Skip to content
This repository was archived by the owner on Jan 16, 2025. It is now read-only.

Cannot Flash Backdoored Firmware #4

Closed
tinysec190 opened this issue Jul 20, 2018 · 1 comment
Closed

Cannot Flash Backdoored Firmware #4

tinysec190 opened this issue Jul 20, 2018 · 1 comment

Comments

@tinysec190
Copy link

I'm unable to flash the firmware created using insert_backdoor.sh.

My setup is iLO4 version 2.50 with an ubuntu linux Host OS.
insert_backdoor.sh correctly creates the backdoored firmware "ilo4_250.bin.backdoored.toflash"
The script finishes and says "Firmware ready to be flashed" however when attempting to flash the firmware using the iLO Web Gui it fails to flash the firmware.

I noticed in your demo gif when the insert_backdoor.sh script finishes it references a script "exploit_write_flash_page.py". I can't seem to find this script in the code you provide and my version of insert_backdoor.sh simply says "Firmware ready to be flashed" when it completes.

What is the correct method of flashing the backdoored firmware?

Thanks again for your help and for your awesome contribution to the community. Really great work.

@alexgzt
Copy link
Contributor

alexgzt commented Aug 3, 2018

Hi,

I'm sorry but we decided, for security reasons, not to publish this specific exploit to avoid persistent compromise of Internet-facing iLO servers.

Regards,
Alex.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants