Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

Re: VMWare poor guest isolation design

Subject: Re: VMWare poor guest isolation design
Date: Fri, 24 Aug 2007 10:03:28 -0800 (AKDT)
On Fri, 24 Aug 2007, Matt Richard wrote:

There are other methods of compromising guests without any
requirements for API's, GUI's, etc -
http://www.mnin.org/write/2006_vmshell_injection.pdf.

Let me preface my response with the admission that my primary virtualization platform is IBM pSeries, I'm not a big fan of Vmware. Even so, this represents, just like the API attack, a unidirectional attack vector, from the host OS to the guest. I simply don't understand why people are making a big deal about these things. If you don't have a secure host platform then you can't have *any* reasonable expectations of security in the guest to begin with.

Now, if someone can prove an attack from one guest to another, or verify if
two UIDs running vms can tamper with the other's vm, then there would be a
security concern. Devoid of that, techniques like this are just one of a million reasons why no one makes reservations at the Bates Hotel. To expect otherwise makes you deserving of getting stabbed in the shower.


        --Arthur Corliss
          Live Free or Die

<Prev in Thread] Current Thread [Next in Thread>