<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Professional VMware &#187; virtualization security</title>
	<atom:link href="http://professionalvmware.com/category/virtualization-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://professionalvmware.com</link>
	<description>How Many Turtles Can You Fit On A Rock?</description>
	<lastBuildDate>Mon, 19 Jul 2010 20:47:57 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.5.3" -->
	<copyright>Copyright &#xA9; 2010 Professional VMware http://creativecommons.org/licenses/by-nc-sa/2.5/</copyright>
	<managingEditor>podcast@professionalvmware.com (Cody Bunch)</managingEditor>
	<webMaster>podcast@professionalvmware.com (Cody Bunch)</webMaster>
	<category>podcast</category>
	<ttl>1440</ttl>
	<image>
		<url>http://professionalvmware.com/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>Professional VMware &#187; virtualization security</title>
		<link>http://professionalvmware.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle>ProfessionalVMware BrownBag Series</itunes:subtitle>
	<itunes:summary>ProfessionalVMware BrownBag Series</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Technology" />
	<itunes:category text="Technology">
		<itunes:category text="Podcasting" />
	</itunes:category>
	<itunes:category text="Technology">
		<itunes:category text="Software How-To" />
	</itunes:category>
	<itunes:author>Cody Bunch</itunes:author>
	<itunes:owner>
		<itunes:name>Cody Bunch</itunes:name>
		<itunes:email>podcast@professionalvmware.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://professionalvmware.com/wp-content/plugins/podpress/images/ProVmwarePodcast.jpg" />
		<item>
		<title>ESX Does RSA?</title>
		<link>http://professionalvmware.com/2009/01/esx-does-rsa/</link>
		<comments>http://professionalvmware.com/2009/01/esx-does-rsa/#comments</comments>
		<pubDate>Sun, 04 Jan 2009 13:40:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[VI3]]></category>
		<category><![CDATA[VMware Security]]></category>
		<category><![CDATA[Virtual Infrastructure]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization security]]></category>
		<category><![CDATA[ESX]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://professionalvmware.com/?p=303</guid>
		<description><![CDATA[Sort of, it seems:
Today, RSA integrates with VMware in an couple of what I would call &#34;useful but not earth-shattering&#34; points &#8211; you can integrate envision authentication with Virtual Center and it also integrates with VDM 2.1 and VMware View Manager for hardened authentication.
&#160;
But, with VMware as mission-critical as it is, security focus is getting [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Sort of, it seems:</p>
<blockquote><p>Today, RSA integrates with VMware in an couple of what I would call &quot;useful but not earth-shattering&quot; points &#8211; you can integrate envision authentication with Virtual Center and it also integrates with VDM 2.1 and VMware View Manager for hardened authentication.</p>
<p>&#160;</p>
<p>But, with VMware as mission-critical as it is, security focus is getting strong.&#160;&#160;&#160; At our recent Quarterly Technology Review, there were LOTS of really cool ideas where to go next, and ideas I would consider earth-shattering, but are so fuzzy at this point, there&#8217;s no point in going on about it.&#160;&#160; Let us do some more work, and then I&#8217;ll talk about it again.</p>
</blockquote>
<p>This is from VirtualGeek, full post <a href="http://virtualgeek.typepad.com/virtual_geek/2008/12/virtualization-security---cage-match-fight.html">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://professionalvmware.com/2009/01/esx-does-rsa/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Hypervisor Framework Paper</title>
		<link>http://professionalvmware.com/2008/12/hypervisor-framework-paper/</link>
		<comments>http://professionalvmware.com/2008/12/hypervisor-framework-paper/#comments</comments>
		<pubDate>Fri, 05 Dec 2008 14:34:00 +0000</pubDate>
		<dc:creator>bunchc</dc:creator>
				<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Security]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization security]]></category>

		<guid isPermaLink="false">http://professionalvmware.com/2008/12/05/hypervisor-framework-paper/</guid>
		<description><![CDATA[ 
The Hacker 2 Hacker Conference Brazil this year featured a paper called “Hypervisor Framework”. An interesting read for those more interested in the nitty gritty of how all this “Virtualization” stuff works
]]></description>
			<content:encoded><![CDATA[<p></p><p><img src="http://www.h2hc.com.br/images/lg.jpg" /> </p>
<p>The Hacker 2 Hacker Conference Brazil this year featured a paper called <a href="http://www.h2hc.com.br/repositorio/2008/Hypervisor%20Framework%20H2HC%202008.pdf">“Hypervisor Framework”</a>. An interesting read for those more interested in the nitty gritty of how all this “Virtualization” stuff works</p>
]]></content:encoded>
			<wfw:commentRss>http://professionalvmware.com/2008/12/hypervisor-framework-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security in a Virtual Environment</title>
		<link>http://professionalvmware.com/2008/12/security-in-a-virtual-environment/</link>
		<comments>http://professionalvmware.com/2008/12/security-in-a-virtual-environment/#comments</comments>
		<pubDate>Fri, 05 Dec 2008 03:03:47 +0000</pubDate>
		<dc:creator>bunchc</dc:creator>
				<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware Security]]></category>
		<category><![CDATA[virtualization security]]></category>

		<guid isPermaLink="false">http://professionalvmware.com/2008/12/04/security-in-a-virtual-environment/</guid>
		<description><![CDATA[So Tarry Singh posted today on the VMware security advisiories. While that’s been covered here, and elsewhere, I did find a few of his points interesting:
Ask yourself the following:
* Do you know that such malicious attacks are not taking place in your environment?
* Do you know if there is some sort of control in your [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>So Tarry Singh posted today on the <a href="http://tarrysingh.blogspot.com/2008/12/vmware-security-advisory-update.html">VMware security advisiories</a>. While that’s been covered here, and elsewhere, I did find a few of his points interesting:</p>
<blockquote><p>Ask yourself the following:</p>
<p>* Do you know that such malicious attacks are not taking place in your environment?<br />
* Do you know if there is some sort of control in your environments?<br />
* How many of you have successfully deployed a CCP that makes your ESX compliant or at least anywhere close to being SOX/PCI DSS 1.x standards? You must be able to control, authorize and demonstrate on your sense of control on these environments, can you do it?<br />
* Are you doing any sort of assessments in your environments, especially Virtual Infrastructures be it Oracle VM, VMware ESX, Citrix Xen, Xen or whatever?<br />
* Are some or any of your virtual platforms registered within your centralized directory, any LDAP v3 variants such as ADS etc?</p></blockquote>
<p>Can you answer these for your environment? Just because it’s virtual doesn’t mean you should forget about security.</p>
]]></content:encoded>
			<wfw:commentRss>http://professionalvmware.com/2008/12/security-in-a-virtual-environment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Webcasts &#8211; VMware Security Best Practices</title>
		<link>http://professionalvmware.com/2008/11/webcasts-vmware-security-best-practices/</link>
		<comments>http://professionalvmware.com/2008/11/webcasts-vmware-security-best-practices/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 17:11:58 +0000</pubDate>
		<dc:creator>bunchc</dc:creator>
				<category><![CDATA[ESX]]></category>
		<category><![CDATA[ESX RPMs]]></category>
		<category><![CDATA[VI3]]></category>
		<category><![CDATA[VMware Security]]></category>
		<category><![CDATA[esx 3.5]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization security]]></category>

		<guid isPermaLink="false">http://professionalvmware.com/2008/11/26/webcasts-vmware-security-best-practices/</guid>
		<description><![CDATA[One of these is archived, the other scheduled to go off on Dec. 16th.&#160; Both require registration, and are worthwhile, despite the obligatory sales pitches.
 
http://research.pcpro.co.uk/detail/RES/1224768378_490.html    This one has already happened, and is available on demand.
 
http://www.netiq.com/events/display.asp?cid=20081114152024NVKN&#38;src=smm    This is the Dec16th event.
]]></description>
			<content:encoded><![CDATA[<p></p><p>One of these is archived, the other scheduled to go off on Dec. 16th.&#160; Both require registration, and are worthwhile, despite the obligatory sales pitches.</p>
<p><a href="http://professionalvmware.com/wp-content/uploads/2008/11/image.png"><img title="image" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="94" alt="image" src="http://professionalvmware.com/wp-content/uploads/2008/11/image-thumb.png" width="197" border="0" /></a> </p>
<p><a title="http://research.pcpro.co.uk/detail/RES/1224768378_490.html" href="http://research.pcpro.co.uk/detail/RES/1224768378_490.html">http://research.pcpro.co.uk/detail/RES/1224768378_490.html</a>    <br />This one has already happened, and is available on demand.</p>
<p><a href="http://professionalvmware.com/wp-content/uploads/2008/11/image1.png"><img title="image" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="59" alt="image" src="http://professionalvmware.com/wp-content/uploads/2008/11/image-thumb1.png" width="236" border="0" /></a> </p>
<p><a title="http://www.netiq.com/events/display.asp?cid=20081114152024NVKN&amp;src=smm" href="http://www.netiq.com/events/display.asp?cid=20081114152024NVKN&amp;src=smm">http://www.netiq.com/events/display.asp?cid=20081114152024NVKN&amp;src=smm</a>    <br />This is the Dec16th event.</p>
]]></content:encoded>
			<wfw:commentRss>http://professionalvmware.com/2008/11/webcasts-vmware-security-best-practices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware Security releases</title>
		<link>http://professionalvmware.com/2008/11/vmware-security-releases/</link>
		<comments>http://professionalvmware.com/2008/11/vmware-security-releases/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 03:13:00 +0000</pubDate>
		<dc:creator>bunchc</dc:creator>
				<category><![CDATA[ESX]]></category>
		<category><![CDATA[VI3]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[esx3.5]]></category>
		<category><![CDATA[esxi]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization security]]></category>

		<guid isPermaLink="false">http://professionalvmware.com/?p=9</guid>
		<description><![CDATA[Straight from the VMware Security announcement mailing list:

          http://www.vmware.com/security/advisories/VMSA-2008-0018.html        


VMware Hosted products and patches for ESX and ESXi resolve multiple security issues. A flaw in the CPU hardware emulation may allow for a privilege escalation on virtual machine guest [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Straight from the VMware Security announcement mailing list:</p>
<p>
<p>          <a href="http://www.vmware.com/security/advisories/VMSA-2008-0018.html">http://www.vmware.com/security/advisories/VMSA-2008-0018.html</a>        </p>
<p>
<blockquote>
<p>VMware Hosted products and patches for ESX and ESXi resolve multiple security issues. A flaw in the CPU hardware emulation may allow for a privilege escalation on virtual machine guest operating systems. In addition a directory traversal issue is resolved.</p>
<p></p></blockquote>
<p>
<p>Read that over again&#8230; A flaw in the <em>HOST</em> can lead to a priviledge escalitions in the <em>GUEST.</em> While scary, there is a patch for this. One should also be looking at using Update Manager to download and deploy patches, or at least joining the <a href="http://www.vmware.com/security/advisories/">security announcement list</a>. The form for that is off to the right of the page.</p>
<p>
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com --><br />  <span class="ztags"><span class="ztagspace">Technorati</span> : <a href="http://www.technorati.com/tag/esx" class="ztag" rel="tag">esx</a>, <a href="http://www.technorati.com/tag/esx3.5" class="ztag" rel="tag">esx3.5</a>, <a href="http://www.technorati.com/tag/esxi" class="ztag" rel="tag">esxi</a>, <a href="http://www.technorati.com/tag/security" class="ztag" rel="tag">security</a>, <a href="http://www.technorati.com/tag/virtualization" class="ztag" rel="tag">virtualization</a>, <a href="http://www.technorati.com/tag/virtualization+security" class="ztag" rel="tag">virtualization security</a>, <a href="http://www.technorati.com/tag/vmware" class="ztag" rel="tag">vmware</a></span>  <br/><br /> <span class="ztags"><span class="ztagspace">Del.icio.us</span> : <a href="http://del.icio.us/tag/esx" class="ztag" rel="tag">esx</a>, <a href="http://del.icio.us/tag/esx3.5" class="ztag" rel="tag">esx3.5</a>, <a href="http://del.icio.us/tag/esxi" class="ztag" rel="tag">esxi</a>, <a href="http://del.icio.us/tag/security" class="ztag" rel="tag">security</a>, <a href="http://del.icio.us/tag/virtualization" class="ztag" rel="tag">virtualization</a>, <a href="http://del.icio.us/tag/virtualization%20security" class="ztag" rel="tag">virtualization security</a>, <a href="http://del.icio.us/tag/vmware" class="ztag" rel="tag">vmware</a></span>  <br/><br /> <span class="ztags"><span class="ztagspace">Zooomr</span> : <a href="http://www.zooomr.com/search/photos/?q=esx" class="ztag" rel="tag">esx</a>, <a href="http://www.zooomr.com/search/photos/?q=esx3.5" class="ztag" rel="tag">esx3.5</a>, <a href="http://www.zooomr.com/search/photos/?q=esxi" class="ztag" rel="tag">esxi</a>, <a href="http://www.zooomr.com/search/photos/?q=security" class="ztag" rel="tag">security</a>, <a href="http://www.zooomr.com/search/photos/?q=virtualization" class="ztag" rel="tag">virtualization</a>, <a href="http://www.zooomr.com/search/photos/?q=virtualization%20security" class="ztag" rel="tag">virtualization security</a>, <a href="http://www.zooomr.com/search/photos/?q=vmware" class="ztag" rel="tag">vmware</a></span>  <br/><br /> <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com/photos/tags/esx" class="ztag" rel="tag">esx</a>, <a href="http://www.flickr.com/photos/tags/esx3.5" class="ztag" rel="tag">esx3.5</a>, <a href="http://www.flickr.com/photos/tags/esxi" class="ztag" rel="tag">esxi</a>, <a href="http://www.flickr.com/photos/tags/security" class="ztag" rel="tag">security</a>, <a href="http://www.flickr.com/photos/tags/virtualization" class="ztag" rel="tag">virtualization</a>, <a href="http://www.flickr.com/photos/tags/virtualization%20security" class="ztag" rel="tag">virtualization security</a>, <a href="http://www.flickr.com/photos/tags/vmware" class="ztag" rel="tag">vmware</a></span> </p>
]]></content:encoded>
			<wfw:commentRss>http://professionalvmware.com/2008/11/vmware-security-releases/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
