Earlier quoted context omitted.
I thought the article was implying the attack involves the BMC's capability to supply (or change) a boot image. However I'm not sure how that would be able to defeat boot image signing and storage encryption.
It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack. And I believe that once you control the BIOS image you control the boot chain of trust.
Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
21–30 of 30 posts
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#22Earlier quoted context omitted.
I thought the article was implying the attack involves the BMC's capability to supply (or change) a boot image. However I'm not sure how that would be able to defeat boot image signing and storage encryption.
It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack. And I believe that once you control the BIOS image you control the boot chain of trust.
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#23Earlier quoted context omitted.
It's possible that some servers hang the BIOS flash off the BMC, or (more likely) at least have some way for the BMC to write to it - if not by design, then through a HW vuln further up the stack. And I believe that once you control the BIOS image you control the boot chain of trust.
You can update the BIOS via SuperMicro's IPMI. It's actually a feature you have to pay extra for: https://www.virtuallifestyle.nl/wp-content/uploads/2016/08/S...
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#24Presuming you can get control of the BMC and transmit arbitrary network traffic, you'd have to limit it somehow. At least some of the compromised servers would be installed in places where any unexpected outgoing network traffic would be noticed and investigated. Large amounts of detectable traffic could be generated too if these things are all pinging away at something. You'd have to trigger it somehow I suppose. But what kind of trigger can you set up on a server running an unknown OS in unknown configuration that may be behind lots of firewalls? Are we sending some kind of weird magic packet to the server? If I was Google or something, I'd have dumb filtering firewalls set up in front of my servers that drop anything that doesn't look like normal network traffic, just to keep any random person from fuzzing the server and triggering some weird unknown bug.
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#25Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#26Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#27>Saying there is a vulnerability in a BMC is like saying the sun is hot. This was my thought upon hearing the story when it broke this morning. There has to either be more to it, or I suppose..less. I did wonder if it was some sort of false flag op designed to make people in the US fearful about Chinese Hacking. Based on the people I've spoken to, inside the industry today, it has succeeded.
Re: Bloomberg Reports China Infiltrated the Supermicro Supply Chain We Investigate
#28Earlier quoted context omitted.
As a matter of routine, nobody with a clue would ever allow public Internet connectivity to the BMC NIC. They would also never allow the "bridge" mode where the BMC NIC gets logically connected to one of the primary NICs (useful if you want to spin up a box with only one drop cable in the lab). I wondered if perhaps the attack involved subverting the air gap between the BMC NIC and a primary NIC. Perhaps a reason to…
In the other threads it has been mentioned that this hypothetical attack could run similarly to the US/Xerox op in the Cold War. The Xerox machines recorded data which was collected by a Xerox technician during regular maintenance. A board with a trojan chip on it could potentially record data to be collected during an RMA. No need for network transmission.
This caused a small stink a while back but I doubt if anything's changed.