Join Us At Hacker Summer Camp

Lights Out: Out-of-Band, Out of Mind, Out of Control

LVCC - L1 - Exhibit Hall West 3 - 1006, Main Track 1
Sat, August 8 @ 2pm PDT
lanyard-rope
lanyard-clip

Presented by:

HD Moore

Founder and CEO

Every enterprise server has a second computer you probably forgot about. The baseboard management controller runs its own OS, has its own network stack, and stays on even when the server is off. It speaks IPMI, a protocol from the 1990s that Dan Farmer thoroughly dismantled in 2013. Thirteen years later, nobody went back to check. We did.

We scanned 15,000 internet-facing BMCs and 125,000 across corporate networks, extracted RAKP password hashes from three out of four targets without credentials, and cracked thousands offline. We show how to fingerprint vendors from unauthenticated GUID responses, extract Dell service tags and HPE serial numbers before logging in, and brute-force the "random" passwords that California's SB-327 law was supposed to fix.

Then we show what comes next: pivoting from a compromised host to its BMC over the internal bus without touching the network, jumping to the out-of-band management VLAN, reusing shared credentials across the fleet, and landing on production hosts via Serial-over-LAN and virtual media. The host and BMC are the same physical machine; network segmentation means nothing when the bridge is a PCIe bus.

We release OOBscan, an open-source IPMI exploitation tool, and demonstrate the full attack chain.


More great things from HD

Podcasts
The shadow era AI, exploits, and cybersecurity's 90s comeback
HD Moore explains how AI is turning hacking back to the 90s, generating permanent exploit skeleton keys and breaking traditional defense.
Talks
Identifying exposures at scale with BloodHound OpenGraph
Traditional exposure management misses hidden attack paths. Learn how BloodHound and Cypher queries can uncover vulnerabilities beyond individual...
Podcasts
Know Your Adversary with HD Moore
runZero CEO HD Moore breaks down the myth of air-gapped networks, the impact of AI on security, and why asset connectivity is everything.
Webcasts
Defending in the shadow era: when the CVE feed goes dark
HD Moore walks through the three eras of vulnerability management: the predictable cycles era, the triage ara of AI-scale discovery, and now the...

More Summer Camp Talks!

Tue, August 4 @ 2:00pm -2:30pm (Florentine A)
Mind the Gap: Bridges, Backplanes, and BloodHound
Network segmentation is a critical final line of defense, but enforcing it at scale is an immense challenge. Join HD Moore as he reveals how attackers routinely bypass firewalls by exploiting overlooked, accidental bridges, from technician laptops and smart thermostats to out-of-band management channels and exposed OT backplanes.

In this session, HD will demonstrate how to leverage identity-correlation techniques to catch dual-homed hosts hiding across multiple networks simultaneously. Discover how to feed this raw data into open-source tools like BloodHound Open Graph to map out the true, unfiltered layout of your network.
Learn More
Wed, August 5 @ 12:00pm - 12:45pm (Florentine F)
I am CVE, AMA!

Tod Beardsley returns to BSides Las Vegas to lead a spirited discussion on the past, present, and future of the CVE Program. Joining him is an expert panel featuring program sponsors Katie Trimble-Noble and Lindsey Cerkovnik, vulnerability managers Lisa Olson (MSRC) and Madison Ficorilli (GitHub Advisory DB), and data scientist Jerry Gamblin (RogoLabs).

This year, the mic belongs to you. Bring your burning questions as the panel tackles the CVE program's role in the global cybersecurity ecosystem, how it handles the onslaught of AI-discovered and AI-created vulnerabilities, and its impact from initial research to downstream applications.

Learn More
Wed, August 5 @ 3:35pm - 4:15pm (Oceanside A, Level 2)
Lights Out: BMC's are Still Broken and Now We Have the Receipts

HD Moore uncovers the critical, overlooked threats hiding in your server's BMCs. Drawing from a massive scan of over 140,000 devices, HD reveals that three out of four internet-facing IPMI hosts still leak passwords and system data.

Learn how attackers are using these always-on, highly trusted devices to deploy persistent firmware implants that survive OS reinstalls, and gain access to OOBscan, a brand-new open-source IPMI auditing tool released exclusively during this session.

Learn More

Book some 1:1 time

Meet with us during Summer Camp