Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
We've had a number of articles covering the interesting news out of Intel's 2019 Open-Source Technology Summit (OSTS) held at Skamania Lodge in Stevenson, Washington. Here's a look back at the news out of the open-source event as well as some other smaller bits of information shared during the event. . Some of the interesting news and insights from OSTS 2019 included: - Intel announced a new hypervisor based on Rust-VMM that is already seeing industry support from multiple key players. - There's now a Cloud Linux Developer Edition that includes the new GUI installer and store. - Clear Linux is seeing industry adoption ranging from Alibaba to deployments in Microsoft's Azure cloud to MontaVista now offering commercial support for Clear Linux. The link for this article located at Phoronix is no longer available. . Uncover significant updates and revelations from OSTS 2019, featuring Intel's latest hypervisor innovations and the growing adoption of Clear Linux across various sectors.. Intel Rust Hypervisor, Clear Linux Adoption, Open Source Technology Summit, Cloud Developer Edition, OSTS 2019. . Brittany Day
Security experts from ERNW have demonstrated the ability to break out of the virtualisation hypervisor of VMware ESXi 5.0 using crafted VMware images. If a provider offers customers the ability to run customer-supplied VMware images on its servers as part of an infrastructure as a service (IaaS) offering, a malicious user could access all data on the server, including other customers' user passwords and virtual machines.. The security experts were able to manipulate the virtual disk images in a way that caused host disks to be mounted in the guest system after launching the VM. Successful attacks have been mounted in this way against fully patched copies of ESXi 5.0, but the researchers point out that, as far as they are aware, this has so far only happened under laboratory conditions. [All of article] The link for this article located at H Security is no longer available. . Cybersecurity researchers exploited vulnerabilities in VMware images, putting underlying host disks at risk. This poses a serious threat for IaaS users to recognize.. VMware Security Risk,IaaS Vulnerability,Hypervisor Exposure,Virtualization Attack,ESXi Threat. . LinuxSecurity.com Team
A Playstation 3 hacker says he has released information about reverse engineering hypervisor technology used in the PS3 after his home in Germany was raided earlier this week, reportedly at Sony's request.. In a comment to a post on his PS3 Linux and Hyper Reverse Engineering Blog, Graf-chokolo writes in the comments section: "Guys, SONY was today at my home with police and got all my stuff and accounts. So be careful from now on." After several readers expressed doubt about the legitimacy of the post, he says in another comment: "Guys, I don't joke, it's serious. And to prove it, I kept my word and uploaded all my HV reversing stuff. Upload it everywhere so SONY couldn't remove it easily. Grab it guys, it contains lots of knowledge about HV and HV procs." The link for this article located at CNET is no longer available. . In a comment to a post on his PS3 Linux and Hyper Reverse Engineering Blog, Graf-chokolo writes in t. playstation, hacker, released, information, about, reverse, engineering, hypervisor, technol. . LinuxSecurity.com Team
Virtualization platforms are software. All software has flaws. Therefore, virtualization platforms have flaws. Simple logic,right? The major virtualization platform vendors, VMware, Xen (now Citrix), and Microsoft, have all had several vulnerabilities over the last few years. However, the major components of a virtualization infrastructure and the IT strategy related to deployment and maintenance of virtualization technologies can be planned and secured fairly well. The following sections will explore the major areas of concern for security professionals.. I. Hypervisor security The hypervisor is a piece of software, in many cases, unless integrated directly with the host platform (see the next section). The major virtualization vendors release patches for their products like any other software providers, and the key to mitigating the risk of hypervisor vulnerabilities is a sound patch management process. Examples of sound patch management practices include maintaining the latest service packs for both guests and hosts, alleviating any unnecessary applications that have a history of vulnerabilities, and applying the latest security rollup patches if and when they are supplied by the virtual software vendor. II. Host/Platform Security The host platform, which connects the VMM and virtual guests to the physical network, can vary widely in the type of configuration options available. This is largely dependent on system architecture; for example, VMware's ESX Server platform has a number of similarities to Red Hat Linux. Given that many of these systems are able to be hardened considerably, a number of The link for this article located at DataCenter Journal is no longer available. . Virtualization security ensures the integrity and availability of virtual environments, focusing on hypervisor protection, host safeguards, network security, compliance, and recovery. Virtualization Security, Hypervisor Best Practices, Security Risks. . LinuxSecurity.com Team
A few years ago I wrote a paper for SANS titled . The original intent for that paper was to serve as the first in a series that dug into all facets of virtsec. Starting with the basic threat analysis of moving systems from hardware to software, that paper dealt with security risks like attacking the host platform, attacking individual guests, and using a shared filesystem. These attacks were all examples of exploiting the nature of running virtual machines in a shared environment with shared resources on the virtual platform; they specifically did not delve into security of the hypervisor. We The link for this article located at TMC Net is no longer available. . Exploring the complexities of cloud architecture safety and the threats associated with overseeing communal infrastructures and assets.. virtualization security, shared resources management, hypervisor security. . LinuxSecurity.com Team
The basic idea/thesis of this article (and the previous, unfinished draft) is this: hypervisors are getting more and more common, and are growing in deployment in everything from datacenter systems to embedded consumer electronics. But, as their deployment increases, more and more security concerns come into play, including a variety of attack methods and the dire consequences of a compromised hypervisor.. If you know what a hypervisor is, then skip this paragraph: A hypervisor is basically a very minimalist operating system designed with the purpose of abstracting real, physical computer hardware from one or more virtual machines running The link for this article located at The Coffee Desk is no longer available. . As virtualization expands across cloud computing and enterprise IT, security concerns tied to hypervisors are rising, necessitating robust measures for protection. Hypervisor Security, Virtualization Risks, Cloud Infrastructure Security. . LinuxSecurity.com Team
Companies in a rush to deploy virtualization technologies for server consolidation efforts could wind up overlooking many security issues and exposing themselves to risks, warns research firm Gartner. . Virtualization software offers the ability to run multiple operating systems, or multiple sessions of a single operating system, on a single physical machine, whether server or desktop. But virtualization software, such as hypervisors, present a layer that will be attacked and security strategies need to be put in place in advance, Gartner warns. The link for this article located at Network World is no longer available. . Cloud technologies enable diverse operational systems, but organizations must prioritize mitigating security vulnerabilities, cautions Forrester.. Virtualization Security, Hypervisor Risks, Risk Management, Security Strategies. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.