Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: VMWare poor guest isolation design
From: Arthur Corliss <corliss () digitalmages com>
Date: Fri, 24 Aug 2007 10:03:28 -0800 (AKDT)

On Fri, 24 Aug 2007, Matt Richard wrote:

There are other methods of compromising guests without any
requirements for API's, GUI's, etc -
http://www.mnin.org/write/2006_vmshell_injection.pdf.

Let me preface my response with the admission that my primary virtualization
platform is IBM pSeries, I'm not a big fan of Vmware.  Even so, this
represents, just like the API attack, a unidirectional attack vector, from
the host OS to the guest.  I simply don't understand why people are making
a big deal about these things.  If you don't have a secure host platform
then you can't have *any* reasonable expectations of security in the guest
to begin with.

Now, if someone can prove an attack from one guest to another, or verify if
two UIDs running vms can tamper with the other's vm, then there would be a
security concern. Devoid of that, techniques like this are just one of a million reasons why no one makes reservations at the Bates Hotel. To expect otherwise makes you deserving of getting stabbed in the shower.

        --Arthur Corliss
          Live Free or Die


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]