I ran across this article from last year again and it got me thinking. The article is a story about how a hardware hacker was able to hack hard drive firmware, first to upload his own firmware, but also to take advantage of the embedded controller, and even install linux on the controller. If you haven't read it it's fairly impressive. [Ed's Comment: I would go further and say that it is a amazing piece of hacking, in the traditional meaning of the word.]
It seems that lately there have been a lot of vulnerabilities targeting embedded peripherals. Those in the article come to mind, also badUSB, and some IPMI vulnerabilities.
What do you think? Are the number of attack vectors targeting embedded peripherals a consequence of more powerful controllers? Worse software? More sophisticated attackers? Or just a random occurrence?
(Score: 2, Interesting) by iamjacksusername on Saturday November 29 2014, @08:01PM
Welcome to updates on ESXi! It is like the year 2000 all over again when we had to build floppies to boot into DOS to run BIOS updates. For example, Dell has Linux images for the firmware but ESXi cannot process them. If you have Dell servers, they provide you a boot image builder so you can PXE- or usb boot each server that needs an update and run the bin image. It is not all Dell's fault - in a sane world, ESXi would natively support linux bin firmware installers or work with the manufacturers to provide a consistent API for flashing firmware so they could produce flash images for ESXi.
(Score: 2) by Arik on Sunday November 30 2014, @03:13AM
In a sane world, firmware updates would be extremely unusual, and accompanied with both a hearfelt apology and an offer to simply RMA the hardware if that is more convenient for you.
If laughter is the best medicine, who are the best doctors?