Google's GotchaGoogle's Gotcha
Intern lists exploits against commercial and open source virtualization products.
Tavis Ormandy, a Google intern working on security issues in virtualized environments, stirred things up this past spring at CanSecWest in Vancouver, British Columbia. In his research paper, with the catchy title "An Empirical Study Into The Security Exposure To Hosts Of Hostile Virtualized Environments," Ormandy detailed a long list of successful exploits against commercial and open source virtualization products. While they were "inside-out" vulnerabilities--attacks launched from within a guest OS against the VM host--he discovered flaws on every platform tested, and one of the real-world outcomes of his research was a production patch to VMware's ESX Server resolving two potential denial-of-service flaws and addressing other concerns. Continue to the sidebar:
Desktops In Play? Return to the story:
Virtualization Security Heats Up
About the Author
You May Also Like