Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. WebUSBWebGPUWebPCIEWebNVMEWebSATAWebATX12V

WebUSBWebGPUWebPCIEWebNVMEWebSATAWebATX12V

Geplant Angeheftet Gesperrt Verschoben Uncategorized
61 Beiträge 30 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

    WebUSB
    WebGPU
    WebPCIE
    WebNVME
    WebSATA
    WebATX12V

    littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
    littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
    littlefox@gotosocial-dev.svc.0x0a.network
    schrieb zuletzt editiert von
    #7

    @volpeon WebAM5

    littlefox@gotosocial-dev.svc.0x0a.networkL 1 Antwort Letzte Antwort
    0
    • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

      @volpeon WebAM5

      littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
      littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
      littlefox@gotosocial-dev.svc.0x0a.network
      schrieb zuletzt editiert von
      #8

      @volpeon WebGDDR6

      littlefox@gotosocial-dev.svc.0x0a.networkL 1 Antwort Letzte Antwort
      0
      • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

        @volpeon WebGDDR6

        littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
        littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
        littlefox@gotosocial-dev.svc.0x0a.network
        schrieb zuletzt editiert von
        #9

        @volpeon

        WebSPI
        WebBIOS
        WebUEFI

        volpeon@icy.wyvern.ripV airtower@woem.menA 2 Antworten Letzte Antwort
        0
        • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

          WebUSB
          WebGPU
          WebPCIE
          WebNVME
          WebSATA
          WebATX12V

          neon@catgirl.centerN This user is from outside of this forum
          neon@catgirl.centerN This user is from outside of this forum
          neon@catgirl.center
          schrieb zuletzt editiert von
          #10

          @volpeon@icy.wyvern.rip Web12VHPWR


          OH GOD ITS BURNING

          1 Antwort Letzte Antwort
          0
          • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

            @manawyrm @volpeon oh no

            manawyrm@chaos.socialM This user is from outside of this forum
            manawyrm@chaos.socialM This user is from outside of this forum
            manawyrm@chaos.social
            schrieb zuletzt editiert von
            #11

            @littlefox @volpeon

            if you don't know more details: be thankful for that and pretend you didn't hear anything.

            if you do know more details: i'm truely sorry for you.

            littlefox@gotosocial-dev.svc.0x0a.networkL 1 Antwort Letzte Antwort
            0
            • manawyrm@chaos.socialM manawyrm@chaos.social

              @littlefox @volpeon

              if you don't know more details: be thankful for that and pretend you didn't hear anything.

              if you do know more details: i'm truely sorry for you.

              littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
              littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
              littlefox@gotosocial-dev.svc.0x0a.network
              schrieb zuletzt editiert von
              #12

              @manawyrm @volpeon tell me more. I crave more.

              manawyrm@chaos.socialM elfin@mstdn.socialE 2 Antworten Letzte Antwort
              0
              • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

                WebUSB
                WebGPU
                WebPCIE
                WebNVME
                WebSATA
                WebATX12V

                mica@mk.absturztau.beM This user is from outside of this forum
                mica@mk.absturztau.beM This user is from outside of this forum
                mica@mk.absturztau.be
                schrieb zuletzt editiert von
                #13

                @volpeon@icy.wyvern.rip Power over WebSocket

                1 Antwort Letzte Antwort
                0
                • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

                  @volpeon

                  WebSPI
                  WebBIOS
                  WebUEFI

                  volpeon@icy.wyvern.ripV This user is from outside of this forum
                  volpeon@icy.wyvern.ripV This user is from outside of this forum
                  volpeon@icy.wyvern.rip
                  schrieb zuletzt editiert von
                  #14

                  @littlefox WebRing0

                  littlefox@gotosocial-dev.svc.0x0a.networkL 1 Antwort Letzte Antwort
                  0
                  • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

                    @littlefox WebRing0

                    littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                    littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                    littlefox@gotosocial-dev.svc.0x0a.network
                    schrieb zuletzt editiert von
                    #15

                    @volpeon WebSMM

                    1 Antwort Letzte Antwort
                    0
                    • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

                      WebUSB
                      WebGPU
                      WebPCIE
                      WebNVME
                      WebSATA
                      WebATX12V

                      ori@woem.menO This user is from outside of this forum
                      ori@woem.menO This user is from outside of this forum
                      ori@woem.men
                      schrieb zuletzt editiert von
                      #16

                      @volpeon@icy.wyvern.rip WebExpressCard

                      1 Antwort Letzte Antwort
                      0
                      • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

                        @volpeon

                        WebSPI
                        WebBIOS
                        WebUEFI

                        airtower@woem.menA This user is from outside of this forum
                        airtower@woem.menA This user is from outside of this forum
                        airtower@woem.men
                        schrieb zuletzt editiert von
                        #17

                        @littlefox@gotosocial-dev.svc.0x0a.network @volpeon@icy.wyvern.rip ​​

                        1 Antwort Letzte Antwort
                        0
                        • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

                          @manawyrm @volpeon tell me more. I crave more.

                          manawyrm@chaos.socialM This user is from outside of this forum
                          manawyrm@chaos.socialM This user is from outside of this forum
                          manawyrm@chaos.social
                          schrieb zuletzt editiert von
                          #18

                          @littlefox @volpeon
                          *sigh*
                          OK, you wanted it:

                          AMI MegaRAC (the BMC web UI for servers) has this feature where they allow you to select a .iso image for a CD-ROM in the web console (next to the KVM/VNC viewer).

                          How did they implement the CD-ROM emulation?
                          They open a WebSockets connection to the BMC, emulate a SCSI CD-ROM drive in JavaScript (!) and send raw SCSI packets back&forth via WebSockets, which the BMC then forwards via internal USB to the host system.

                          littlefox@gotosocial-dev.svc.0x0a.networkL awooo@floofy.techA elfin@mstdn.socialE mxshift@social.treehouse.systemsM ellie@ellieayla.netE 7 Antworten Letzte Antwort
                          0
                          • volpeon@icy.wyvern.ripV volpeon@icy.wyvern.rip

                            WebUSB
                            WebGPU
                            WebPCIE
                            WebNVME
                            WebSATA
                            WebATX12V

                            legion495@mk.absturztau.beL This user is from outside of this forum
                            legion495@mk.absturztau.beL This user is from outside of this forum
                            legion495@mk.absturztau.be
                            schrieb zuletzt editiert von
                            #19

                            @volpeon@icy.wyvern.rip WebDOCSIS

                            1 Antwort Letzte Antwort
                            0
                            • manawyrm@chaos.socialM manawyrm@chaos.social

                              @littlefox @volpeon
                              *sigh*
                              OK, you wanted it:

                              AMI MegaRAC (the BMC web UI for servers) has this feature where they allow you to select a .iso image for a CD-ROM in the web console (next to the KVM/VNC viewer).

                              How did they implement the CD-ROM emulation?
                              They open a WebSockets connection to the BMC, emulate a SCSI CD-ROM drive in JavaScript (!) and send raw SCSI packets back&forth via WebSockets, which the BMC then forwards via internal USB to the host system.

                              littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                              littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                              littlefox@gotosocial-dev.svc.0x0a.network
                              schrieb zuletzt editiert von
                              #20

                              @manawyrm @volpeon oh goth it's beautiful I love it

                              manawyrm@chaos.socialM 1 Antwort Letzte Antwort
                              0
                              • littlefox@gotosocial-dev.svc.0x0a.networkL littlefox@gotosocial-dev.svc.0x0a.network

                                @manawyrm @volpeon oh goth it's beautiful I love it

                                manawyrm@chaos.socialM This user is from outside of this forum
                                manawyrm@chaos.socialM This user is from outside of this forum
                                manawyrm@chaos.social
                                schrieb zuletzt editiert von
                                #21

                                @littlefox @volpeon less fortunate: they also fucked up the permissions checks on that websocket in a bunch of BMCs.

                                You can send arbitrary SCSI packets to the host system with this mechanism...
                                Both Linux and Windows really aren't hardened against evil block storage devices.

                                Imagine the rest of the story.

                                littlefox@gotosocial-dev.svc.0x0a.networkL athenas@hachyderm.ioA spacekatia@girlcock.clubS wildduck@mamot.frW lino@chaos.socialL 6 Antworten Letzte Antwort
                                1
                                0
                                • manawyrm@chaos.socialM manawyrm@chaos.social

                                  @littlefox @volpeon less fortunate: they also fucked up the permissions checks on that websocket in a bunch of BMCs.

                                  You can send arbitrary SCSI packets to the host system with this mechanism...
                                  Both Linux and Windows really aren't hardened against evil block storage devices.

                                  Imagine the rest of the story.

                                  littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                                  littlefox@gotosocial-dev.svc.0x0a.networkL This user is from outside of this forum
                                  littlefox@gotosocial-dev.svc.0x0a.network
                                  schrieb zuletzt editiert von
                                  #22

                                  @manawyrm @volpeon gnihihihihihi 😆

                                  1 Antwort Letzte Antwort
                                  0
                                  • manawyrm@chaos.socialM manawyrm@chaos.social

                                    @littlefox @volpeon less fortunate: they also fucked up the permissions checks on that websocket in a bunch of BMCs.

                                    You can send arbitrary SCSI packets to the host system with this mechanism...
                                    Both Linux and Windows really aren't hardened against evil block storage devices.

                                    Imagine the rest of the story.

                                    athenas@hachyderm.ioA This user is from outside of this forum
                                    athenas@hachyderm.ioA This user is from outside of this forum
                                    athenas@hachyderm.io
                                    schrieb zuletzt editiert von
                                    #23

                                    @manawyrm @littlefox @volpeon It sounds bad but is it really? If you have BMC access you would be able to do all sorts of evil things already.
                                    Unless there is an ACL system which pretends this is “safe”…

                                    manawyrm@chaos.socialM 1 Antwort Letzte Antwort
                                    0
                                    • manawyrm@chaos.socialM manawyrm@chaos.social

                                      @littlefox @volpeon less fortunate: they also fucked up the permissions checks on that websocket in a bunch of BMCs.

                                      You can send arbitrary SCSI packets to the host system with this mechanism...
                                      Both Linux and Windows really aren't hardened against evil block storage devices.

                                      Imagine the rest of the story.

                                      spacekatia@girlcock.clubS This user is from outside of this forum
                                      spacekatia@girlcock.clubS This user is from outside of this forum
                                      spacekatia@girlcock.club
                                      schrieb zuletzt editiert von
                                      #24

                                      @manawyrm this is beautiful o.o

                                      1 Antwort Letzte Antwort
                                      0
                                      • athenas@hachyderm.ioA athenas@hachyderm.io

                                        @manawyrm @littlefox @volpeon It sounds bad but is it really? If you have BMC access you would be able to do all sorts of evil things already.
                                        Unless there is an ACL system which pretends this is “safe”…

                                        manawyrm@chaos.socialM This user is from outside of this forum
                                        manawyrm@chaos.socialM This user is from outside of this forum
                                        manawyrm@chaos.social
                                        schrieb zuletzt editiert von
                                        #25

                                        @athenas @littlefox @volpeon Yes, there is access control with username/password or even LDAP, which might be used by badly informed users.

                                        But yes, the correct response is to _ALWAYS_ firewall and heavily isolate BMCs, consider them hostile and dangerous at all times.

                                        Their firmware is sooo shoddily written that they're basically remote code execution as a service.

                                        athenas@hachyderm.ioA viss@mastodon.socialV 2 Antworten Letzte Antwort
                                        0
                                        • manawyrm@chaos.socialM manawyrm@chaos.social

                                          @athenas @littlefox @volpeon Yes, there is access control with username/password or even LDAP, which might be used by badly informed users.

                                          But yes, the correct response is to _ALWAYS_ firewall and heavily isolate BMCs, consider them hostile and dangerous at all times.

                                          Their firmware is sooo shoddily written that they're basically remote code execution as a service.

                                          athenas@hachyderm.ioA This user is from outside of this forum
                                          athenas@hachyderm.ioA This user is from outside of this forum
                                          athenas@hachyderm.io
                                          schrieb zuletzt editiert von
                                          #26

                                          @manawyrm @littlefox @volpeon I was thinking of fine-grained ACL, where somebody could get the idea of “just mounting CDROMs is suuurely safe”.

                                          Other than that, that’s my mental model around them as well

                                          1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum