101010.pl is one of the many independent Mastodon servers you can use to participate in the fediverse.
101010.pl czyli najstarszy polski serwer Mastodon. Posiadamy wpisy do 2048 znaków.

Server stats:

582
active users

#supermicro

0 posts0 participants0 posts today

Got #Proxmox installed on the #Supermicro SuperServer 4028GR-TRT2 and added to the cluster. I'm being mad janky with my #corosync tho because cause I don't want the #GPU node to be a 24/7 machine so I gave my main three high availability nodes two #quorum votes instead of one so as long as the three nodes primary HA nodes are online, it can tolerate a single node failure. Next step is to install the nVidia drives, get the vGPU unlock working for some VDI LAN party fun, and then deploy a LXC with the GPUs passed-through and install llama.cpp

#homelab #llm #llama

RE:
https://transfem.social/notes/a1v9w5kz0h7l01de

Podatność typu RCE w firmware BMC IPMI Supermicro

BMC (Baseboard Management Controller) to mikrokontroler obecny często przy płytach głównych serwerów. Wykorzystując IPMI (Intelligent Platform Management Interface), pozwala na monitorowanie ich parametrów czy sterowanie nimi, zapewnia też zdalny dostęp. Jest zupełnie niezależny – posiada swój procesor, firmware oraz RAM. Można o nim myśleć po prostu jako o niezależnym, dedykowanym komputerze o...

#WBiegu #Cve #Serwer #Sprzęt #Supermicro

sekurak.pl/podatnosc-typu-rce-

Sekurak · Podatność typu RCE w firmware BMC IPMI SupermicroBMC (Baseboard Management Controller) to mikrokontroler obecny często przy płytach głównych serwerów. Wykorzystując IPMI (Intelligent Platform Management Interface), pozwala na monitorowanie ich parametrów czy sterowanie nimi, zapewnia też zdalny dostęp. Jest zupełnie niezależny – posiada swój procesor, firmware oraz RAM. Można o nim myśleć po prostu jako o niezależnym, dedykowanym komputerze o...

Q: What do you look forward to on a Sunday morning?
A: Relaxing with calm music, a bowl of strawberries, and some quality time with NVDIMM Persistent Memory modules

03:19.. it's still early, plenty of time to debug IRQs! 😊

also, for whoever needs to know this newfangled manner of kernel command line arguments in Fedora/Redhat distros ... if you're tired of typing out the active kernel string when looking up its params via "grubby", here's a var-subshell substituted whatever call to ease those pains:

---
root@upgrayyed:~# grubby --info=$(grubby --default-kernel)
index=1
kernel="/boot/vmlinuz-6.10.7-200.fc40.x86_64"
args="ro resume=UUID=redacted rd.md.uuid=redacted rd.md.uuid=redacted console_msg_format=syslog loglevel=7 hibernate=no iommu=pt mem_encrypt=off selinux=0 nouveau.blacklist=1 rd.driver.blacklist=nouveau modprobe.blacklist=nouveau console=tty0 console=ttyS0 console=ttyS1"
root="UUID=redacted"
initrd="/boot/initramfs-6.10.7-200.fc40.x86_64.img $tuned_initrd"
title="Fedora Linux (6.10.7-200.fc40.x86_64) 40 (Server Edition)"
id="e1f345d2eb0a4de3ab64da772c942e05-6.10.7-200.fc40.x86_64"
---

#Stories from the #trenches...

Ran a
#Debian apt dist-upgrade on my #Proxmox server before moving it from a shared #network cabinet at the #colocation facility in #LA to my personal cabinet, thinking that when I booted it up it'll be up to date from the last reboot months ago. When I discovered the LACP bundle wasn't coming up for it, I found it sitting at the infamous (initramfs) prompt. Apparently #Linux #Kernel 6.8 removed support for #LSI SAS1068E cards, or at least was very unhappy with it. At the moment I am stuck with kernel 6.5 until I either blast off this #Supermicro X9 server entirely, or get an LSI 9311-8i + SAS cables.

For the cost of upgrading the CPUs, quadrupling the RAM, getting that LSI card + cables, and swapping the 2x10G NIC for a 2x40G NIC at $420, I could get an X10 box on
#eBay with almost the same specs, and if I double that to $1000 I could aim for an X11-based box. Decisions, decisions, although the most important one for now is to put off such unnecessary purchases until I land my next job.

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #40/2023 is out! It includes the following and much more:

🇺🇸 🗳️ D.C. Board of #Elections confirms voter data stolen in site hack
🔓 🪪 #MGM Resorts confirms hackers stole customers’ personal data during #cyberattack
🔓 🧬 #DNA testing service 23andMe investigating theft of user data
🔓 🎧 #Sony confirms #databreach impacting thousands in the U.S.
📱 💥 Lyca Mobile Group Services Significantly Disrupted by Cyberattack
🔓 🕵🏻‍♂️ #NATO investigating breach, #leak of internal documents
🔓 🇪🇺 European Telecommunications Standards Institute Discloses Data Breach
🔓 🏨 #MotelOne discloses data breach following #ransomware attack
🇰🇵 💰 North Korea's #Lazarus Group Launders $900 Million in #Cryptocurrency
🇧🇪 🇨🇳 #Alibaba accused of ‘possible espionage’ at European hub
🇨🇳 #China-linked cyberspies #backdoor #semiconductor firms with #CobaltStrike
🥸 Meet LostTrust #ransomware — A likely rebrand of the #MetaEncryptor gang
🇬🇾 🇨🇳 #Guyana Governmental Entity Hit by #DinodasRAT in #CyberEspionage Attack
🇷🇺 🇺🇸 #FBI most-wanted Russian hacker reveals why he burned his passport
🇺🇸 🏥 #FDA cyber mandates for #medicaldevices goes into effect
☁️ 🔓 Number of Internet-Exposed #ICS Drops Below 100,000
☁️ #Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via #SQL Server Instance
🦠 📈 #QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks
🔓 🍏 #Apple Warns of Newly Exploited iOS 17 Kernel Zero-Day
🎣 🧑🏻‍💼 US Executives Targeted in #Phishing Attacks Exploiting Flaw in Indeed Job Platform
🦠 🏦 #Zanubis #Android Banking Trojan Poses as Peruvian Government App to Target Users
🦠 🇮🇷 Iranian APT Group #OilRig Using New Menorah #Malware for Covert Operations
🔐 ☁️ #Amazon to make #MFA mandatory for 'root' #AWS accounts by mid-2024
🛡️ 🧅 #Microsoft Defender no longer flags #Tor Browser as malware
👀 X-Force uncovers global #NetScaler Gateway credential harvesting campaign
🐛 💰 Zero-days for hacking #WhatsApp are now worth millions of dollars
🩹 #Cisco fixes hard-coded root credentials in Emergency Responder
🔓 Vulnerabilities in #Supermicro BMCs could allow for unkillable server #rootkits
🔓 🐧 Looney Tunables: New #Linux Flaw Enables Privilege Escalation on Major Distributions
🐍 Warning: #PyTorch Models Vulnerable to Remote Code Execution via ShellTorch
🩹 Microsoft Edge, Teams get fixes for zero-days in #opensource libraries
🔓 🔥 Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw
☁️ Cloudflare #DDoS protections ironically bypassed using #Cloudflare

📚 This week's recommended reading is: "8 Steps to Better Security: A Simple Cyber Resilience Guide for Business" by Kim Crawley

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

X’s Infosec Newsletter · InfoSec MASHUP - Week 40/2023By Xavier «X» Santolaria

Hi everyone!

Can anyone advice on a good but not brand new server (i.e. #supermicro or similar)? Basically an affordable server for personal use (running #FreeBSD of course) but still powerful enough to handle some extra load if needed?

I currently have a X10SL7-F which so far is ok(ish) for the job, but I want to scale up within a reasonable price

Any suggestions are highly appreciated!

Thanks!