메뉴
BL
Ars Technica • 51일 전

메인보드 취약점으로 수천 개 서버 원격 해킹 위협

IMP
9/10
핵심 요약

세계 유수 서버 제조사들의 제품에 포함된 베이스보드 관리 컨트롤러(BMC)에서 심각한 보안 취약점들이 대거 발견되었습니다. 이 취약점들은 서버 운영체제와 독립적으로 작동하는 BMC의 특성상 해커가 서버에 깊고 지속적인 백도어 액세스 권한을 얻을 수 있게 만듭니다. 10년 이상 된 구형 취약점이 여전히 방치되고 있는 등 기업의 데이터센터가 직면한 핵심 보안 위협을 점검해야 하는 중요한 사안입니다.

번역된 본문

본문 설정: 스토리 텍스트 크기(작게, 표준, 크게), 너비(표준, 넓게), 링크(표준, 주황색) - (*구독자 전용, 더 알아보기, 내비게이션으로 최소화 등 웹페이지 UI 요소)

수요일 발표된 연구에 따르면, 세계 최대 규모 제조사들이 판매하고 인터넷에 연결된 수천 대의 서버가 시스템 메인보드 깊숙한 곳에 숨어있는 심각한 취약점(일부는 10년 이상 된 취약점)을 악용하여 원격으로 백도어(불법 접근 통로)를 심을 수 있는 것으로 나타났습니다.

베이스보드 관리 컨트롤러(Baseboard management controllers, BMC)는 거의 모든 기업용 서버 메인보드에 내장된 소형 컴퓨터입니다. 일반적으로 BMC라는 약자로 불리는 이 마이크로컨트롤러는 자체 운영체제 펌웨어, 네트워크 스택, 그리고 IP 주소를 통해 실행됩니다. 관리자들은 이를 통해 수많은 서버의 물리적 상태를 모니터링하고, 시스템 재부팅, 업데이트 설치, 심지어 운영체제 재설치와 같은 다양한 작업을 수행할 수 있습니다. BMC는 서버의 전원이 꺼져 있거나 응답하지 않을 때도 작동하기 때문에 이른바 '무인(Lights out)' 및 '대역 외(Out-of-band)' 관리 기능을 제공합니다.

'만연하고, 모니터링이 부족하며, 패치가 제대로 되지 않는 평행적 공격 표면'

연구원들은 적어도 2013년부터 데이터센터에 대한 깊고 지속적인 접근 권한을 얻으려는 해커들에게 BMC가 완벽한 기회를 제공한다고 경고해 왔습니다. 가장 큰 문제는 BMC가 서버와 독립적으로 작동하고 관리 작업을 수행할 수 있게 해주는 프로토콜인 IPMI입니다. 이 펌웨어의 취약점으로 인해 공격자는 컨트롤러에서 원격으로 악성 코드를 실행하고, 이를 통해 해당 컨트롤러가 관리하는 서버를 감염시킬 수 있었습니다.

수요일 라스베이거스에서 열린 블랙햇(Black Hat) 보안 컨퍼런스에서 발표된 연구에 따르면, 그 이후로 크게 달라진 것은 없는 것으로 나타났습니다. 펌웨어 보안 전문가이자 보안 업체 runZero의 CEO 겸 창립자인 HD 무어(HD Moore)는 HPE, 슈퍼마이크로(Supermicro), 아보센트(Avocent), 화웨이(Huawei), 레노버(Lenovo), 델(Dell) 등이 판매하는 BMC에서 12개 이상의 새로운 취약점을 발견했습니다. 무어는 또한 2013년에 경고했던 취약점 중 일부가 수정 조치가 있었음에도 불구하고 여전히 활성화되어 있다는 사실을 발견했습니다.

무어는 발표에 앞서 이메일을 통해 다음과 같이 작성했습니다. "결과적으로 이는 인터넷에 노출되어 있고 기업 내부 네트워크에 널리 퍼져 있으며, 많은 사람들이 인식하는 것보다 훨씬 악용 가능성이 높은, 만연하고 모니터링이 부족하며 패치가 제대로 되지 않는 평행적 공격 표면을 형성했습니다."

이러한 위협을 강조하고 정량화하기 위해 무어는 두 차례의 대규모 스캔을 감독했습니다. 하나는 인터넷에 연결된 BMC를 전반적으로 스캔한 것이고, 다른 하나는 기업 네트워크 내부의 장치를 내부적으로 조사한 것입니다. 외부 스캔 결과, 관리 서비스를 외부에 노출하는 BMC가 86,000개 이상 발견되었습니다. 이러한 장치의 54% 이상이 하나 이상의 심각한 취약점을 포함하고 있었습니다. 최대 75,000대는 여전히 CVE-2013-4786(관리자 수준의 BMC 계정 비밀번호를 오프라인으로 크래킹할 수 있게 하는 IPMI 2.0 인증 프로토콜의 취약점)에 취약한 것으로 나타났습니다. 한편, 126,761개의 BMC에 대한 내부 스캔에서는 거의 29%가 하나 이상의 심각한 취약점을 가지고 있는 것으로 조사되었습니다.

날로 늘어나는 취약점 목록

발표를 앞두고 무어가 새롭게 발견한 취약점의 수는 날마다 증가하여 특정 수치를 제공하기 어렵습니다. 연구원이 BMC 제조사가 패치할 시간을 가질 때까지 취약점 세부 정보를 기밀로 유지하고 있기 때문에, 개별 취약점을 구체적으로 공개할 수도 없습니다. 일반적으로 주요 버그의 유형은 다음과 같습니다:

  1. IPMI 인증 핸드셰이크의 결함: 해커는 인증 요구 사항을 우회하는 방식으로 미리 정해진 메시지 교환 시퀀스를 변경할 수 있습니다. 이를 통해 공격자는 BMC에 제한적인 발판을 마련할 수 있으며, 이후 다른 취약점을 악용해 관리자 권한을 획득하게 됩니다. 영향을 받는 제품으로는 HPE iLO, Supermicro, OpenBMC, 그리고 H3C 및 엔비디아(Nvidia)의 OpenBMC 기반 제품 등이 있습니다.

  2. 세션 내에서 무결성 및 암호화 보호를 강제하지 않는 IPMI의 실패: "장치는 공격자 자신의 헤더로부터 들어오는 각 패킷을 인증하고 해독할지 여부를 결정하며..." (원문 누락으로 인한 문장 중단)

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday. Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive. A “pervasive, under-monitored, under-patched parallel attack surface” Researchers have warned since at least 2013 that BMCs present a golden opportunity for hackers looking for ways to gain deep and persistent access to datacenters. The chief culprit was IPMI , the protocol that allows BMCs to operate independently of servers and to perform administrative tasks. Vulnerabilities in this firmware made it possible for attackers to remotely execute malicious code on the controllers and, from there, infect the servers they manage. Research presented Wednesday at the Black Hat security conference in Las Vegas shows that little has changed since then. HD Moore, a firmware security expert and the CEO and founder of security firm runZero , uncovered more than a dozen new vulnerabilities in BMCs sold by HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others. Moore has also found that some of the weaknesses he warned of in 2013 remain active, despite measures intended to fix them. “The end result is a pervasive, under-monitored, under-patched parallel attack surface that is both Internet-exposed and widespread inside corporate networks, and is much more exploitable than many folks realize,” Moore wrote in an email ahead of his talk. To highlight and quantify the threat, Moore oversaw two large-scale scans. One scanned Internet-connected BMCs at large, while the other internally surveyed the devices inside corporate networks. The external scan found more than 86,000 BMCs that exposed a management service to the public. More than 54 percent of those devices contained one or more critical vulnerabilities. As many as 75,000 of them remained vulnerable to CVE-2013-4786 , a vulnerability in the IPMI 2.0 authentication protocol that enables off-line cracking of administrator-level BMC account passwords. The internal scan of 126,761 BMCs, meanwhile, found that nearly 29 percent of them had one or more critical vulnerabilities. A vulnerability list that grows by the day The number of new vulnerabilities Moore has discovered in the lead-up to his has grown by the day, making it hard to provide a specific number. Because the researcher is keeping vulnerability details confidential until the BMC makers have time to patch them, he’s also not at liberty to disclose many of them individually. Generally speaking, some of the bug classes are: 1. Flaws in the IPMI authentication handshake. Hackers can alter the prescribed sequence of massage exchanges in a way that bypasses authentication requirements. This gives an attacker a limited toehold into the BMC. The attacker can then gain administrative access by exploiting other vulnerabilities. Affected products include HPE iLO, Supermicro, OpenBMC, and OpenBMC-derived products from H3C and Nvidia. 2. A failure of IPMI to enforce integrity and encryption protections in-session. “The device decides whether to authenticate and decrypt each packet from that attacker’s own header, and not from the algorithms the session negotiated, so an unsigned, unencrypted command is accepted on a secured session,” Moore said. A proof-of-concept exploit Moore developed uses such bugs to “chain otherwise-unexploitable issues into full sessions.” Affected vendors include HPE, Supermicro, and Intel (legacy). 3. Predictable session identifiers. Session tokens are generated from counters or from a clock rather than secure random sources. This allows an attacker to predict and take over another user’s live BMC session across both the IPMI service and browser-based KVM consoles. The two most significant bugs are both present in Supermicro systems. 4. Pre-authentication memory corruptions. A length-validation error in the management SSH service is reachable before authentication and can be driven to execute malicious code. Moore found the vulnerabilities in HPE iLO systems. 5. The existence of unsigned or attacker-controllable firmware and unenforced configuration integrity. An authenticated administrator can install a persistent implant or replace the key used to verify firmware. These can be chained to separate authentication bypasses and privilege escalation vulnerabilities. Affected vendors include Supermicro, H3C, and Dell. 6. The use of secrets recoverable from firmware as live credentials. Keys and constants that can be extracted from public firmware can be used to authenticate to, or decrypt traffic from, BMCs. Affected vendors include Supermicro, OpenBMC, Huawei, and Dell. 7. Default and factory-random credentials that can be compromised by hash disclosure made possible through CVE-2013-4786. Frequently, devices continue to use default credentials. Even when the credentials have been changed before shipping, the small keyspaces of factory-randomized passwords make them recoverable in offline cracking attacks. Affected vendors include HPE, Supermicro, and Dell. HPE was the worst (eight digits or alphanum), and Supermicro and Dell use slightly longer defaults, which increase the cost of the attack and may delay the cleartext recovery by hours or days, depending on available compute. While many of the vulnerabilities must be exploited following authentication, that condition generally can be met by exploiting a smaller number of pre-authentication vulnerabilities Moore has identified. In other cases, hackers who gain limited access to a BMC can use it to install an old, unpatched, or backdoored firmware image. Then the hacker can use control of the OS to further tamper with the BMC. Exploiting BMC vulnerabilities isn’t merely a hypothetical possibility. In 2021, researchers discovered ILObleed , a malicious implant that infected HPE servers with wiper firmware that destroyed data stored on hard drives. Even after administrators reinstalled the operating system, swapped out hard drives, or took other common disinfection steps, ILObleed would remain intact and reactivate the disk-wiping attack. The vulnerability the attackers exploited in that campaign had been patched in HPE BMCs four years earlier but hadn’t been installed in the compromised devices. Last year, the Cybersecurity and Infrastructure Security Agency added a critical vulnerability in an AMI BMC to its known list of exploited vulnerabilities. Moore has released an open source tool he called OOBscan. Administrators can use it to scan their entire fleet of servers to detect the growing list of BMC vulnerabilities he has cataloged. Beyond running OOBscan, admins can defend against most of these attacks by doing the following: Set long, unique *usernames* and long, complex passwords Disable IPMI wherever possible Disable KCS wherever possible (block host-side access to the BMC) Isolate each BMC NIC individually, avoid placing multiple on a shared VLAN “BMCs are still an underrated risk,” Moore wrote. “This work points to the ecosystem being well behind the curve in terms of code quality and architecture.” Dan Goodin Senior Security Editor Dan Goodin Senior Security