Introducing FORGE: A Practical Security Framework for Data Centers And AI InfrastructureExplore FORGE
Data Center Exposure Alert

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

An aggregate view of internet-exposed management controllers across the world.

The finding

Every server has a second computer inside it. Most teams never watch it.

A BMC (Baseboard Management Controller) is a dedicated processor on nearly every server. It can power the machine on or off, mount virtual media, reinstall it, open a remote console, and change low-level platform configuration - even when the operating system is down. When it faces the internet, it is one of the most powerful doors into a data center, and it sits beneath everything your security stack can see.

01 · exposed

36,000 reachable from the open internet

More than 36,000 IPMI services answered on UDP/623 in a Shodan sweep · over 30,000 were live BMCs - hardware that was never meant to leave a private management network.

02 · vulnerable

25,000+ leak the hash before login

Via CVE-2013-4786, an IPMI 2.0 flaw, a BMC returns password-derived RAKP material before authentication completes. Any unauthenticated attacker reachable on UDP/623 can capture it and recover the password through offline cracking.

03 · invisible

Below the line your tools watch

EDR, cloud posture, and network tooling all live above the OS. The BMC sits beneath that boundary. It can act on the server from below while staying largely invisible to the controls meant to protect the host.

Offline crack estimate

How long would your BMC survive?

If your controller leaked its password hash before you logged in - how long until an attacker had it?

Offline crack estimateCVE-2013-4786 · RAKP · benchmarked at 80 GH/s
What one exposed BMC gives an attacker

One exposed BMC. Total host takeover.

A compromised BMC gives attackers control of the entire server below the operating system. In data centers, flat networks and reused credentials can turn one exposed interface into access to shared storage, critical systems, neighboring tenants, and potentially the entire cluster.

Destruction. The server is reimaged and held for ransom - seen in the wild.
Adversary
Attacker
anyone on the public internet
Entry point
Exposed BMC
reachable on UDP/623
Step 1
Weak config / default creds
admin admin
Step 1
Hash leaked pre-auth
CVE-2013-4786 · RAKP
Step 2
Cracked offline
wordlist · factory format
STEP 3
Full host control
power · boot · console
Step 4
Reimage & lock the host
virtual media
Impact
Held for ransom
ransomware
Step 4
Pivot the OOB network
flat mgmt LAN
Impact
Cluster-wide control
peer BMCs
Step 4
Multi-tenant GPU host
one server · many customers
Impact
Tenant breakout
data leakage
Step 4
Firmware backdoor
survives wipes
Impact
Persistence
Invisible to your stack

Want to talk?

We'd love to learn more about what brings you here. Whether you run a data center or you're just curious about what we found, let's talk.