3 ms·
I'm not sure why a penetration tester would bother to run this against a VM when they had already obtained a privilege level that allows memory modification of
by btbuilder 14y ago
I'm not sure why a penetration tester would bother to run this against a VM when they had already obtained a privilege level that allows memory modification of the hypervisor process. That level of access is already the equivalent of physical access.
- shabble 14y agoSurely a tool like this is exactly how you translate that 'physical access' into a useful result within the target VM? If that VM is handling the data you're tasked with stealing, bypassing auth and getting a root-shell equivalent which you can use to exfiltrate is probably just as or more useful than taking a memory image at the hypervisor. The "It's all over when they have physical access" idea always seemed to me like "Once the thief steals your safe, they can probably get it open eventually", but they still do need to get it open. Yes, you might succeed eventually with just a hand-drill and hacksaw, but a set of grinding tools and cutting torch is going to make it much easier and faster.
- btbuilder 14y agoI'm not sure that it's as tough as your analogy makes out. I'd say something like "Once the thief notices the safe door is open they can probably take your secrets out of it" :) However, I agree that there are probably some cases where the secrets are in memory rather than on the disk where this approach would be very useful. The typical case though is reboot to alternative media or single user mode.