|
|||||||||||
|
Re: More on VMWare poor guest isolation design
From: Tim Newsham <newsham(at)lava.net>
Date: Sat Aug 25 2007 - 15:05:13 EDT
Your position seems to be that an easy automated scripting interface is a lot more dangerous than a slightly harder indirect attack method. The truth is that they are both scriptable and reliable. Techniques for attacking virtual machines from the host are certainly no harder to code than the average remote exploit that worms used to propogate. Do you really think a worm writer who wants to compromise VMWare guests would take advantage of a scripting interface but shy away from the task if he had to write custom code to break into the guest? > 4. This is also not so much about this specific issue at hand--we can easily Here's a best practice: Don't assume that guests are protected from software running on the host system. > As a side note, I specialize in hardening Windows so all of these systems A (virtual) machine where attackers can arbitrarily read and write the memory, the disk and even alter devices is going to be a soft target. The physical analogy that someone brought up earlier works well here. Would you consider your machine locked down if someone could open your computer case, yank the hard drive and attach new devices to the system at will? Well, with a virtual machine they can do that while the machine is running. > Mark Burnett
Tim Newsham
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:13:34 EDT |
||||||||||
|
|||||||||||