SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Vendor demonstrates insider attack on VMware ESX

Vendor demonstrates insider attack on VMware ESX

By:  Jon Brodkin  On: 10 Sep 2010 For: Network World (U.S.) (GM) Creator
 

An engineer with BeyondTrust Software Inc. said IT workers with root access to VMware Inc.’s ESX hypervisor could manipulate the service console and steal data tied to virtual machines and then delete history and log files. VMWare says root passwords to any system will allow access but moving to ESXi will make data harder to steal

VMware Inc.’s ESX hypervisor could let IT staff steal sensitive data by abusing administrative access, particularly if customers fail to implement role-based access controls, the security vendor BeyondTrust Software Inc. argued at the recent VMworld conference.

IT staff with root access to VMware ESX can steal virtual machine disk files and then erase log files and other traces of the illicit activity by manipulating the service console, a Linux-based instance that manages the VMware hypervisor, BeyondTrust says. This could make it easy to steal medical records, financial data, or any other files tied to virtual machines, says Jordan Bean, principal systems engineer for Carlsbad, Calif.-based BeyondTrust. Bean provided a demonstration of this type of attack on the VMworld conference exposition floor.

But in response, VMware noted that root access to any sort of IT product could let users do malicious things. VMware doesn't have built-in access controls for the service console, but does offer a recommended set of best practices to enable role-based access controls and has partnered with third parties – including BeyondTrust – to track and manage access into virtualized environments.

Moreover, VMware is eliminating the service console in future versions of its core hypervisor platform. For the past several versions of vSphere – formerly known as VMware Infrastructure – the vendor has offered both the ESX and ESXi architectures in parallel. But in the next release, the date of which has not yet been announced, ESX will be eliminated leaving only ESXi, which lacks a service console.

ESXi has a much smaller attack surface, roughly 100 MB instead of 2 GB, largely because the Linux-based service console has been replaced by APIs and modules that let administrators create and manage virtual machines.

Problems related to root access are possible in any IT product, says Venu Aravamudan, a senior director for product marketing at VMware.

"It's not as much a vulnerability in that clearly if you got the root password to anything" – like a SQL Server or a router – "you can do whatever you want. You're never going to stop that from occurring for any product in the marketplace today," he says.

But the specific scenario of stealing virtual machine disk files demonstrated by BeyondTrust is much harder to achieve with ESXi than it is with ESX.

"You're still going to have one root password," says Charu Chaubal, senior technical marketing manager for VMware. "But this phenomenon of one user that can do everything is highly mitigated [in ESXi]. By going to the ESXi architecture, it's almost like you're closing the garage door, and now you can only go through the windows, and every window can be locked individually."

Under the ESX architecture with the service console, Bean says by logging in with the same username and password used to create an ESX host, a user can essentially operate invisibly to VMware's security.


Sign up for our Newsletters

 












Print |  Views: 3781   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




jon brodkin Jon Brodkin is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Recent Canadian IT Jobs




Related Content

VMware disses bare-metal desktop hypervisors
VMware disses bare-metal desktop hypervisorsVMware claims it doesn't need to deliver on its promise of a bare-metal desktop hypervisor, but says that if it does choose to release a so-called Type 1 client hypervisor it would be better than Citrix's
Citrix targets laptop security with new XenDesktop
Citrix targets laptop security with new XenDesktopCitrix's next version of XenDesktop will automatically encrypt corporate data on employee-owned laptops and include a bare-metal client hypervisor
Greene out, Maritz in at VMware
Greene out, Maritz in at VMwareThe founder and CEO of the wildly successful virtualization firm is gone, replaced by a Microsoft vet and cloud computing pioneer, and causing a huge drop in share prices
Is the hypervisor the new monoculture?
that monstrous clang you heard on august 12 was the sound of vmware shuffling off its armour of invincibility. the darling of the virtualization market left some stray code in an update, which convinced hypervisors their
blog comments powered by Disqus