Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Do you find yourself in the position where you just bought a piece of server kit (new or used) and you do not know what the IPMI password is, and you don't have a OS/screen to reset it, or it's set to some static IP that you don't know?

Do you find yourself in the position where you just bought a piece of server kit (new or used) and you do not know what the IPMI password is, and you don't have a OS/screen to reset it, or it's set to some static IP that you don't know?

Scheduled Pinned Locked Moved Uncategorized
2 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • benjojo@benjojo.co.ukB This user is from outside of this forum
    benjojo@benjojo.co.ukB This user is from outside of this forum
    benjojo@benjojo.co.uk
    wrote last edited by
    #1

    Do you find yourself in the position where you just bought a piece of server kit (new or used) and you do not know what the IPMI password is, and you don't have a OS/screen to reset it, or it's set to some static IP that you don't know?

    Please enjoy this small (70MB) image you can put on a USB stick and blindly boot the machine into, assuming the USB boots, it will set the IPMI to a known value, and set the network back to "normal" values (no VLAN and DHCP)

    Enjoy! (and report back if you find it worked on things not already confirmed in the readme)

    Link Preview Image
    GitHub - benjojo/headless-ipmi-reset: A USB Stick to wipe a IPMI and return it to pre set standards

    A USB Stick to wipe a IPMI and return it to pre set standards - benjojo/headless-ipmi-reset

    favicon

    GitHub (github.com)

    1 Reply Last reply
    3
    0
    • R relay@relay.infosec.exchange shared this topic
      R relay@relay.mycrowd.ca shared this topic
      R relay@relay.publicsquare.global shared this topic
    • hoffmanlabs@infosec.exchangeH This user is from outside of this forum
      hoffmanlabs@infosec.exchangeH This user is from outside of this forum
      hoffmanlabs@infosec.exchange
      wrote last edited by
      #2

      @benjojo There’s an IPMI brute-force around, if that's not what you're doing here.

      CVE-2013-4786

      favicon

      (support.hpe.com)

      This is reportedly unfixable on various HP servers.

      “HPSBHF02981 rev.4 - HPE Integrated Lights-Out 2, 3, 4, 5 (iLO 2, iLO 3, iLO 4, and iLO 5) and HPE Superdome Flex RMC - IPMI 2.0 RCMP+ Authentication Remote Password Hash Vulnerability (RAKP)”

      TL;DR: ask nicely for a weakly-hashed IPMI password, then crack it offline.

      On at least some of these boxes, the iLO command that blocks this access:

      MP:CM> sa -lanipmi d

      #openvms #itanium #security #ipmi

      1 Reply Last reply
      1
      0
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups