Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 84 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Virtualization Backdoors Emerge
EH-Net
May 19, 2013, 07:00:11 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Virtualization Backdoors Emerge  (Read 2683 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: July 24, 2006, 02:38:49 PM »

Quote
Virtual machines and virtualization are becoming more popular. For enterprises, virtualization makes server management much easier. But with great new advances in enterprise technology come new techniques to exploit these new advances. In March of this year, the University of Michigan and a Microsoft research team wrote a paper on how it is possible to backdoor a virtual machine.

A prototype of this rootkit, named "subvirt," was created to test this idea. It works by exploiting a vulnerability and then dropping a VMM (virtual machine monitor) underneath a Windows or Linux host. Once the target OS is loaded into a virtual machine, the rootkit becomes impossible to detect because no security software running on the target system can access its position. This really raises the bar for antivirus and anti-spyware/malware applications to try to detect such a rootkit.

You can read more detail about this study at:
http://www.eecs.umich.edu/virtual/papers/king06.pdf

Also, many undocumented back-channels allow various functionalities to communicate with the virtual machine. These back-channel functions allow various actions, such as communicating between the host and a guest operating system and connecting and disconnecting devices. An attacker can use these back channels to further explore a network.

You can read more details about these various back-channels at:
http://chitchat.at.infoseek.co.jp/vmware/index.html

Courtesy of The Neohapsis Security Threat Watch Team

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.