🔥 🔥 🔥 💻 💻 💻 💻 🔥 🔥 🔥 Retweeted Hector Martin
Oh gosh, the memories. Burn it all. Burn it all to the ground.https://twitter.com/marcan42/status/1008981518159511553 …
🔥 🔥 🔥 💻 💻 💻 💻 🔥 🔥 🔥 added,
Hector Martin @marcan42
HP iLO4 authentication bypass: curl -H "Connection: AAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
No, that's not a crash PoC. That's a full blown auth bypass. sscanf into fixed buffer overwrites a flag field that bypasses auth. Yes, really.
https://airbus-seclab.github.io/ilo/SSTIC2018-Slides-EN-Backdooring_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-czarny.pdf …
Show this thread
10:50 AM - 19 Jun 2018
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
. | ex