<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Professional VMware &#187; virtualization security</title> <atom:link href="http://professionalvmware.com/category/virtualization-security/feed/" rel="self" type="application/rss+xml" /><link>http://professionalvmware.com</link> <description>How Many Turtles Can You Fit On A Rock?</description> <lastBuildDate>Thu, 24 May 2012 13:39:29 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.2</generator> <item><title>ESX Does RSA?</title><link>http://professionalvmware.com/2009/01/esx-does-rsa/</link> <comments>http://professionalvmware.com/2009/01/esx-does-rsa/#comments</comments> <pubDate>Sun, 04 Jan 2009 13:40:38 +0000</pubDate> <dc:creator>admin</dc:creator> <category><![CDATA[security]]></category> <category><![CDATA[VI3]]></category> <category><![CDATA[Virtual Infrastructure]]></category> <category><![CDATA[virtualization security]]></category> <category><![CDATA[VMware Security]]></category> <category><![CDATA[ESX]]></category> <category><![CDATA[rsa]]></category> <category><![CDATA[VMware]]></category> <guid
isPermaLink="false">http://professionalvmware.com/?p=303</guid> <description><![CDATA[Sort of, it seems: Today, RSA integrates with VMware in an couple of what I would call &#34;useful but not earth-shattering&#34; points &#8211; you can integrate envision authentication with Virtual Center and it also integrates with VDM 2.1 and VMware View Manager for hardened authentication. &#160; But, with VMware as mission-critical as it is, security [...]]]></description> <content:encoded><![CDATA[<p></p><p>Sort of, it seems:</p><blockquote><p>Today, RSA integrates with VMware in an couple of what I would call &quot;useful but not earth-shattering&quot; points &#8211; you can integrate envision authentication with Virtual Center and it also integrates with VDM 2.1 and VMware View Manager for hardened authentication.</p><p>&#160;</p><p>But, with VMware as mission-critical as it is, security focus is getting strong.&#160;&#160;&#160; At our recent Quarterly Technology Review, there were LOTS of really cool ideas where to go next, and ideas I would consider earth-shattering, but are so fuzzy at this point, there&#8217;s no point in going on about it.&#160;&#160; Let us do some more work, and then I&#8217;ll talk about it again.</p></blockquote><p>This is from VirtualGeek, full post <a
href="http://virtualgeek.typepad.com/virtual_geek/2008/12/virtualization-security---cage-match-fight.html">here</a>.</p> ]]></content:encoded> <wfw:commentRss>http://professionalvmware.com/2009/01/esx-does-rsa/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Hypervisor Framework Paper</title><link>http://professionalvmware.com/2008/12/hypervisor-framework-paper/</link> <comments>http://professionalvmware.com/2008/12/hypervisor-framework-paper/#comments</comments> <pubDate>Fri, 05 Dec 2008 14:34:00 +0000</pubDate> <dc:creator>bunchc</dc:creator> <category><![CDATA[security]]></category> <category><![CDATA[Virtualization]]></category> <category><![CDATA[virtualization security]]></category> <category><![CDATA[VMware]]></category> <category><![CDATA[VMware Security]]></category> <guid
isPermaLink="false">http://professionalvmware.com/2008/12/05/hypervisor-framework-paper/</guid> <description><![CDATA[The Hacker 2 Hacker Conference Brazil this year featured a paper called “Hypervisor Framework”. An interesting read for those more interested in the nitty gritty of how all this “Virtualization” stuff works]]></description> <content:encoded><![CDATA[<p></p><p><img
src="http://www.h2hc.com.br/images/lg.jpg" /></p><p>The Hacker 2 Hacker Conference Brazil this year featured a paper called <a
href="http://www.h2hc.com.br/repositorio/2008/Hypervisor%20Framework%20H2HC%202008.pdf">“Hypervisor Framework”</a>. An interesting read for those more interested in the nitty gritty of how all this “Virtualization” stuff works</p> ]]></content:encoded> <wfw:commentRss>http://professionalvmware.com/2008/12/hypervisor-framework-paper/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Security in a Virtual Environment</title><link>http://professionalvmware.com/2008/12/security-in-a-virtual-environment/</link> <comments>http://professionalvmware.com/2008/12/security-in-a-virtual-environment/#comments</comments> <pubDate>Fri, 05 Dec 2008 03:03:47 +0000</pubDate> <dc:creator>bunchc</dc:creator> <category><![CDATA[virtualization security]]></category> <category><![CDATA[VMware]]></category> <category><![CDATA[VMware Security]]></category> <guid
isPermaLink="false">http://professionalvmware.com/2008/12/04/security-in-a-virtual-environment/</guid> <description><![CDATA[So Tarry Singh posted today on the VMware security advisiories. While that’s been covered here, and elsewhere, I did find a few of his points interesting: Ask yourself the following: * Do you know that such malicious attacks are not taking place in your environment? * Do you know if there is some sort of [...]]]></description> <content:encoded><![CDATA[<p></p><p>So Tarry Singh posted today on the <a
href="http://tarrysingh.blogspot.com/2008/12/vmware-security-advisory-update.html">VMware security advisiories</a>. While that’s been covered here, and elsewhere, I did find a few of his points interesting:</p><blockquote><p>Ask yourself the following:</p><p>* Do you know that such malicious attacks are not taking place in your environment?<br
/> * Do you know if there is some sort of control in your environments?<br
/> * How many of you have successfully deployed a CCP that makes your ESX compliant or at least anywhere close to being SOX/PCI DSS 1.x standards? You must be able to control, authorize and demonstrate on your sense of control on these environments, can you do it?<br
/> * Are you doing any sort of assessments in your environments, especially Virtual Infrastructures be it Oracle VM, VMware ESX, Citrix Xen, Xen or whatever?<br
/> * Are some or any of your virtual platforms registered within your centralized directory, any LDAP v3 variants such as ADS etc?</p></blockquote><p>Can you answer these for your environment? Just because it’s virtual doesn’t mean you should forget about security.</p> ]]></content:encoded> <wfw:commentRss>http://professionalvmware.com/2008/12/security-in-a-virtual-environment/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Webcasts &#8211; VMware Security Best Practices</title><link>http://professionalvmware.com/2008/11/webcasts-vmware-security-best-practices/</link> <comments>http://professionalvmware.com/2008/11/webcasts-vmware-security-best-practices/#comments</comments> <pubDate>Wed, 26 Nov 2008 17:11:58 +0000</pubDate> <dc:creator>bunchc</dc:creator> <category><![CDATA[ESX]]></category> <category><![CDATA[esx 3.5]]></category> <category><![CDATA[ESX RPMs]]></category> <category><![CDATA[security]]></category> <category><![CDATA[VI3]]></category> <category><![CDATA[virtualization security]]></category> <category><![CDATA[VMware Security]]></category> <guid
isPermaLink="false">http://professionalvmware.com/2008/11/26/webcasts-vmware-security-best-practices/</guid> <description><![CDATA[One of these is archived, the other scheduled to go off on Dec. 16th.&#160; Both require registration, and are worthwhile, despite the obligatory sales pitches. http://research.pcpro.co.uk/detail/RES/1224768378_490.html This one has already happened, and is available on demand. http://www.netiq.com/events/display.asp?cid=20081114152024NVKN&#38;src=smm This is the Dec16th event.]]></description> <content:encoded><![CDATA[<p></p><p>One of these is archived, the other scheduled to go off on Dec. 16th.&#160; Both require registration, and are worthwhile, despite the obligatory sales pitches.</p><p><a
href="http://professionalvmware.com/wp-content/uploads/2008/11/image.png"><img
title="image" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="94" alt="image" src="http://professionalvmware.com/wp-content/uploads/2008/11/image-thumb.png" width="197" border="0" /></a></p><p><a
title="http://research.pcpro.co.uk/detail/RES/1224768378_490.html" href="http://research.pcpro.co.uk/detail/RES/1224768378_490.html">http://research.pcpro.co.uk/detail/RES/1224768378_490.html</a> <br
/>This one has already happened, and is available on demand.</p><p><a
href="http://professionalvmware.com/wp-content/uploads/2008/11/image1.png"><img
title="image" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="59" alt="image" src="http://professionalvmware.com/wp-content/uploads/2008/11/image-thumb1.png" width="236" border="0" /></a></p><p><a
title="http://www.netiq.com/events/display.asp?cid=20081114152024NVKN&amp;src=smm" href="http://www.netiq.com/events/display.asp?cid=20081114152024NVKN&amp;src=smm">http://www.netiq.com/events/display.asp?cid=20081114152024NVKN&amp;src=smm</a> <br
/>This is the Dec16th event.</p> ]]></content:encoded> <wfw:commentRss>http://professionalvmware.com/2008/11/webcasts-vmware-security-best-practices/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>VMware Security releases</title><link>http://professionalvmware.com/2008/11/vmware-security-releases/</link> <comments>http://professionalvmware.com/2008/11/vmware-security-releases/#comments</comments> <pubDate>Wed, 12 Nov 2008 03:13:00 +0000</pubDate> <dc:creator>bunchc</dc:creator> <category><![CDATA[ESX]]></category> <category><![CDATA[esx3.5]]></category> <category><![CDATA[esxi]]></category> <category><![CDATA[security]]></category> <category><![CDATA[VI3]]></category> <category><![CDATA[Virtualization]]></category> <category><![CDATA[virtualization security]]></category> <category><![CDATA[VMware]]></category> <guid
isPermaLink="false">http://professionalvmware.com/?p=9</guid> <description><![CDATA[Straight from the VMware Security announcement mailing list: http://www.vmware.com/security/advisories/VMSA-2008-0018.html VMware Hosted products and patches for ESX and ESXi resolve multiple security issues. A flaw in the CPU hardware emulation may allow for a privilege escalation on virtual machine guest operating systems. In addition a directory traversal issue is resolved. Read that over again&#8230; A flaw [...]]]></description> <content:encoded><![CDATA[<p></p><p>Straight from the VMware Security announcement mailing list:</p><p><p> <a
href="http://www.vmware.com/security/advisories/VMSA-2008-0018.html">http://www.vmware.com/security/advisories/VMSA-2008-0018.html</a></p><p><blockquote><p>VMware Hosted products and patches for ESX and ESXi resolve multiple security issues. A flaw in the CPU hardware emulation may allow for a privilege escalation on virtual machine guest operating systems. In addition a directory traversal issue is resolved.</p><p></p></blockquote><p><p>Read that over again&#8230; A flaw in the <em>HOST</em> can lead to a priviledge escalitions in the <em>GUEST.</em> While scary, there is a patch for this. One should also be looking at using Update Manager to download and deploy patches, or at least joining the <a
href="http://www.vmware.com/security/advisories/">security announcement list</a>. The form for that is off to the right of the page.</p><p><p
xmlns="" class="zoundry_raven_tags"> <br
/> <span
class="ztags"><span
class="ztagspace">Technorati</span> : <a
href="http://www.technorati.com/tag/esx" class="ztag" rel="tag">esx</a>, <a
href="http://www.technorati.com/tag/esx3.5" class="ztag" rel="tag">esx3.5</a>, <a
href="http://www.technorati.com/tag/esxi" class="ztag" rel="tag">esxi</a>, <a
href="http://www.technorati.com/tag/security" class="ztag" rel="tag">security</a>, <a
href="http://www.technorati.com/tag/virtualization" class="ztag" rel="tag">virtualization</a>, <a
href="http://www.technorati.com/tag/virtualization+security" class="ztag" rel="tag">virtualization security</a>, <a
href="http://www.technorati.com/tag/vmware" class="ztag" rel="tag">vmware</a></span> <br/><br
/> <span
class="ztags"><span
class="ztagspace">Del.icio.us</span> : <a
href="http://del.icio.us/tag/esx" class="ztag" rel="tag">esx</a>, <a
href="http://del.icio.us/tag/esx3.5" class="ztag" rel="tag">esx3.5</a>, <a
href="http://del.icio.us/tag/esxi" class="ztag" rel="tag">esxi</a>, <a
href="http://del.icio.us/tag/security" class="ztag" rel="tag">security</a>, <a
href="http://del.icio.us/tag/virtualization" class="ztag" rel="tag">virtualization</a>, <a
href="http://del.icio.us/tag/virtualization%20security" class="ztag" rel="tag">virtualization security</a>, <a
href="http://del.icio.us/tag/vmware" class="ztag" rel="tag">vmware</a></span> <br/><br
/> <span
class="ztags"><span
class="ztagspace">Zooomr</span> : <a
href="http://www.zooomr.com/search/photos/?q=esx" class="ztag" rel="tag">esx</a>, <a
href="http://www.zooomr.com/search/photos/?q=esx3.5" class="ztag" rel="tag">esx3.5</a>, <a
href="http://www.zooomr.com/search/photos/?q=esxi" class="ztag" rel="tag">esxi</a>, <a
href="http://www.zooomr.com/search/photos/?q=security" class="ztag" rel="tag">security</a>, <a
href="http://www.zooomr.com/search/photos/?q=virtualization" class="ztag" rel="tag">virtualization</a>, <a
href="http://www.zooomr.com/search/photos/?q=virtualization%20security" class="ztag" rel="tag">virtualization security</a>, <a
href="http://www.zooomr.com/search/photos/?q=vmware" class="ztag" rel="tag">vmware</a></span> <br/><br
/> <span
class="ztags"><span
class="ztagspace">Flickr</span> : <a
href="http://www.flickr.com/photos/tags/esx" class="ztag" rel="tag">esx</a>, <a
href="http://www.flickr.com/photos/tags/esx3.5" class="ztag" rel="tag">esx3.5</a>, <a
href="http://www.flickr.com/photos/tags/esxi" class="ztag" rel="tag">esxi</a>, <a
href="http://www.flickr.com/photos/tags/security" class="ztag" rel="tag">security</a>, <a
href="http://www.flickr.com/photos/tags/virtualization" class="ztag" rel="tag">virtualization</a>, <a
href="http://www.flickr.com/photos/tags/virtualization%20security" class="ztag" rel="tag">virtualization security</a>, <a
href="http://www.flickr.com/photos/tags/vmware" class="ztag" rel="tag">vmware</a></span></p> ]]></content:encoded> <wfw:commentRss>http://professionalvmware.com/2008/11/vmware-security-releases/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
