<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>BMC on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/bmc/</link><description>Recent content in BMC on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 30 Jul 2026 14:08:32 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/bmc/index.xml" rel="self" type="application/rss+xml"/><item><title>IPMI Flaw Leaks Password Hashes From 24,650 Exposed Servers</title><link>https://hackingpassion.com/ipmi-bmc-password-hash-exposed-servers/</link><pubDate>Thu, 30 Jul 2026 14:08:32 +0200</pubDate><guid>https://hackingpassion.com/ipmi-bmc-password-hash-exposed-servers/</guid><description>&lt;p>A flaw more than 20 years old just left &lt;strong>36,872&lt;/strong> servers reachable straight from the internet. Not the websites they run, the servers themselves, through the one small chip that controls them even when they are powered down. Of those, &lt;strong>24,650&lt;/strong> handed over what an attacker needs to crack their password, before a single person had logged in, and there is no patch on the way. 🧐&lt;/p>
&lt;p>Server-class machines carry a second, smaller computer built onto the motherboard. It has its own processor, its own network port, and its own power, and it runs whether the server is switched on or off. Its job is to let an administrator manage the machine from far away: power it on, reboot it, reinstall it, watch the screen, all without walking into the data center. Different brands give it different names, iLO, iDRAC, or just the IPMI interface, but underneath it is the same part, a &lt;strong>baseboard management controller&lt;/strong>, a &lt;strong>BMC&lt;/strong>.&lt;/p></description></item></channel></rss>