Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Warning for those who use Supermicro IPMI View GUI
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Warning for those who use Supermicro IPMI View GUI

ssftssft Member
edited April 2017 in General

I wanted to ensure my IPMI credentials were still encrypted using the GUI vs https. Ran a Wireshark to follow the whole process. RMCP+ /w encryption was forced on, and everything was encrypted...until I opened the KVM console.

This loads up a very similar java vm console as the https site would do, albeit with less hassle. However there is a big difference between the two. During the beginning of the VNC connection to port 5900, my IPMI username and password were passed in clear text. Clear as day, doing a string search in the capture there was my password.

I then ran a capture doing it the https way. Almost the same thing happens, it launches the java vm and establishes a VNC connection to port 5900...except my id and pwd was nowhere to be seen. It appears to pass a randomly generated id/pwd, or some other method is used however what I know for sure is my password is not found anywhere in the trace.

Additionally as far as the VNC session goes, I don't think it's encrypted either scenario...something to keep in mind. At least though my username and password isn't passed in clear text when launching the KVM console via the site vs IPMI View GUI. In case anyone is interested, using IPMI View 2.12.0 connecting to a Supermicro IPMI running fw 3.27.

Comments

  • ClouviderClouvider Member, Patron Provider

    Your IPMI fw versions doesn't matter anything without the board model.

  • WSSWSS Member

    HOLY SHIT VNC ISN'T ENCRYPTED?

    STOP THE PRESS!

    Wait, is it 2000 again?

    Thanked by 1Corey
  • ssftssft Member

    @Clouvider said:
    Your IPMI fw versions doesn't matter anything without the board model.

    X10SLM-F

Sign In or Register to comment.