BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Lights Out: Out-of-Band\, Out of Mind\, Out of Contr
 ol\n   Tags: DEF CON Official Talk | Demo ðŸ’» | Tool ðŸ›  | Exploit ðŸª²\
 n   When: Saturday\, Aug 8\, 14:00 - 14:59 PDT\n   Where: LVCCW Level 1 Ha
 ll 3 1006 (Main Track 1) and DCTV-1 - [1]Map\n\n   Description:\n\n   Ever
 y enterprise server has a second computer you probably forgot\n   about. T
 he baseboard management controller runs its own OS\, has its\n   own netwo
 rk stack\, and stays on even when the server is off. It speaks\n   IPMI\, 
 a protocol from the 1990s that Dan Farmer thoroughly dismantled\n   in 201
 3. Thirteen years later\, nobody went back to check. We did.\n\n   We scan
 ned 15\,000 internet-facing BMCs and 125\,000 across corporate\n   network
 s\, extracted RAKP password hashes from three out of four\n   targets with
 out credentials\, and cracked thousands offline. We show\n   how to finger
 print vendors from unauthenticated GUID responses\,\n   extract Dell servi
 ce tags and HPE serial numbers before logging in\,\n   and brute-force the
  "random" passwords that California's SB-327 law\n   was supposed to fix.\
 n\n   Then we show what comes next: pivoting from a compromised host to it
 s\n   BMC over the internal bus without touching the network\, jumping to 
 the\n   out-of-band management VLAN\, reusing shared credentials across th
 e\n   fleet\, and landing on production hosts via Serial-over-LAN and virt
 ual\n   media. The host and BMC are the same physical machine\; network\n 
   segmentation means nothing when the bridge is a PCIe bus.\n\n   We relea
 se OOBscan\, an open-source IPMI exploitation tool\, and\n   demonstrate t
 he full attack chain.\n\n   ========================================\n\n\n
 \n   FOUNDATIONAL IPMI RESEARCH (2013-2014)\n   ==========================
 ============\n\n   Dan Farmer - IPMI Security Research Hub http://fish2.co
 m/ipmi/\n\n   Dan Farmer - "IPMI: Freight Train to Hell" (January 2013)\n 
   http://fish2.com/ipmi/itrain.html\n\n   Dan Farmer - "Sold Down the Rive
 r" (June 2014)\n   http://fish2.com/ipmi/river.pdf\n\n   Dan Farmer - IPMI
  Security Best Practices http://fish2.com/ipmi/bp.pdf\n\n   Dan Farmer - C
 racking IPMI Passwords Remotely\n   http://fish2.com/ipmi/remote-pw-cracki
 ng.html\n\n   Dan Farmer - IPMI Tools (GitHub) https://github.com/zenfish/
 ipmi\n\n   HD Moore - "A Penetration Tester's Guide to IPMI and BMCs" (Jul
 y 2013)\n   https://www.rapid7.com/blog/post/2013/07/02/a-penetration-test
 ers-guide-to-ipmi/\n\n   Bonkoski\, Bielber\, Halderman - "Illuminating th
 e Security Issues\n   Surrounding Lights-Out Server Management" (WOOT '13\
 , August 2013)\n   https://jhalderm.com/pub/papers/ipmi-woot13.pdf\n\n   U
 S-CERT Alert TA13-207A - Risks of Using the Intelligent Platform\n   Manag
 ement Interface (IPMI)\n   https://www.cisa.gov/uscert/ncas/alerts/TA13-20
 7A\n\n   CVE-2013-4786 - IPMI 2.0 RAKP Authentication Remote Password Hash
 \n   Retrieval https://nvd.nist.gov/vuln/detail/CVE-2013-4786\n\n   Metasp
 loit IPMI Modules (ipmi_dumphashes\, ipmi_cipher_zero\,\n   ipmi_version)\
 n   https://github.com/rapid7/metasploit-framework/blob/master/documentati
 on/modules/auxiliary/scanner/ipmi/ipmi_dumphashes.md\n\n   ===============
 =========================\n\n\n\n   INTEL ME / AMT VULNERABILITIES\n   ===
 ===========================\n\n   CVE-2017-5689 "Silent Bob is Silent" - I
 ntel AMT Remote Privilege\n   Escalation (CVSS 9.8) https://nvd.nist.gov/v
 uln/detail/CVE-2017-5689\n\n   Intel SA-00075 - Intel Active Management Te
 chnology Elevation of\n   Privilege (May 2017)\n   https://www.intel.com/c
 ontent/www/us/en/security-center/advisory/intel-sa-00075.html\n\n   Intel 
 SA-00086 - Intel ME/SPS/TXE Multiple Vulnerabilities (November\n   2017)\n
    https://www.intel.com/content/www/us/en/security-center/advisory/intel-
 sa-00086.html\n\n   EFF - "Intel's Management Engine is a Security Hazard"
  (May 2017)\n   https://www.eff.org/deeplinks/2017/05/intels-management-en
 gine-security-hazard-and-users-need-way-disable-it\n\n   Wikipedia - Intel
  Management Engine (comprehensive history)\n   https://en.wikipedia.org/wi
 ki/Intel_Management_Engine\n\n   Evdokimov - "Intel AMT Stealth Breakthrou
 gh" (Black Hat USA 2017)\n   https://blackhat.com/docs/us-17/thursday/us-1
 7-Evdokimov-Intel-AMT-Stealth-Breakthrough-wp.pdf\n\n   ==================
 ======================\n\n\n\n   PLATINUM APT - WEAPONIZED OOB MANAGEMENT\
 n   ========================================\n\n   Microsoft - "PLATINUM A
 ctivity Group Using Intel AMT for C2" (June\n   2017)\n   https://www.micr
 osoft.com/en-us/security/blog/2017/06/07/platinum-continues-to-evolve-find
 -ways-to-maintain-invisibility/\n\n   ====================================
 ====\n\n\n\n   ASPEED BMC HARDWARE VULNERABILITIES\n   ===================
 ================\n\n   CVE-2019-6260 "Pantsdown" - ASPEED AST2400/AST2500 
 AHB Bridge\n   Arbitrary R/W (CVSS 9.8)\n   https://nvd.nist.gov/vuln/deta
 il/cve-2019-6260\n\n   Stewart Smith - "CVE-2019-6260: Gaining Control of 
 BMC from the Host\n   Processor" (January 2019)\n   https://www.flamingspo
 rk.com/blog/2019/01/23/cve-2019-6260-gaining-control-of-bmc-from-the-host-
 processor/\n\n   OpenBMC Security Advisory for CVE-2019-6260\n   https://g
 ithub.com/openbmc/openbmc/issues/3475\n\n   Pantsdown Exploit Tool https:/
 /github.com/amboar/cve-2019-6260\n\n   ===================================
 =====\n\n\n\n   ECLYPSIUM BMC RESEARCH (2019-2025)\n   ===================
 ===============\n\n   Eclypsium - "CloudBorne: Bare-Metal Cloud Server Vul
 nerabilities"\n   (2019)\n   https://eclypsium.com/blog/the-ilobleed-impla
 nt-lights-out-management-like-you-wouldnt-believe/\n\n   Eclypsium - "Vuln
 erable Firmware in the Supply Chain" (2019) -\n   Lenovo/Vertiv MergePoint
  EMS\n   https://eclypsium.com/wp-content/uploads/Vulnerable-Firmware-in-t
 he-Supply-Chain.pdf\n\n   Eclypsium - BMC&C Part 1: "Supply Chain Vulnerab
 ilities Put Server\n   Ecosystem At Risk" (December 2022) CVE-2022-40259 (
 RCE via Redfish\n   API)\, CVE-2022-40242\, CVE-2022-2827\n   https://ecly
 psium.com/blog/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/\
 n\n   Eclypsium - BMC&C Part 2: "Lights Out Forever" (July 2023)\n   CVE-2
 023-34329 (CVSS 9.1\, auth bypass via HTTP header spoofing)\,\n   CVE-2023
 -34330 https://eclypsium.com/research/bmcc-lights-out-forever/\n\n   Eclyp
 sium - BMC&C Part 3: AMI MegaRAC Vulnerabilities (March 2025)\n   CVE-2024
 -54085 (CVSS 10.0\, remote auth bypass via Redfish Host\n   Interface)\n  
  https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/\n\n   
 Eclypsium - "CVE-2024-54085 Joins CISA's KEV" (July 2025)\n   https://ecly
 psium.com/blog/bmc-vulnerability-cve-2024-05485-cisa-known-exploited-vulne
 rabilities/\n\n   Eclypsium - Nuclei Templates for AMI MegaRAC Detection (
 July 2025)\n   https://eclypsium.com/blog/eclypsium-releases-tools-for-det
 ecting-ami-megarac-bmc-vulnerabilities/\n\n   Eclypsium - "The iLOBleed Im
 plant" (analysis/commentary)\n   https://eclypsium.com/blog/the-ilobleed-i
 mplant-lights-out-management-like-you-wouldnt-believe/\n\n   =============
 ===========================\n\n\n\n   NVIDIA BMC RESEARCH\n   ============
 =======\n\n   NVIDIA OSR - "Breaking BMC: The Forgotten Key to the Kingdom
 " (DEF CON\n   31\, 2023) 18 vulnerabilities\, 9 exploits\, full chain to 
 persistent\n   firmware implant\n   https://developer.nvidia.com/blog/anal
 yzing-baseboard-management-controllers-to-secure-data-center-infrastructur
 e/\n\n   DEF CON 31 Talk Description (Tereshkin & Zabrocki)\n   https://fo
 rum.defcon.org/node/245714\n\n   ========================================\
 n\n\n\n   iLOBLEED ROOTKIT (2020-2021)\n   ============================\n\
 n   Amnpardaz - "Implant.ARM.iLOBleed.a" Technical Report (December 2021)\
 n   First known in-the-wild BMC firmware implant\n   https://threats.amnpa
 rdaz.com/en/2021/12/28/implant-arm-ilobleed-a/\n\n   Amnpardaz - Full Tech
 nical Analysis PDF\n   https://threats.amnpardaz.com/en/wp-content/uploads
 /sites/5/2021/12/Implant.ARM_.iLOBleed.a-en.pdf\n\n   ====================
 ====================\n\n\n\n   HPE iLO SECURITY RESEARCH & TOOLS\n   =====
 ============================\n\n   CVE-2017-12542 - HPE iLO4 Authenticatio
 n Bypass (CVSS 9.8)\n   https://nvd.nist.gov/vuln/detail/CVE-2017-12542\n\
 n   Airbus Security Lab - "Subverting Your Server Through Its BMC: The HPE
 \n   iLO4 Case" (SSTIC 2018) PÃ©rigaud\, Gazet\, Czarny - firmware analysi
 s\,\n   backdooring\, persistence\n   https://airbus-seclab.github.io/ilo/
 SSTIC2018-Article-subverting_your_server_through_its_bmc_the_hpe_ilo4_case
 -gazet_perigaud_czarny.pdf\n\n   Airbus Security Lab - Presentation Slides
  (SSTIC 2018)\n   https://airbus-seclab.github.io/ilo/SSTIC2018-Slides-EN-
 Backdooring_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-c
 zarny.pdf\n\n   Airbus Security Lab - iLO4/iLO5 Toolbox (firmware analysis
 \,\n   extraction\, exploitation)\n   https://github.com/airbus-seclab/ilo
 4_toolbox\n\n   iLO4 Unlock - Custom firmware patching for HPE iLO4 (fan c
 ontrol\,\n   diagnostics) https://github.com/kendallgoto/ilo4_unlock\n\n  
  ========================================\n\n\n\n   SUPERMICRO IPMI FIRMWA
 RE TOOLS\n   ==============================\n\n   Supermicro IPMI Firmware
  Source Code (GPL release)\n   https://github.com/devicenull/supermicro_ip
 mi_firmware\n\n   IPMI Firmware Tools - Extract\, modify\, and rebuild Sup
 ermicro firmware\n   images https://github.com/devicenull/ipmi_firmware_to
 ols\n\n   smcbmc - Decrypt Supermicro BMC firmware images\n   https://gith
 ub.com/c0d3z3r0/smcbmc\n\n   super-bmc-fw-tools - Decrypt Supermicro BMC f
 irmware (alternative\n   implementation) https://github.com/zt-chen/super-
 bmc-fw-tools\n\n   Supermicro IPMI License Key Generation (reverse enginee
 red)\n   https://github.com/manfromafar/supermicro-ipmi-keygen\n\n   =====
 ===================================\n\n\n\n   JUNGLESEC RANSOMWARE (2018)\
 n   ===========================\n\n   BleepingComputer - "JungleSec Ransom
 ware Infects Victims Through IPMI\n   Remote Consoles" (December 2018)\n  
  https://www.bleepingcomputer.com/news/security/junglesec-ransomware-infec
 ts-victims-through-ipmi-remote-consoles/\n\n   ===========================
 =============\n\n\n\n   GOVERNMENT ADVISORIES\n   =====================\n\
 n   CISA/NSA - "Harden Baseboard Management Controllers" Joint CSI (June\n
    2023)\n   https://media.defense.gov/2023/Jun/14/2003241405/-1/-1/0/CSI_
 HARDEN_BMCS.PDF\n\n   CISA Alert - "CISA and NSA Release Joint Guidance on
  Hardening BMCs"\n   (June 2023)\n   https://www.cisa.gov/news-events/aler
 ts/2023/06/14/cisa-and-nsa-release-joint-guidance-hardening-baseboard-mana
 gement-controllers-bmcs\n\n   NSA Press Release - "NSA and CISA Release Gu
 ide to Protect BMCs" (June\n   2023)\n   https://www.nsa.gov/Press-Room/Pr
 ess-Releases-Statements/Press-Release-View/Article/3426648/nsa-and-cisa-re
 lease-guide-to-protect-baseboard-management-controllers/\n\n   CISA Bindin
 g Operational Directive 23-02 - Mitigating the Risk from\n   Internet-Expo
 sed Management Interfaces (June 2023)\n   https://www.cisa.gov/news-events
 /directives/bod-23-02-mitigating-risk-internet-exposed-management-interfac
 es\n\n   CVE-2024-54085 - Added to CISA Known Exploited Vulnerabilities Ca
 talog\n   (June 2025) https://nvd.nist.gov/vuln/detail/CVE-2024-54085\n\n 
   ========================================\n\n\n\n   CALIFORNIA SB-327 IoT
  SECURITY LAW\n   ==================================\n\n   SB-327 Bill Tex
 t - California Legislative Information\n   https://leginfo.legislature.ca.
 gov/faces/billTextClient.xhtml?bill_id=201720180SB327\n\n   ==============
 ==========================\n\n\n\n   IPMI SPECIFICATION\n   ==============
 ====\n\n   IPMI v2.0 Specification (Intel\, maintained by DMTF)\n   https:
 //www.intel.com/content/www/us/en/products/docs/servers/ipmi/ipmi-second-g
 en-interface-spec-v2-rev1-1.html\n\n   ===================================
 =====\n\n\n\n   CRACKING TOOLS\n   ==============\n\n   Hashcat - Mode 730
 0: IPMI2 RAKP HMAC-SHA1\n   https://hashcat.net/wiki/doku.php?id=example_h
 ashes\n\n   John the Ripper (bleeding-jumbo branch) - IPMI RAKP support\n 
   https://github.com/openwall/john\n\n   =================================
 =======\n\n\n\n   ADDITIONAL BMC VULNERABILITY REFERENCES\n   ============
 ===========================\n\n   CVE-2022-40259 - AMI MegaRAC Arbitrary C
 ode Execution via Redfish API\n   https://nvd.nist.gov/vuln/detail/CVE-202
 2-40259\n\n   CVE-2023-34329 - AMI MegaRAC Auth Bypass via HTTP Header Spo
 ofing\n   (CVSS 9.1) https://nvd.nist.gov/vuln/detail/CVE-2023-34329\n\n  
  CVE-2018-7078 - HPE iLO4/iLO5 Remote Code Execution\n   https://nvd.nist.
 gov/vuln/detail/CVE-2018-7078\n\n   CVE-2018-7113 - HPE iLO5 Secure Boot B
 ypass\n   https://nvd.nist.gov/vuln/detail/CVE-2018-7113\n\n   CVE-2021-29
 202 - HPE iLO Host-to-iLO Arbitrary Code Execution\n   https://nvd.nist.go
 v/vuln/detail/CVE-2021-29202\n\n   =======================================
 =\n\n\n\n   RELATED TOOLS\n   =============\n\n   ipmitool - Standard open
 -source IPMI management utility\n   https://github.com/ipmitool/ipmitool\n
 \n   PCILeech - Direct Memory Access (DMA) attack toolkit (relevant to\n  
  BMC-host trust) https://github.com/ufrisk/pcileech\n\n   Shadowserver Fou
 ndation - Open IPMI Report (ongoing internet scanning)\n   https://www.sha
 dowserver.org/what-we-do/network-reporting/open-ipmi-report/\n\n   Speaker
 Bio:  HD "hdm" Moore\n\n   HD Moore is a pioneer of the cybersecurity indu
 stry who has dedicated\n   his career to vulnerability research\, network 
 discovery\, and software\n   development since the 1990s. He is most recog
 nized for creating\n   Metasploit and is a passionate advocate for open-so
 urce software and\n   vulnerability disclosure. HD serves as the CEO and f
 ounder of runZero\,\n   a provider of cutting-edge exposure management sof
 tware and cloud\n   services that helps organizations minimize risk across
  their total\n   attack surface. Prior to founding runZero\, he held leade
 rship\n   positions at Atredis Partners\, Rapid7\, and BreakingPoint. HD's
 \n   professional journey began with exploring telephone networks\,\n   de
 veloping exploits for the Department of Defense\, and hacking into\n   fin
 ancial institution networks. When he's not working\, he enjoys\n   hacking
  on weird Go projects\, building janky electronics\, running in\n   circle
 s\, and playing single-player RPGs.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n
 \n\n
DTEND:20260808T215900Z
DTSTART:20260808T210000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-
 1
SUMMARY:Lights Out: Out-of-Band\, Out of Mind\, Out of Control
END:VEVENT
END:VCALENDAR
