HP iLO4 authentication bypass: curl -H "Connection: AAAAAAAAAAAAAAAAAAAAAAAAAAAAA" No, that's not a crash PoC. That's a full blown auth bypass. sscanf into fixed buffer overwrites a flag field that bypasses auth. Yes, really. https://airbus-seclab.github.io/ilo/SSTIC2018-Slides-EN-Backdooring_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-czarny.pdf …
-
Show this thread
-
Replying to @marcan42
Not to mention that BIOS updates are not free anymore from HP, no service contract, no updates
3 replies 3 retweets 49 likes -
Replying to @Mc_Tedson
This and other such nonsense. Guess why the last two servers I got to spec out were Lenovos, not HPs? Are you listening,
@HPE?3 replies 3 retweets 57 likes -
It’s OK, latest HP server use Intel AMT. I guess it was cheaper than the iLO HW and SW. I swore no more HP for me anymore
1 reply 0 retweets 7 likes -
Hmm? Just updated my iLO4 in an (old) Gen8 to 2.60 and that fixed it. This download and the SystemPAQ (against Meltdown and Spectre) were free w/o service agreement or license...
1 reply 2 retweets 8 likes -
They started doing this shit with Gen9. And of the two servers we bought, we couldn't even register one because our reseller had apparently registered its serial themselves in exclusive mode. Never buying HP servers again until they stop this nonsense.pic.twitter.com/LD1Xz26p4v
3 replies 6 retweets 28 likes -
So you don't buy Cisco network gear then either right? Because they have been doing this for decades.
2 replies 0 retweets 0 likes
Indeed, I don't. I actually used to like HP switches (Procurve is still good value surplus/2nd hand), but their latest stuff is a mess. I tried Juniper, Huawei, Dell and went with Dell (Force10) recently. They actually support multiple OSes and are x86 based.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.