如何通过网络检查我的Supermicro IPMI是否受到明文管理员密码的破坏?


Answers:


13

只需通过telnet到端口49152中的IPMI IP地址并执行特定的GET请求即可。如果您遭到入侵,应该获取用户名和密码。

telnet server.example.com 49152

在连接请求GET /PSBlock并观察结果之后,应该是这样的:

Trying 192.168.1.22...
Connected to server.example.com.
Escape character is '^]'.
GET /PSBlock

回答:

=%}?
0adminADMIN**yourPlaintextPasswordHere**;TTroot**AnotherPassword**???%?v?i?o???DDD@??

要解决此问题,请将IPMI固件更新到最新版本。该固件特定于您的IPMI控制器,因此您应该在Supermicro网站上获得指定的固件。

然后,在更新固件后,更改密码

By using our site, you acknowledge that you have read and understand our Cookie Policy and Privacy Policy.
Licensed under cc by-sa 3.0 with attribution required.