I'm excited to announce our "Out-of-Band" series; these articles focus on the security risks of management devices like BMCs, serial servers, and IP-enabled KVMs. "Out-of-Band, Part 1: The new generation of IP KVMs and how to find them" is now live at:
https://www.runzero.com/blog/oob-p1-ip-kvm/
@hdm last time I reported vulns in BMCs, I was told it was unsporting. Glad to see you're picking up the flashlight to shine on how terrible these devices often are.
@mxshift thank you! it's a mess out there - glad to see all of this stuff finally going into open source, but the horrors!