Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-13-2008, 10:38 AM
num_gg@laposte.net
Guest
 
Posts: n/a
Default Server virtualization and security?

Hi all,

Don't know whether it's the good spot to post but this is a simple
question and I did not find any studies about this point:

I know that virtualization is seen as a great solution to managing the
data center of the future; server virtualization enables besides a
better way to address common issues like resources allocation and
optimization, hot plug application deployment, space and energy
consumption savings and so on...

But: My question is from the security and anti-hacking protection
point of view. Someone says that "virtualization allows securisation
and isolation of a network as breaking a virtual system doesn't allow
to take over the whole system (and especially the host system)".
Personnally I wonder how one can be so sure.

What if a server "virtually" hosting my app and another one which is a
great security hole? If a hacker manage to take over the virtual
system hosting the "loosely secured app" is it simple (or not?) for
him to take over the other virtual systems or ,what's even worse, the
whole system?

Any idea?
Any link where this issue is addressed?

Cheers

num


Reply With Quote
  #2 (permalink)  
Old 02-13-2008, 12:08 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: Server virtualization and security?

num_gg@laposte.net wrote:


> But: My question is from the security and anti-hacking protection
> point of view. Someone says that "virtualization allows securisation
> and isolation of a network as breaking a virtual system doesn't allow
> to take over the whole system (and especially the host system)".
> Personnally I wonder how one can be so sure.



Depends very much on the implementation. Virtuozzo and User Mode Linux, for
example, offer virtually no security boundaries.

Reply With Quote
  #3 (permalink)  
Old 02-13-2008, 01:22 PM
Todd H.
Guest
 
Posts: n/a
Default Re: Server virtualization and security?

num_gg@laposte.net writes:

> Hi all,
>
> Don't know whether it's the good spot to post but this is a simple
> question and I did not find any studies about this point:
>
> I know that virtualization is seen as a great solution to managing the
> data center of the future; server virtualization enables besides a
> better way to address common issues like resources allocation and
> optimization, hot plug application deployment, space and energy
> consumption savings and so on...
>
> But: My question is from the security and anti-hacking protection
> point of view. Someone says that "virtualization allows securisation
> and isolation of a network as breaking a virtual system doesn't allow
> to take over the whole system (and especially the host system)".
> Personnally I wonder how one can be so sure.
>
> What if a server "virtually" hosting my app and another one which is a
> great security hole? If a hacker manage to take over the virtual
> system hosting the "loosely secured app" is it simple (or not?) for
> him to take over the other virtual systems or ,what's even worse, the
> whole system?
>
> Any idea?
> Any link where this issue is addressed?


Full escape from a VMWare virtual machine was apparently demonstrated
late in 2007. I saw a talk by SANS handler Tom Liston who was
discussing the issues they leveraged to perform it. Googling, I
found a mention of it in this blog
http://www.pauldotcom.com/2007/07/31...tualizati.html

Liston's 2006 presentation which is light on details due to disclousre
issues is here
http://handlers.sans.org/tliston/Thw...on_Skoudis.pdf

However, with modifications to the vmware configuration, things can
be locked down quite well. He mentioned several of these in a talk I
attended of his in mid-late 2007.

Also notable on this virtualization security front are the squabbles
between Tom Ptacek's Montasano security and Joanna Rutkowska (author
of Blue Pill).

http://theinvisiblethings.blogspot.c...challenge.html

Montasano's version provides more background though:
http://www.matasano.com/log/895/joan...t-us-prove-it/

Best Regards,
--
Todd H.
http://www.toddh.net/

Reply With Quote
  #4 (permalink)  
Old 02-13-2008, 10:25 PM
Russell Wood
Guest
 
Posts: n/a
Default Re: Server virtualization and security?

On 2008-02-13, num_gg@laposte.net <num_gg@laposte.net> wrote:
>
> ... securisation ..


WTF?

> ... If a hacker manage to take over the virtual system hosting the
> "loosely secured app" is it simple (or not?) for him to take over the
> other virtual systems or ,what's even worse, the whole system?


Possibly. Drop the guest, mount its file system and make modifications
then bring the guest back up.

--
Russell Wood
<http://www.dynode.net/~rjw/>

Reply With Quote
  #5 (permalink)  
Old 02-18-2008, 02:54 PM
num_gg@laposte.net
Guest
 
Posts: n/a
Default THREAD CLOSING: Server virtualization and security?

Hi all,

Thanks to *all* for your answers and links for further information.

I close the thread (but the issue seems far from closed).

cheers

Num,

Reply With Quote
  #6 (permalink)  
Old 02-19-2008, 06:20 AM
Todd H.
Guest
 
Posts: n/a
Default Re: THREAD CLOSING: Server virtualization and security?

num_gg@laposte.net writes:

> Hi all,
>
> Thanks to *all* for your answers and links for further information.
>
> I close the thread (but the issue seems far from closed).


Is thread closing a Google Groups thing?

--
Todd H.
http://www.toddh.net/

Reply With Quote
  #7 (permalink)  
Old 02-21-2008, 04:00 PM
num_gg@laposte.net
Guest
 
Posts: n/a
Default Re: THREAD CLOSING: Server virtualization and security?

ok ok ok...
Facing protest, the thread is NOT closed.

....

Now Andy, it's up to you.

....

(just kidding)

:))





Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security kernels JeZuZ alt.computer.security 2 09-22-2005 09:35 AM


All times are GMT. The time now is 08:04 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45