this post was submitted on 29 Jul 2026
22 points (100.0% liked)

Cybersecurity

10360 readers
351 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] Cyber@feddit.uk 5 points 2 days ago

To counter the risk, it's advised to block UDP port 623 at the network edge, rotate factory-issued passwords during provisioning, disable legacy or weak options such as IPMI 1.5, restrict BMC access to a dedicated private management network, and apply network access controls to ensure only approved administrative systems can reach BMC interfaces.

Seems even IPMI 2.0 won't fix this either

Keep your BMCs OoB...

[–] kn33@lemmy.world 4 points 2 days ago

Fucking hell

[–] f4f4f4f4f4f4f4f4@sopuli.xyz 1 points 2 days ago

Only the hashes? Supermicro must have upped their game. You used to be able to get them to spit out their IPMI passwords in plaintext.