5 ms·
Or break down and invest in a VMWare license, and run everything (_everything_) in a virtual machine.
by al1x 13y ago
Or break down and invest in a VMWare license, and run everything (_everything_) in a virtual machine.
- spindritf 13y agoYou can get that for free and designed for security: http://qubes-os.org/trac http://qubes-os.org/trac
- unimpressive 13y agoI tried to find an article about an attack against virtualization that used some CPU trickery to spy on everything the host computer was doing. (Including other virtual machines on the same host.) Sadly I couldn't. So here are all the tabs I opened during my search instead. http://www.kb.cert.org/vuls/id/649219 http://www.kb.cert.org/vuls/id/649219 https://www.scmagazineus.com/Altor-Networks-Altor-VF/Review/3009/ https://www.scmagazineus.com/Altor-Networks-Altor-VF/Review/... https://www.juniper.net/us/en/products-services/software/security/vgw-series/ https://www.juniper.net/us/en/products-services/software/sec... http://news.cnet.com/8301-13846_3-10395695-62.html?tag=mncol;title http://news.cnet.com/8301-13846_3-10395695-62.html?tag=mncol... http://www.itworld.com/security/80289/securing-your-virtual-environment http://www.itworld.com/security/80289/securing-your-virtual-... http://www.symantec.com/connect/blogs/infographic-what-small-businesses-should-know-about-virtualization-security http://www.symantec.com/connect/blogs/infographic-what-small... A quick look at these shows them to be wholly not what I'm looking for. (And wholly unfit for HN I might add, which is where I got them.) If anyone out there has a link to the vulnerability I'm thinking of (it was on HN at one point), or useful information on securing virtual machines against breakout malware, that would be awesome.
- socillion 13y agoThis one? http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-privilege-escalation/ http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-pr... http://www.vupen.com/blog/20120904.Advanced_Exploitation_of_Xen_Sysret_VM_Escape_CVE-2012-0217.php http://www.vupen.com/blog/20120904.Advanced_Exploitation_of_... Exploits are developed to break VMs, just like everything else, and are promptly patched once revealed. Apart from general intrusion detection tools, I think you would be hard pressed to find anything to guard against them. Maybe run a VM inside another VM ;)
- unimpressive 13y agoSadly not that one. It was a general vulnerability based on the way processors work that is effectively unpatchable. Something that could easily fit into Zalewski's Silence on the Wire.
- zvrba 13y agoMaybe this one, related to SMM: http://arstechnica.com/security/2009/03/storm-over-intel-cpu-security-could-be-tempest-in-a-teapot/ http://arstechnica.com/security/2009/03/storm-over-intel-cpu...
- unimpressive 13y agoThat's still not it, oh well. (But it is clever)