<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bmc-Ipmi on CuraSec</title><link>https://curasec.metacog.co.kr/tags/bmc-ipmi/</link><description>Recent content in Bmc-Ipmi on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 29 Jul 2026 13:07:14 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/bmc-ipmi/index.xml" rel="self" type="application/rss+xml"/><item><title>24,650 Internet-Exposed BMCs Leak IPMI Password Hashes Pre-Auth</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-24-650-internet-exposed-bmcs-disclose-ipmi-password-hashes-b/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-24-650-internet-exposed-bmcs-disclose-ipmi-password-hashes-b/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> The IPMI RAKP pre-auth hash disclosure flaw is a known long-standing weakness, but this research quantifies how many organizations still expose BMC interfaces directly to the internet. Audit all BMC/IPMI management interfaces for internet reachability and enforce firewall or out-of-band network isolation; rotate IPMI credentials on any system that may have been exposed.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No active exploitation campaign, IOCs, or ATT&amp;amp;CK-mappable TTPs are provided; this is a research enumeration finding. File as context for what attackers can target on internet-facing server management planes, but there is nothing actionable to hunt or detect today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A research finding showing widespread internet exposure of server management interfaces — useful benchmark data for a future board deck on infrastructure hygiene, but no breach, vendor incident, or regulatory trigger requires leadership action now.&lt;/li>
&lt;/ul></description></item></channel></rss>