I'm no expert, but wouldn't be more efficient to completely replace the BMC with a malicious one? That way it should be virtually impossible to detect
The cons to that approach is the work it takes to design a BMC without knowing how the existing one is designed. Replicating all of the BMC behavior is hard. Differences in behavior might be easily spotted, whereas this can lie dormant until triggered. "Why does unit #4322 have a faster/slower ping response?" Oops, discovered!
Making sense of the alleged Supermicro motherboard attack
21–30 of 328 posts
Re: Making sense of the alleged Supermicro motherboard attack
#22Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.
> Why wouldn’t a company notice any of the outbound traffic using firewalls? The attacker could use this to escape AWS/shared computing sandboxes/containers in order to attack their peers. Exfiltrating the data stolen could be easily hidden in something that looks like legitimate customer traffic.
Re: Making sense of the alleged Supermicro motherboard attack
#23Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.
There wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.
Re: Making sense of the alleged Supermicro motherboard attack
#24I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak.
To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those countries, it would definitely be the first thing I would do.
Re: Making sense of the alleged Supermicro motherboard attack
#25Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.
I don’t know what you mean by the first question. The implication was that this was a bit of a drift net attack. Compromise a few lots, then wake them up a few months later figure out where they are. Most aren’t useful, but if you got the right batch, some might end up someplace interesting. I would assume the reason why no one noticed outbound traffic is because it’s dormant.
Re: Making sense of the alleged Supermicro motherboard attack
#26Earlier quoted context omitted.
The cons to that approach is the work it takes to design a BMC without knowing how the existing one is designed. Replicating all of the BMC behavior is hard. Differences in behavior might be easily spotted, whereas this can lie dormant until triggered. "Why does unit #4322 have a faster/slower ping response?" Oops, discovered!
You don't have to redesign the BMC. Just repackage them with additional dice to take over I/O pins as needed.
Re: Making sense of the alleged Supermicro motherboard attack
#27Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.
Outbound traffic is allowed unrestricted in 95% of the deployments, it is just a life fact, people trust their own systems.
Re: Making sense of the alleged Supermicro motherboard attack
#28Is this really that hard to imagine? I am willing to bet that there are teams of spies who have infiltrated Google, Facebook, Amazon, etc. Spies from US, Russia, China, Britain, Israel, Germany, etc, must have dozens of spies working as engineers are getting access to all that data as we speak. To think that they aren't would be rather naive, in my opinion. If I were head of the spy agencies in any one of those count…
1) happen to be country that makes all electronics
2) Company with a lot of ties to your country is happen to be top server supplier
3) Companies that use these servers happen to work for DoD, CIA and all major points of interest.
Re: Making sense of the alleged Supermicro motherboard attack
#29Earlier quoted context omitted.
There wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.
The traffic has to travel over wire as TCP/IP, regardless of what device generated it. It has to travel over wire somewhere! The device can’t magically communicate with China. Any outbound firewall could detect that, especially traffic going to ports that aren’t even open/used.
Or if they can insert themselves into the maintenance team, they can retrieve their chips at a later date.
Re: Making sense of the alleged Supermicro motherboard attack
#30Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up for me.
There wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.