3 ms·
I'm a complete noob when it comes to CTF, but escaping a VM to control the host is total witchcraft to me. Darknet Diaries just had a great podcast on the Pwn2O
by ThisIsTheWay 6y ago
I'm a complete noob when it comes to CTF, but escaping a VM to control the host is total witchcraft to me. Darknet Diaries just had a great podcast on the Pwn2Own CTF hosted by CanSecWest cyber-security conference, which includes a competition to escape a virtualized machine. Highly recommended, it's a great listen.
https://darknetdiaries.com/episode/82/ https://darknetdiaries.com/episode/82/
- tyingq 6y agoThe details are witchcrafty to me, but the base idea that virtual devices passed to the guest can have unintended access to host memory (or files, etc) seems straightforward. Edit: Curious, are there common guest escapes that exploit something other than virtual devices?
- mav3rick 6y agoCore hypervisor code may have a bug that can be triggered via the kvm API.
- fulafel 6y agoThe guest-host API is just attack surface like any other (file formats, network protocols, kernel syscall api, browser sandbox etc) and typically the privileged side is implemented in memory-unsafe languages. As bugs in memory-unsafe PL code have high probability to be exploitable, giving control to the attacker, the game is set.