HP iLO4 authentication bypass: curl -H "Connection: AAAAAAAAAAAAAAAAAAAAAAAAAAAAA" No, that's not a crash PoC. That's a full blown auth bypass. sscanf into fixed buffer overwrites a flag field that bypasses auth. Yes, really. https://airbus-seclab.github.io/ilo/SSTIC2018-Slides-EN-Backdooring_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-czarny.pdf …
-
Show this thread
-
Replying to @marcan42
Not to mention that BIOS updates are not free anymore from HP, no service contract, no updates
3 replies 3 retweets 49 likes -
Replying to @Mc_Tedson
This and other such nonsense. Guess why the last two servers I got to spec out were Lenovos, not HPs? Are you listening,
@HPE?3 replies 3 retweets 57 likes -
It’s OK, latest HP server use Intel AMT. I guess it was cheaper than the iLO HW and SW. I swore no more HP for me anymore
1 reply 0 retweets 7 likes -
Hmm? Just updated my iLO4 in an (old) Gen8 to 2.60 and that fixed it. This download and the SystemPAQ (against Meltdown and Spectre) were free w/o service agreement or license...
1 reply 2 retweets 8 likes -
They started doing this shit with Gen9. And of the two servers we bought, we couldn't even register one because our reseller had apparently registered its serial themselves in exclusive mode. Never buying HP servers again until they stop this nonsense.pic.twitter.com/LD1Xz26p4v
3 replies 6 retweets 28 likes -
Hm. With the System BIOS it said the same too (Entitlement required). But could d/l it anyway... But it's true: The iLO4 2.60 was free for Gen8.pic.twitter.com/q5dCyxz301
1 reply 0 retweets 2 likes -
Yeah, iLO firmware is still free (and server independent; there is only one iLO4, it doesn't matter what server you have, the firmware is the same), but the BIOS updates are not.
2 replies 1 retweet 8 likes -
btw, there are iLO4 (for Gen9 and older) and iLO5 (for Gen10)
1 reply 0 retweets 0 likes
Yes, and iLO3, and iLO2. But within each generation the firmware is the same across the entire product line.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.