From an Exposed iLO to Persistent Root via CVE-2017-12542

In this blog, I’ll walk through how a single unpatched out-of-band management interface let me take full control of a physical server — from one unauthenticated HTTP request, to a remote console, to a pre-OS root shell, to a permanent SSH backdoor — without ever knowing a single operating-system credential. Prologue “Power belongs to the people that take it.” — Mr. Robot Every serious server has a second, smaller computer bolted onto its motherboard whose entire job is to let an administrator control the machine as if they were standing in front of it — power it on, watch it boot, type at its console — over the network, whether or not the real operating system is even running. It is the most powerful interface on the box, and it is the one people forget to patch. ...

July 31, 2026 · 9 min

From IPMI to Full Infrastructure Compromise via Proxmox

In this blog, I’ll walk through how a single exposed IPMI/BMC interface let me take full control of a physical server — and how that server turned out to be a Proxmox hypervisor, handing me every virtual machine and container running on top of it, along with the backups behind them. Prologue “A bug is never just a mistake. It represents something bigger. An error of thought that makes you who you are.” — Elliot Alderson, Mr. Robot ...

July 31, 2026 · 10 min