmc

0 posts0 participants0 posts today

Critical #AMI #MegaRAC bug can let attackers hijack, brick #servers
MegaRAC #BMC provides "lights-out" and "out-of-band" remote system management capabilities that help admins troubleshoot servers as if they were physically in front of the devices. The firmware is used by over a dozen #server vendors that provide equipment to many cloud service and #datacenter providers, including #HPE, #Asus, #ASRock, and others.
bleepingcomputer.com/news/secu

BleepingComputer · Critical AMI MegaRAC bug can let attackers hijack, brick servers
More from Sergiu Gatlan
Replied in thread

@lumi Cortana from Halo 4 voice: I can tell you so many reasons why #GPLv3 would be a horribe decision and inevitably enshure that said Kernel can't retain compatibility longterm nor share code...

  • @landley went through all of this and came to the conclusion that #Copyleft doesn't work!

Plus doing so would basically create only unnecessary and redundant labour whilst not providing any real, practical benefit to the end-users...

Espechally since #Linux is galaxies ahead in terms of #documentatation, #developers, #support and #support

Die Art wie #BMC die Sattelstützenklemme realisiert hat ist schon irgendwie episch (ist ein Keil, der sich durch Gewicht von oben quasi erst richtig fest drückt).

Wäre sie nur manchmal nicht so unfassbar schwer zu lösen wenn du das🚲wieder flugfertig machen möchtest.

Sonst ging's immer irgendwie, heute scheint das Rad aber noch nicht wieder fliegen zu wollen.🙄

Hackable #Intel and #Lenovo hardware that went undetected for 5 years won’t ever be fixed
For years, #BMC from multiple manufacturers have incorporated vulnerable versions of #opensource software known as #lighttpd. In 2018, lighttpd developers released a new version that fixed “various use-after-free scenarios,” but didn’t include a #CVE vulnerability tracking number as is customary. BMC makers including #AMI and #ATEN were using affected versions of this software.
arstechnica.com/security/2024/

#Intel and #Lenovo servers impacted by 6-year-old #BMC flaw
During recent scans of Baseboard Management Controllers, Binarly firmware security firm discovered a remotely exploitable heap out-of-bounds read vulnerability through the #Lighttpd web server processing "folded" HTTP request headers.
It was addressed in August 2018, the maintainers of Lighthttpd patched it silently in version 1.4.51 but #AMI #MegaRAC BMC to missed the fix, possibly because no #CVE was assigned.
bleepingcomputer.com/news/secu