General Pr0ken File System - Hacking IBM's GPFS presented at Troopers 2015

by Florian Grunow, Felix Wilhelm,

Summary : The IBM General Parallel File System (IBM GPFS) is a high performance cluster file system powering some of the world's biggest super computers. Customers range from "Infiniti Red Bull Racing" to the "Bayrische Börse AG", as well as many universities around the globe. This makes it a prime target for attackers as not only the data stored in the file system is valuable, but also the machines running the GPFS are quite powerful, too. Besides presenting a detailed overview of the GPFS architecture and the flaws that come with it, we walk through the discovery and exploitation of a bug that looked simple at first but developed to a very special journey into the guts of GPFS.