Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. WebUSBWebGPUWebPCIEWebNVMEWebSATAWebATX12V

WebUSBWebGPUWebPCIEWebNVMEWebSATAWebATX12V

Geplant Angeheftet Gesperrt Verschoben Uncategorized
61 Beiträge 30 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • manawyrm@chaos.socialM manawyrm@chaos.social

    @littlefox @volpeon less fortunate: they also fucked up the permissions checks on that websocket in a bunch of BMCs.

    You can send arbitrary SCSI packets to the host system with this mechanism...
    Both Linux and Windows really aren't hardened against evil block storage devices.

    Imagine the rest of the story.

    littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
    littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
    littlefox@gotosocial-dev.svc.0x0a.network
    schrieb zuletzt editiert von
    #22

    @manawyrm @volpeon gnihihihihihi 😆

    1 Antwort Letzte Antwort
    0
    • manawyrm@chaos.socialM manawyrm@chaos.social

      @littlefox @volpeon less fortunate: they also fucked up the permissions checks on that websocket in a bunch of BMCs.

      You can send arbitrary SCSI packets to the host system with this mechanism...
      Both Linux and Windows really aren't hardened against evil block storage devices.

      Imagine the rest of the story.

      athenas@hachyderm.ioA This user is from outside of this forum
      athenas@hachyderm.ioA This user is from outside of this forum
      athenas@hachyderm.io
      schrieb zuletzt editiert von
      #23

      @manawyrm @littlefox @volpeon It sounds bad but is it really? If you have BMC access you would be able to do all sorts of evil things already.
      Unless there is an ACL system which pretends this is “safe”…

      manawyrm@chaos.socialM 1 Antwort Letzte Antwort
      0
      • manawyrm@chaos.socialM manawyrm@chaos.social

        @littlefox @volpeon less fortunate: they also fucked up the permissions checks on that websocket in a bunch of BMCs.

        You can send arbitrary SCSI packets to the host system with this mechanism...
        Both Linux and Windows really aren't hardened against evil block storage devices.

        Imagine the rest of the story.

        spacekatia@girlcock.clubS This user is from outside of this forum
        spacekatia@girlcock.clubS This user is from outside of this forum
        spacekatia@girlcock.club
        schrieb zuletzt editiert von
        #24

        @manawyrm this is beautiful o.o

        1 Antwort Letzte Antwort
        0
        • athenas@hachyderm.ioA athenas@hachyderm.io

          @manawyrm @littlefox @volpeon It sounds bad but is it really? If you have BMC access you would be able to do all sorts of evil things already.
          Unless there is an ACL system which pretends this is “safe”…

          manawyrm@chaos.socialM This user is from outside of this forum
          manawyrm@chaos.socialM This user is from outside of this forum
          manawyrm@chaos.social
          schrieb zuletzt editiert von
          #25

          @athenas @littlefox @volpeon Yes, there is access control with username/password or even LDAP, which might be used by badly informed users.

          But yes, the correct response is to _ALWAYS_ firewall and heavily isolate BMCs, consider them hostile and dangerous at all times.

          Their firmware is sooo shoddily written that they're basically remote code execution as a service.

          athenas@hachyderm.ioA viss@mastodon.socialV 2 Antworten Letzte Antwort
          0
          • manawyrm@chaos.socialM manawyrm@chaos.social

            @athenas @littlefox @volpeon Yes, there is access control with username/password or even LDAP, which might be used by badly informed users.

            But yes, the correct response is to _ALWAYS_ firewall and heavily isolate BMCs, consider them hostile and dangerous at all times.

            Their firmware is sooo shoddily written that they're basically remote code execution as a service.

            athenas@hachyderm.ioA This user is from outside of this forum
            athenas@hachyderm.ioA This user is from outside of this forum
            athenas@hachyderm.io
            schrieb zuletzt editiert von
            #26

            @manawyrm @littlefox @volpeon I was thinking of fine-grained ACL, where somebody could get the idea of “just mounting CDROMs is suuurely safe”.

            Other than that, that’s my mental model around them as well

            1 Antwort Letzte Antwort
            0
            • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

              WebUSB
              WebGPU
              WebPCIE
              WebNVME
              WebSATA
              WebATX12V

              tsia_@chaos.socialT This user is from outside of this forum
              tsia_@chaos.socialT This user is from outside of this forum
              tsia_@chaos.social
              schrieb zuletzt editiert von
              #27

              @volpeon WebSCSI

              https://chaos.social/@manawyrm/115972694235993598

              1 Antwort Letzte Antwort
              0
              • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

                WebUSB
                WebGPU
                WebPCIE
                WebNVME
                WebSATA
                WebATX12V

                f4grx@chaos.socialF This user is from outside of this forum
                f4grx@chaos.socialF This user is from outside of this forum
                f4grx@chaos.social
                schrieb zuletzt editiert von
                #28

                @volpeon there's also WebSerial.

                1 Antwort Letzte Antwort
                0
                • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

                  WebUSB
                  WebGPU
                  WebPCIE
                  WebNVME
                  WebSATA
                  WebATX12V

                  shia@mk.absturztau.beS This user is from outside of this forum
                  shia@mk.absturztau.beS This user is from outside of this forum
                  shia@mk.absturztau.be
                  schrieb zuletzt editiert von
                  #29

                  @volpeon@icy.wyvern.rip WEBYuri anyone?

                  1 Antwort Letzte Antwort
                  0
                  • manawyrm@chaos.socialM manawyrm@chaos.social

                    @littlefox @volpeon less fortunate: they also fucked up the permissions checks on that websocket in a bunch of BMCs.

                    You can send arbitrary SCSI packets to the host system with this mechanism...
                    Both Linux and Windows really aren't hardened against evil block storage devices.

                    Imagine the rest of the story.

                    wildduck@mamot.frW This user is from outside of this forum
                    wildduck@mamot.frW This user is from outside of this forum
                    wildduck@mamot.fr
                    schrieb zuletzt editiert von
                    #30

                    @manawyrm @littlefox @volpeon 😍💀

                    1 Antwort Letzte Antwort
                    0
                    • manawyrm@chaos.socialM manawyrm@chaos.social

                      @littlefox @volpeon
                      *sigh*
                      OK, you wanted it:

                      AMI MegaRAC (the BMC web UI for servers) has this feature where they allow you to select a .iso image for a CD-ROM in the web console (next to the KVM/VNC viewer).

                      How did they implement the CD-ROM emulation?
                      They open a WebSockets connection to the BMC, emulate a SCSI CD-ROM drive in JavaScript (!) and send raw SCSI packets back&forth via WebSockets, which the BMC then forwards via internal USB to the host system.

                      awooo@floofy.techA This user is from outside of this forum
                      awooo@floofy.techA This user is from outside of this forum
                      awooo@floofy.tech
                      schrieb zuletzt editiert von
                      #31

                      @manawyrm @littlefox @volpeon fun fact, the iDRAC virtual console is (slightly modified) VNC over a websocket

                      wolf480pl@mstdn.ioW 1 Antwort Letzte Antwort
                      0
                      • manawyrm@chaos.socialM manawyrm@chaos.social

                        @athenas @littlefox @volpeon Yes, there is access control with username/password or even LDAP, which might be used by badly informed users.

                        But yes, the correct response is to _ALWAYS_ firewall and heavily isolate BMCs, consider them hostile and dangerous at all times.

                        Their firmware is sooo shoddily written that they're basically remote code execution as a service.

                        viss@mastodon.socialV This user is from outside of this forum
                        viss@mastodon.socialV This user is from outside of this forum
                        viss@mastodon.social
                        schrieb zuletzt editiert von
                        #32

                        @athenas @littlefox @volpeon @manawyrm inam reminded of int80s and travis goodspeeds antiforensics talks where they rewrote hard drive firmware to behave differently when they detected forensic sequential reads after a certain thresshold. 'hard drives are just tiny embedded linux devices'

                        1 Antwort Letzte Antwort
                        0
                        • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

                          @manawyrm @volpeon tell me more. I crave more.

                          elfin@mstdn.socialE This user is from outside of this forum
                          elfin@mstdn.socialE This user is from outside of this forum
                          elfin@mstdn.social
                          schrieb zuletzt editiert von
                          #33

                          @littlefox @manawyrm @volpeon You really don't.

                          littlefox@gotosocial-dev.svc.0x0a.networkL 1 Antwort Letzte Antwort
                          0
                          • manawyrm@chaos.socialM manawyrm@chaos.social

                            @littlefox @volpeon
                            *sigh*
                            OK, you wanted it:

                            AMI MegaRAC (the BMC web UI for servers) has this feature where they allow you to select a .iso image for a CD-ROM in the web console (next to the KVM/VNC viewer).

                            How did they implement the CD-ROM emulation?
                            They open a WebSockets connection to the BMC, emulate a SCSI CD-ROM drive in JavaScript (!) and send raw SCSI packets back&forth via WebSockets, which the BMC then forwards via internal USB to the host system.

                            elfin@mstdn.socialE This user is from outside of this forum
                            elfin@mstdn.socialE This user is from outside of this forum
                            elfin@mstdn.social
                            schrieb zuletzt editiert von
                            #34

                            @manawyrm @littlefox @volpeon Aaaaargh!

                            1 Antwort Letzte Antwort
                            0
                            • elfin@mstdn.socialE elfin@mstdn.social

                              @littlefox @manawyrm @volpeon You really don't.

                              littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                              littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                              littlefox@gotosocial-dev.svc.0x0a.network
                              schrieb zuletzt editiert von
                              #35

                              @elfin @manawyrm @volpeon I need all the knowledge 😆

                              elfin@mstdn.socialE 1 Antwort Letzte Antwort
                              0
                              • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

                                @elfin @manawyrm @volpeon I need all the knowledge 😆

                                elfin@mstdn.socialE This user is from outside of this forum
                                elfin@mstdn.socialE This user is from outside of this forum
                                elfin@mstdn.social
                                schrieb zuletzt editiert von
                                #36

                                @littlefox @manawyrm @volpeon Some things just aren't healthy.

                                littlefox@gotosocial-dev.svc.0x0a.networkL 1 Antwort Letzte Antwort
                                0
                                • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

                                  WebUSB
                                  WebGPU
                                  WebPCIE
                                  WebNVME
                                  WebSATA
                                  WebATX12V

                                  jcm@wafrn.jcm.reJ This user is from outside of this forum
                                  jcm@wafrn.jcm.reJ This user is from outside of this forum
                                  jcm@wafrn.jcm.re
                                  schrieb zuletzt editiert von
                                  #37

                                  WebMMIO to rule all of them!

                                  1 Antwort Letzte Antwort
                                  0
                                  • elfin@mstdn.socialE elfin@mstdn.social

                                    @littlefox @manawyrm @volpeon Some things just aren't healthy.

                                    littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                                    littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                                    littlefox@gotosocial-dev.svc.0x0a.network
                                    schrieb zuletzt editiert von
                                    #38

                                    @elfin @manawyrm @volpeon I know 😆
                                    I never claimed this was healthy 😆

                                    elfin@mstdn.socialE 1 Antwort Letzte Antwort
                                    0
                                    • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

                                      @elfin @manawyrm @volpeon I know 😆
                                      I never claimed this was healthy 😆

                                      elfin@mstdn.socialE This user is from outside of this forum
                                      elfin@mstdn.socialE This user is from outside of this forum
                                      elfin@mstdn.social
                                      schrieb zuletzt editiert von
                                      #39

                                      @littlefox @manawyrm @volpeon Fair enough.

                                      I've worked on some storage in my day and I have seen some shady shit ... but that kludge is horrific.

                                      manawyrm@chaos.socialM 1 Antwort Letzte Antwort
                                      0
                                      • elfin@mstdn.socialE elfin@mstdn.social

                                        @littlefox @manawyrm @volpeon Fair enough.

                                        I've worked on some storage in my day and I have seen some shady shit ... but that kludge is horrific.

                                        manawyrm@chaos.socialM This user is from outside of this forum
                                        manawyrm@chaos.socialM This user is from outside of this forum
                                        manawyrm@chaos.social
                                        schrieb zuletzt editiert von
                                        #40

                                        @elfin @littlefox @volpeon Littlefox knows me long enough to know that when I say: „oh god“, things are really bad 😹🤭

                                        littlefox@gotosocial-dev.svc.0x0a.networkL 1 Antwort Letzte Antwort
                                        0
                                        • manawyrm@chaos.socialM manawyrm@chaos.social

                                          @elfin @littlefox @volpeon Littlefox knows me long enough to know that when I say: „oh god“, things are really bad 😹🤭

                                          littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                                          littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                                          littlefox@gotosocial-dev.svc.0x0a.network
                                          schrieb zuletzt editiert von
                                          #41

                                          @manawyrm @elfin @volpeon 😆

                                          manawyrm@chaos.socialM 1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum