Virtualization and Cloud Advisor

Expert analysis and advice on server virtualization technologies, deployments and management.

RSS
All Posts | RSS

Our blogger: Bernard Golden is CEO of consulting firm HyperStratus, which specializes in virtualization, cloud computing and related issues. He is also the author of "Virtualization for Dummies," the best-selling book on virtualization to date.

Fri, May 23, 2008

Threats Lurk Outside Open Doors in Virtual Infrastructure

By Edward L. Haletky

Keywords: VMware, virtual infrastructure, virtual security, virtualization security, Active Directory

According to polls I've conducted on VMware Communities, 80 percent of the people using VMware Virtual Infrastructure trust the security model VMware has used. Yet more than 70 percent are integrating VMware ESX into Active Directory; and only a few are augmenting their security with access controls.

However, anyone with a legitimate AD account has the potential to log in to the VMware ESX service console and gain access to restricted data. Some of this data valuable in itself; much of the rest is critical to the system and could be further used by hackers to craft attacks on other data stores.

Even with group policies and other measures in place, there is a lot of room for individual access rights to go unmodified and leave unintentional access permissions in place.

Incorrectly protected configuration and script files could reveal such things as the system password, server configurations, configuration change histories and the names of VM, network and other resources. In addition, it is possible to see how virtual machines are configured, and the logs associated with the running of VMs.

Thankfully the raw Virtual Machine Disk Format (VMDK) is not available to a generic user, but information about the VM is. That in itself creates an issue. Interestingly enough Network File System (NFS)-based datastores are not accessible at all by a regular user from the VMware ESX host.

The host will give information about how the VM is configured, about the networks to which it's connected, and how the disks are setup as well.

Lastly it is possible for the firewall, Virtual Infrastructure Client authorizations, and other information about the VMware ESX Server to be discovered.

This is useful information for a hacker. I have listed only a few but there is quite a bit of information leakage that could be used to possibly subvert the host.

While the AD authentication is secure when using Secure LDAP or Winbind, it is still possible for non-administrators to gain access to systems and gain vital information about the host, VMs, and the entire virtual environment.

To combat this, servers and networks need to be hardened further. More importantly, VM installations need more authentication controls.

There are at least three methods that can be used to limit access to the VMware ESX host built in to the management appliance.

They are: tcpwrappers (tool to limit access via IP to various daemons), pam_access (tool to limit logins to the system by user, group, and IP in addition to limiting logins to only certain times), and the packet filtering firewall (limit access via IP). It is important to apply at least two of the three listed to get full coverage, just in case one fails.

More from IT Drilldown « Back to Virtualization
CASE STUDY
Bank Scores with Server Virtualization
They say old habits die hard. It's a adage that's certainly true for ICICI Bank's senior GM and the Group CTO, Pravir Vohra. As a man who was part of the team that popularized online banking and helped create a new revenue stream for ICICI Bank, Vohra is already known as an IT leader who can make a difference. Full Story »

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization ABCs

Get up to speed on virtualization.

Learn More »
Virtualization MarketSpace
MarketSpace White Papers
Twenty-to-One Consolidation on Intel Architecture: New Tools for Virtualization and Workload Management
Consolidation isn't easy—especially considering the costs and risks that come with bringing multiple applications and operating systems together on a single mainframe or proprietary platform... Learn more »
Building the Virtualized Enterprise with VMware Infrastructure
Many organizations struggle with their legacy IT infrastructures which are often plagued by high costs, slow response times and inconsistent management... Learn more »
TECHNOLOGY ASSESSMENT: The Impact of Virtualization Software on Operating Environments
Virtualization is a potential game-changer for modern computing. This IDC Technology Assessment discusses how virtualization technologies impact operating environments, now and in the future... Learn more »
Reducing Server Total Cost of Ownership with VMware Virtualization Software
Technology purchases are often quantified simply by hardware and software costs. But there's more to it. This TCO study takes a holistic view—considering soft dollars too, like ongoing maintenance and... Learn more »
 
SPONSORED LINKS
 

Virtualization Benchmark and TCO Analysis-Read Now

New IDG Survey Results on Data Center Automation

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

Learn to Leverage Maximum Computing Power

Windows Vista: Essential Benefits and Deployment Strategies

Best Practices: Safe and Secure Hardware Asset Recovery

White Paper: Migrating to Windows Vista and Microsoft Office 2007 Together

White Paper: Enabling Next Generation IP Communications

White Paper: A Cohesive Network Security Approach

Why Your Firewall, VPN, and IEEE Aren't Enough to Protect Your Network

Dramatically boost network capacity and speed-up to 600 Mbps

Learn how companies are changing how they reach out to their most profitable customers.

Remote Infrastructure Management - What Your Peers are Thinking

Complementary BI: The New Approach to Business Intelligence

Unified Communications & Collaboration: Game-Changing Business Results

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

File Integrity Monitoring: Prove compliance and secure your IT environments

Affordable technology-no compromise. HP server solutions

SOA Educational Library at the TIBCO SOA Resource Center

CIO Viewpoints: Migrating to Exchange 2007

Server Virtualization Benchmark Results

White Paper: The Roadmap to Data Center Automation

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

White Paper: Scaling Down HPC for Smaller Organizations

White Paper: Never Enough Compute Power?

Microsoft Windows Vista Cost and Benefit Estimator

White Paper: Efficient Desktop Application Management

White Paper: Take your Call Center to the Next Level

Is Your WLAN Helping You Comply with Security Guidelines of the PCI Standard?

White Paper: Improve Employee Efficiency and Reduce Telecom Costs

White Paper: Green Issues for Networking

Operational Excellence Is Key to Maximizing IT Investments

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Webcast - "Into the Wild: Managing Laptops Outside the Office"

Mobility is Growing: Survey Shows Why CIOs are Concerned

Learn what it takes to build a holistic digital collaboration platform

Make Hidden Trends, Inter-Relationships and Influences Visible.

Improve delivery of product information to customers.

Renowned Engineering Institution Chooses AMD Processor-Based Servers

Corral, configure and control all your mischievous machinery with a Lantronix device server

Spend less. Get hosted UC. Get cash back. It's easy under a Cypress

Predict the future with HP Insight Power Manager

Log onto Hitachi True Stories, films inspired by the next great achievement

Earn PROFESSIONAL DOCTORATE Part-Time, Online at Syracuse University's iSchool

 
 
RESOURCE CENTER