Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: VMWare poor guest isolation design

From: Arthur Corliss <corliss(at)digitalmages.com>
Date: Fri Aug 24 2007 - 14:03:28 EDT


On Fri, 24 Aug 2007, Matt Richard wrote:

> There are other methods of compromising guests without any
> requirements for API's, GUI's, etc -
> http://www.mnin.org/write/2006_vmshell_injection.pdf.

Let me preface my response with the admission that my primary virtualization platform is IBM pSeries, I'm not a big fan of Vmware. Even so, this represents, just like the API attack, a unidirectional attack vector, from the host OS to the guest. I simply don't understand why people are making a big deal about these things. If you don't have a secure host platform then you can't have *any* reasonable expectations of security in the guest to begin with.

Now, if someone can prove an attack from one guest to another, or verify if two UIDs running vms can tamper with the other's vm, then there would be a security concern. Devoid of that, techniques like this are just one of a million reasons why no one makes reservations at the Bates Hotel. To expect otherwise makes you deserving of getting stabbed in the shower.

 	--Arthur Corliss
 	  Live Free or Die
Received on Fri Aug 24 14:18:20 2007

This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:13:23 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library