The great mistake is that those servers have a management Ethernet interface connected to the Internet.
The management Ethernet port of a server, on which it listens for the IPMI protocol, is supposed to be connected only to a dedicated internal management network, which must be separated from the Internet, and also from the normal internal networks.
It is not expected that IPMI is secure. Security is supposed to be achieved by physical separation.
I find it quite amusing what the so called security researches did spend the time to obscure the serial number 'CZ2D3J01XT' of their 'HPE ProLiant DL380 Gen11' server.
4 comments
[ 0.26 ms ] story [ 7.3 ms ] threadHow sure are we that it was an accident to share password hashes with the world?
The management Ethernet port of a server, on which it listens for the IPMI protocol, is supposed to be connected only to a dedicated internal management network, which must be separated from the Internet, and also from the normal internal networks.
It is not expected that IPMI is secure. Security is supposed to be achieved by physical separation.