Ok, so I have this HP-server in my garage that I've had for years.
I decided to plug it in, add drives and connect the iLO port.

Ofcourse, I have forgotten the iLO password - and I dont have a monitor that I can use to reset it via the BIOS.

I do remember this vulnerability from a couple of years ago, that where I could get the password (or change it) for the Administrator user with a curl post request.
But I can't find it.

Help

#linux #curl #hp #ilo #infosec #vulnerability_research #vulnerability #askfedi #askfediverse

@selea not sure about vulnerability, however there were plenty of tiny jumpers on old HPE servers. Check motherboard manual just in case.

@valdeg

Yeah that's true. I did not think of it at all.

Thanks