Security hole in HP server when powered down
Summary
In 2005 HP recommended an unusual workaround for the ProLiant DL585 server: pull the power cable. A bug in the Integrated Lights-Out remote management module up to firmware 1.8 allowed unauthorised network access to the server controls while it was switched off. Only without power was the iLO switched off as well, but then every restart required a trip to the server room.
Ideas
- Remote management modules remain active even when the server is switched off.
- A bug in the management controller opens access independently of the operating system.
- Only disconnecting the power reliably switched off the vulnerable controller.
- The workaround made remote management, the actual purpose of iLO, impossible.
Insights
- Out-of-band management is a computer of its own with its own attack surface.
- With servers, “switched off” does not mean “unreachable”.
Facts
- iLO up to and including firmware 1.8 was affected; version 1.81 was in the works.
- The problem concerned the HP ProLiant DL585 model.
References
Critique
- The report does not say whether the attack was possible from the internet or only from the management network.
Remarks
- Later BMC and iLO generations also had serious holes; today management controllers belong in a separate network as a matter of principle.
Recommendations
- Operate iLO, iDRAC and other BMCs exclusively in an isolated management network.
- Keep the firmware of management controllers as up to date as the operating system.
Links to the original source and the Web Archive open in a new tab.