%category_title%, %blog_title%, virtualization, virtualisation

About the Author

author photo

Kris Buytaert is a long time Linux and Open Source Consultant doing Linux and Open Source projects in Belgium , Europe and the rest of the universe. He is currently working for Inuits, and starting up some new projects still in stealth mode. Kris is the Co-Author of Virtualization with Xen, used to be the maintainer of the openMosix HOWTO and author of different technical publications. He is a frequent speaker at different international conferences.

See All Posts by This Author

Live Virtual Machine Migration Vulnerability

Anthony Liguori has a good summary of the Blackhat paper by Jon Oberheide, Evan Cooke and Farnam Jahanian of the University of Michigan about Xensploit .

Black Hat Logo

The idea of Xensploit is to use a Man in the Middle attack between 2 hosts performing a Live migration. The fundamental flaw is that by default Live migration of virtual machines is unencrypted or often even unauthenticated. Of course good network security practice isolates this kind of traffic in it’s own VLAN, but it shows that security is becoming a bigger issue day by day.

The vulnerability seems to be present with VMWare and Xen versions prior to 3.1 but according to Anthony not with KVM.

Share this story on your favorite social bookmarking tool:

These icons link to social bookmarking sites where readers can share and discover new web pages.
  • bodytext
  • del.icio.us
  • StumbleUpon
  • Reddit
  • Technorati
  • Slashdot
  • description
  • Shadows
  • Fark
  • YahooMyWeb
  • NewsVine
  • TailRank
  • Simpy
  • Blue Dot
  • blogmarks
  • SphereIt
  • Ma.gnolia
  • description
  • MisterWong
  • Scoopeo
  • Spurl
  • BlogMemes
  • PlugIM
  • De.lirio.us
  • BlinkList
  • description
---------------------------------------------------------------------------------------------------------------------
- Like Virtualization.com? Subscribe to our RSS feed or newsletter to stay up-to-date! - - Also, don't forget to check our job board for the best jobs in the virtualization industry -
---------------------------------------------------------------------------------------------------------------------

Post a Response

  • Have anything to share?

    Don't hesitate to contact us with news, tips, rumours, requests for guest posts, case-studies, white papers, interview suggestions etc.