24,000 Server Underbellies Are Hanging Out In The Open And Nobody Noticed For Twenty Years
I need you to understand something. I have been awake since yesterday. My coffee is cold. I have fourteen open tickets. And I just read that twenty-four THOUSAND servers are leaking password hashes through a vulnerability that is old enough to rent a car.
A Baseboard Management Controller, for the Lambs in the back who don't know, is basically a tiny secret computer bolted to the bottom of your server. It lets admins manage hardware remotely, even when the main system is off. It is incredibly powerful. It has basically no business being exposed to the open internet. And yet. Here we are. Twenty-four thousand of them. Just sitting there. Hashing out their passwords to anyone who wanders past.
The flaw is roughly twenty years old. Two. Zero. Years. That means this hole in the fence predates some of the junior sysadmins currently ignoring my Slack messages. The Wolves did not even have to be clever here. They just had to show up and ask nicely.
Because nobody did the shearing. Nobody applied the ointment. The Shepherds presumably saw the patching advisory, said "we'll schedule that for Q3," and then it became Q3 of 2031 somehow.
The really fun part is that once a Wolf grabs that hash, they can crack it offline at their leisure, or just pass it directly to authenticate against the BMC. Full hardware-level access. They can power cycle your servers, mount virtual drives, redirect your console. It is not a bad day. It is a catastrophic one. All because someone left the BMC port facing the Sky Pasture with a vulnerability that has been documented since before smartphones existed.
I am not angry. I am just tired.
Remediation (Please, I Am Begging You)
First: Stop exposing BMC interfaces to the internet. Put them on a dedicated out-of-band management network. This is not a new idea. This is a very old idea. Do the old idea.
Second: Apply the firmware updates. Yes, the ones you have been deferring. Do the shearing. Right now. Before you finish reading this.
Third: Audit what is actually exposed. Shodan will tell you. It will not be a fun conversation with yourself but it will be a necessary one.
Fourth: If your hashes are already out there, rotate credentials immediately and assume the worst, because the worst has probably already happened.
The Shepherds will ask for a one-page summary of all this. Tell them the fence had a hole for twenty years and we just noticed. That should cover it.
Go check your BMCs. I'll be here, staring at my cold coffee.
Original Report: https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/