|
|||||||||||
|
Re: VMWare poor guest isolation design
From: Arthur Corliss <corliss(at)digitalmages.com>
Date: Thu Aug 23 2007 - 12:49:15 EDT
> I have run across a design issue in VMware's scripting automation API that I don't see this as a serious problem. This is the virtual equivalent of no physical security. If the host OS (or an account within it) is compromised, of course all bets are off when it comes to a virtual machine running within it. Furthermore, this attack only works if you are running the vmware guest utilities *and* you are currently logged into a GUI desktop running the vmware userland process. I personally look at this as an issue for Windows. I personally don't install the vmware guest software for my Linux VMs, nor would I log into a GUI as root. For that matter, if you are merely hosting the guest VMs why would you need to ever use the vmware console after installation? Use a network-based access method, making the need for the vmware guest utilities unnecessary. That should be sufficient for all OS'es. In (not so) short, this attack vector is virtually worthless if reasonable security practices are employed. --Arthur Corliss Live Free or DieReceived on Thu Aug 23 15:27:41 2007 This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:13:17 EDT |
||||||||||
|
|||||||||||