Researchers find 24,650 exposed BMCs disclose IPMI authentication hashes before login, enabling offline password cracking.