<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Red Teaming on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/red-teaming/</link>
    <description>Recent content in Red Teaming on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 25 Apr 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/red-teaming/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Vulnerability Disclosure: Restricted Shell Breakout (CVE-2025-1950) and Privilege Escalation (CVE-2025-1951) in IBM Power Hardware Management Console (HMC)</title>
      <link>https://insinuator.net/2025/04/vulnerability-disclosure-restricted-shell-breakout-cve-2025-1950-and-privilege-escalation-cve-2025-1951-in-ibm-power-hardware-management-console-hmc/</link>
      <pubDate>Fri, 25 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/04/vulnerability-disclosure-restricted-shell-breakout-cve-2025-1950-and-privilege-escalation-cve-2025-1951-in-ibm-power-hardware-management-console-hmc/</guid>
      <description>&lt;p&gt;We discovered a private key for accessing an IBM Hardware Management Console&#xA;(HMC) during a recent red team engagement. The IBM Hardware Management Console&#xA;(HMC) is a dedicated management system used to control and manage IBM servers,&#xA;especially those running on Power Systems (like IBM Power9/Power10) and&#xA;mainframes (z Systems). After brief research, we identified two security&#xA;vulnerabilities that can be leveraged to gain root access to the HMC.&lt;/p&gt;&#xA;&lt;p&gt;Access for most users via SSH is limited through the &lt;code&gt;hmcbash&lt;/code&gt;, a restricted&#xA;shell environment. Using &lt;code&gt;LD_PRELOAD&lt;/code&gt;, attackers can break out of the restricted&#xA;bash and gain access to additional binaries installed on the system. With the&#xA;restrictions lifted, attackers can use a &lt;code&gt;setuid&lt;/code&gt; binary, &lt;code&gt;copysshkey&lt;/code&gt;, to&#xA;elevate privileges to &lt;code&gt;root&lt;/code&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
