Show simple item record

dc.contributor.authorClayton, Syler W.
dc.date.accessioned2019-01-29T22:27:08Z
dc.date.available2019-01-29T22:27:08Z
dc.date.issued2014-04
dc.identifier.urihttp://hdl.handle.net/11122/9761
dc.descriptionMaster's Project (M.S.) University of Alaska Fairbanks, 2014en_US
dc.description.abstractThe Intelligent Platform Management Interface (IPMI) is a protocol that allows administrators to manage servers remotely. Hardware vendors including Dell, HP, Supermicro, IBM, Lenovo, Fujitsu and Oracle support IPMI though a Baseboard Management Controller (BMC) which can either be integrated into the motherboard or purchased as a pluggable module. The BMC runs silently alongside other components of the server and provides a lower level of hardware access than the Operating System (OS). This allows support for features like power cycling the server, mounting virtual media and accessing a remote console. The failure of BMC vendors to produce a more secure product, along with the inherent flaws of the IPMI protocol, increases the need for these systems' security capabilities to be evaluated. The IPMI protocol and various vendor implementations of the BMC has been the subject of recent scrutiny, and initial investigation has raised concerns about the security properties of these components. This project focuses on evaluating specific IPMI supported hardware and software setup in an environment modeled to simulate real use, for the explicit purpose of evaluating the security of the system. This project presents: several methods by which unprivileged users can gain remote access to the system, a list of best practices for proper configuration, a guide to clearing configuration settings before decommission, and a basic Metasploit module to scan for BMC related services.en_US
dc.language.isoen_USen_US
dc.subjectClient/server computingen_US
dc.subjectComputer interfacesen_US
dc.subjectComputer securityen_US
dc.titleIntelligent platform management interface protocol securityen_US
dc.typeOtheren_US
dc.type.degreems
dc.identifier.departmentDepartment of Computer Science
dc.contributor.committeeHay, Brian
dc.contributor.committeeNance, Kara
dc.contributor.committeeGenetti, Jon
refterms.dateFOA2020-03-06T01:32:06Z


Files in this item

Thumbnail
Name:
Clayton_S_2014.pdf
Size:
7.660Mb
Format:
PDF

This item appears in the following Collection(s)

Show simple item record