Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
:debian: 饾殰饾殠饾殨饾殠饾殜 :opensuse:
:debian: 饾殰饾殠饾殨饾殠饾殜 :opensuse:
@selea@social.linux.pizza  路  activity timestamp 2 weeks ago

Ok, so I have this HP-server in my garage that I've had for years.
I decided to plug it in, add drives and connect the iLO port.

Ofcourse, I have forgotten the iLO password - and I dont have a monitor that I can use to reset it via the BIOS.

I do remember this vulnerability from a couple of years ago, that where I could get the password (or change it) for the Administrator user with a curl post request.
But I can't find it.

Help

#linux #curl #hp #ilo #infosec #vulnerability_research #vulnerability #askfedi #askfediverse

  • Copy link
  • Flag this post
  • Block
Stanislas :NotLikeThis:
Stanislas :NotLikeThis:
@angristan@mstdn.io  路  activity timestamp 2 weeks ago

@selea 馃憖 https://github.com/skelsec/CVE-2017-12542/blob/master/exploit_1.py

GitHub

CVE-2017-12542/exploit_1.py at master 路 skelsec/CVE-2017-12542

Test and exploit for CVE-2017-12542. Contribute to skelsec/CVE-2017-12542 development by creating an account on GitHub.
  • Copy link
  • Flag this comment
  • Block
:debian: 饾殰饾殠饾殨饾殠饾殜 :opensuse:
:debian: 饾殰饾殠饾殨饾殠饾殜 :opensuse:
@selea@social.linux.pizza  路  activity timestamp 2 weeks ago

@angristan

That's it was that one I was looking for.
Sadly, I was a good boy back then and actually patched the iLO - so the machine is not vulnerable

  • Copy link
  • Flag this comment
  • Block
Stanislas :NotLikeThis:
Stanislas :NotLikeThis:
@angristan@mstdn.io  路  activity timestamp 2 weeks ago

@selea hahaha

  • Copy link
  • Flag this comment
  • Block
:debian: 饾殰饾殠饾殨饾殠饾殜 :opensuse:
:debian: 饾殰饾殠饾殨饾殠饾殜 :opensuse:
@selea@social.linux.pizza  路  activity timestamp 2 weeks ago

@angristan

Thank you!

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct