About the Author

author photo

Kris Buytaert is a long time Linux and Open Source Consultant doing Linux and Open Source projects in Belgium , Europe and the rest of the universe. He is currently working for Inuits, and starting up some new projects still in stealth mode. Kris is the Co-Author of Virtualization with Xen, used to be the maintainer of the openMosix HOWTO and author of different technical publications. He is a frequent speaker at different international conferences.

See All Posts by This Author

0wning Xen … In More Detail

————————————————————————————————————-

—————————————————————————————————————

Over at her own blog, Joanna Rutkowska from Invisible Things has some updates on their findings about Xen security as we earlier reported.

Joanna argues that most of the attacks presented indeed require that the attacker first gains access to the Dom0 before he can launch the attacks but that doesn’t take away the severeness of the issues.

Other rootkits also require for the attacker to first gain root access before he can hide his toolset from the eyes of the administrator.

She continues to argue that other attacks already provide people with potential access from DomU to Dom0 via a virtual machine escape bug

But even there the attacker first has to gain root in the DomU before he can potentially climb up to Dom0

Still there’s a significant difference in gaining (root) access, and hiding the fact that you got it. But indeed neither of both should be possible

- Like Virtualization.com? Subscribe to our RSS feed or newsletter to stay up-to-date! - - Also, don't forget to check our job board for the best jobs in the virtualization industry -
Explore Microsoft's Portfolio of Virtualization ProductsExplore Microsoft's Portfolio of Virtualization products

Post a Response

  • Have anything to share?

    Don't hesitate to contact us with news, tips, rumours, requests for guest posts, case-studies, white papers, interview suggestions etc.
  • Global Knowledge CCNA and Virtualization Training