Eclypsium Company
Kumwe kuongorora kwakaratidza kuti matambudziko aya anokanganisawo firmware yeBMC controllers inoshandiswa muGigabyte Enterprise Servers server mapuratifomu, ayo anoshandiswawo mumaseva kubva kumakambani akadai seAcer, AMAX, Bigtera, Ciara, Penguin Computing uye sysGen. Iwo ane dambudziko BMC controllers akashandisa panjodzi MergePoint EMS firmware yakagadziriswa neyechitatu-bato mutengesi Avocent (ikozvino kupatsanurwa kweVertiv).
Kusagadzikana kwekutanga kunokonzerwa nekushaikwa kwekriptographic verification yekurodha firmware updates (chete CRC32 checksum verification ndiyo inoshandiswa, zvinopesana.
Kusagadzikana kwechipiri kuripo mune firmware yekuvandudza kodhi uye inobvumidza iwe kutsiva yako mirairo, iyo inozoitwa muBMC nepamusoro-soro ropafadzo. Kuti urwise, zvakakwana kushandura kukosha kweRemoteFirmwareImageFilePath parameter mu bmcfwu.cfg configuration file, iyo nzira inoenda kumufananidzo we firmware yakagadziridzwa inotsanangurwa. Munguva yekuvandudza kunotevera, iyo inogona kutangwa nemurairo muIPMI, iyi parameter ichagadziriswa neBMC uye inoshandiswa sechikamu chepopen () kufona sechikamu chemutsara we /bin/sh. Sezvo mutsara wekugadzira iyo shell yekuraira wakagadzirwa uchishandisa iyo snprintf () kufona pasina kucheneswa kwakaringana kwemavara akakosha, vanorwisa vanogona kutsiva kodhi yavo kuti vauraye. Kuti utore kusazvibata, unofanirwa kuve nekodzero dzinokutendera kuti utumire murairo kune BMC controller kuburikidza neIPMI (kana uine kodzero dzemaneja pane server, unogona kutumira IPMI kuraira pasina humwe humbowo).
Gigabyte naLenovo vakaziviswa nezvematambudziko kumashure muna Chikunguru 2018 uye vakakwanisa kuburitsa zvigadziriso ruzivo rwusati rwaburitswa pachena. Lenovo kambani
Musi waChivabvu 8 wegore rino, Gigabyte yakaburitsa zvigadziriso zvemabhobho eamai neASPEED AST2500 controller, asi seLenovo, yakangogadzirisa kusagadzikana kwemirairo. Mabhodhi ari munjodzi akavakirwa paASPEED AST2400 anoramba asina zvigadziriso izvozvi. Gigabyte zvakare
Ngatiyeukei kuti BMC inyanzvi inodzora yakaiswa mumaseva, ine yayo CPU, ndangariro, chengetedzo uye sensor polling interfaces, iyo inopa yakaderera-level interface yekutarisa uye kutonga server midziyo. Uchishandisa BMC, zvisinei neiyo inoshanda sisitimu inoshanda pane sevha, unogona kutarisa mamiriro emasensa, maneja simba, firmware uye disks, kuronga kure kure booting pamusoro petiweki, simbisa kushanda kweiyo kure yekuwana console, nezvimwe.
Source: opennet.ru