<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Viewpoints &#187; Virtualization</title>
	<atom:link href="http://advosys.ca/viewpoints/category/virtualization/feed/" rel="self" type="application/rss+xml" />
	<link>http://advosys.ca/viewpoints</link>
	<description>Security, operating systems and the IT industry</description>
	<lastBuildDate>Tue, 31 Aug 2010 13:06:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Free XenServer release moved to March 30</title>
		<link>http://advosys.ca/viewpoints/2009/03/free-xenserver-now-march-30/</link>
		<comments>http://advosys.ca/viewpoints/2009/03/free-xenserver-now-march-30/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 13:39:56 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[xen]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=298</guid>
		<description><![CDATA[Quick follow-up to yesterday&#8217;s post: The download page for XenServer / Essentials for XenSource now says: &#8220;The new free Citrix XenServer will be available on March 30.&#8221; So, we&#8217;ll have to wait until Monday. No reason is given for this change that I can find. Meanwhile, you can still download the current version of XenServer [...]]]></description>
			<content:encoded><![CDATA[<p>Quick follow-up to <a title="XenServer virtualization to go free today" href="http://advosys.ca/viewpoints/2009/03/xenserver-essentials-virtualization-free/">yesterday&#8217;s post</a>:</p>
<p>The <a title="Xensource downloads" href="http://www.citrix.com/English/ps2/products/subfeature.asp?contentID=1681151">download page</a> for XenServer / Essentials for XenSource now says:</p>
<blockquote><p>&#8220;The new free Citrix XenServer will be available on March 30.&#8221;</p></blockquote>
<p>So, we&#8217;ll have to wait until Monday. No reason is given for this change that I can find.</p>
<p>Meanwhile, you can still download the current version of XenServer for free along with a license key that apparently enables the high availability and storage management features of Essentials.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2009/03/xenserver-essentials-virtualization-free/' rel='bookmark' title='Permanent Link: XenServer virtualization to go free today'>XenServer virtualization to go free today</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2009/03/free-xenserver-now-march-30/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>XenServer virtualization to go free today</title>
		<link>http://advosys.ca/viewpoints/2009/03/xenserver-essentials-virtualization-free/</link>
		<comments>http://advosys.ca/viewpoints/2009/03/xenserver-essentials-virtualization-free/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 12:05:54 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[xen]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=293</guid>
		<description><![CDATA[March 25 is the day Citrix their promised to release XenServer with the Essentials virtualization management suite for free. As of 8:30am EDT their download page still points to a different version. Hopefully that will change in a few hours. VMware paved the way a few years ago by releasing VMWare Server for free, followed [...]]]></description>
			<content:encoded><![CDATA[<p>March 25 is the day Citrix their promised to release <a title="Citrix XenSource" href="http://www.xensource.com/">XenServer</a> with the <a title="Essentials for XenSource" href="http://http://www.xensource.com/">Essentials</a> virtualization management suite for free.</p>
<p>As of 8:30am EDT their <a title="Citrix Xen downloads" href="http://www.citrix.com/English/ps2/products/subfeature.asp?contentID=1681151">download page</a> still points to a different version. Hopefully that will change in a few hours.</p>
<p>VMware paved the way a few years ago by releasing <a title="VMware Server" href="http://www.vmware.com/products/server/">VMWare Server</a> for free, followed later the higher performance <a title="ESXi base metal hypervisor" href="http://www.vmware.com/products/esxi/">ESXi hypervisor</a> kernel. Microsoft has their own &#8220;free&#8221; hypervisor HyperV, but this offering from Citrix blows all of those away.</p>
<p>XenServer with Essentials provides VMotion-like live migration of running VMs for load balancing and high availability, shared storage management, and centralized management of VM image. Apparently it can provision both virtual and physical servers by booting either from images served over the network.</p>
<p>Xen has been popular for a while with newer virtual private server hosting providers like <a title="SliceHost" href="http://www.slicehost.com/">SliceHost</a> and <a title="GoGrid" href="http://www.gogrid.com/">GoGrid</a> , and is the hypervisor used by &#8220;cloud computing&#8221; providers, most notably <a title="Amazon Elastic Cloud Computing" href="http://aws.amazon.com/ec2/">Amazon EC2</a>.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2009/03/free-xenserver-now-march-30/' rel='bookmark' title='Permanent Link: Free XenServer release moved to March 30'>Free XenServer release moved to March 30</a></li>
<li><a href='http://advosys.ca/viewpoints/2006/11/security-of-virtualization/' rel='bookmark' title='Permanent Link: Security of virtualization'>Security of virtualization</a></li>
<li><a href='http://advosys.ca/viewpoints/2006/04/virtualization-insecurity/' rel='bookmark' title='Permanent Link: Can virtualization be trusted for security?'>Can virtualization be trusted for security?</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2009/03/xenserver-essentials-virtualization-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIS releases Vmware ESX security guide</title>
		<link>http://advosys.ca/viewpoints/2007/10/cis-vmware-esx-security-guide/</link>
		<comments>http://advosys.ca/viewpoints/2007/10/cis-vmware-esx-security-guide/#comments</comments>
		<pubDate>Tue, 23 Oct 2007 21:29:15 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[virtualization security]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/2007/10/cis-vmware-esx-security-guide/</guid>
		<description><![CDATA[The Center for Internet Security has now released guidelines for hardening hosts running VMWare ESX Server 3. This supplements the more general virtual machine security guide they published in September. The ESX guidelines cover basic to intermediate techniques for hardening the ESX host and linux-based service console, including ESX-specific guidance for file and directory permissions [...]]]></description>
			<content:encoded><![CDATA[<p>The <a title="Center for Internet Security" href="http://cisecurity.org/">Center for Internet Security</a> has now released <a title=" CIS Level 1 Benchmark for Virtual Machines" href="http://cisecurity.org/bench_vm.html">guidelines</a> for hardening hosts running VMWare ESX Server 3. This supplements the more general virtual machine security guide <a title="CIS releases virtual machine security guide" href="http://advosys.ca/viewpoints/2007/09/cis-virtualization-security-guide/">they published</a> in September.</p>
<p>The ESX guidelines cover basic to intermediate techniques for hardening the ESX host and linux-based service console, including ESX-specific guidance for file and directory permissions and kernel tuning, and recommendations for the remote web and GUI consoles.</p>
<p>There is no automated scoring tool for assessing conformance to the recommendations, but a backup script and list of critical files to backup in the service console before making changes are provided.</p>
<p>Download the guidelines here: <a title="VMware ESX Server 3.x Benchmark" href="http://cisecurity.org/bench_vm.html">VMware ESX Server 3.x Benchmark</a></p>
<p><em>Update (Mar 2008)</em>: Another VMware ESX guide that also covers SAN, network and other often ignored components has been released by by the NSA. Find it (and guidelines for many other products) here: <a title="NSA current security configuration guides" href="http://www.nsa.gov/ia/guidance/security_configuration_guides/current_guides.shtml">NSA Current Security Configuration Guides</a></p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2007/09/cis-virtualization-security-guide/' rel='bookmark' title='Permanent Link: CIS releases virtual machine security guide'>CIS releases virtual machine security guide</a></li>
<li><a href='http://advosys.ca/viewpoints/2007/09/multiple-critical-vulnerabilities-in-all-vmware-products/' rel='bookmark' title='Permanent Link: Multiple critical vulnerabilities in all VMware products'>Multiple critical vulnerabilities in all VMware products</a></li>
<li><a href='http://advosys.ca/viewpoints/2007/05/vmware-workstation-6-released/' rel='bookmark' title='Permanent Link: VMware Workstation 6 released'>VMware Workstation 6 released</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2007/10/cis-vmware-esx-security-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple critical vulnerabilities in all VMware products</title>
		<link>http://advosys.ca/viewpoints/2007/09/multiple-critical-vulnerabilities-in-all-vmware-products/</link>
		<comments>http://advosys.ca/viewpoints/2007/09/multiple-critical-vulnerabilities-in-all-vmware-products/#comments</comments>
		<pubDate>Thu, 20 Sep 2007 15:37:05 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[virtualization security]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/2007/09/multiple-critical-vulnerabilities-in-all-vmware-products/</guid>
		<description><![CDATA[VMware has announced several privilege escalation and denial of service vulnerabilities affecting every single supported VMware product, including the flagship VMware ESX server product line. Some of the issues could potentially allow users in a guest VM to execute code on the host, so these are critical problems. Interestingly, the issues are not in the [...]]]></description>
			<content:encoded><![CDATA[<p>
   VMware has announced several privilege escalation and denial of service vulnerabilities affecting every single supported VMware product, including the flagship VMware ESX server product line. Some of the issues could potentially allow users in a guest VM to execute code on the host, so these are critical problems.
</p>
<p>
   Interestingly, the issues are not in the virtualization technology itself but in supporting services like the DHCP service and components of the Linux-based admin console in VMware ESX such as Samba and cron.
</p>
<p>
   Secunia has <a href="http://secunia.com/advisories/26909/" title="VMware ESX Server Multiple Security Updates">posted some details</a> . The official announcement from VMware seems to have only gone out to subscribers of their security mailing list  (I can&#8217;t find it on their web site) but Full Disclosure has <a href="http://archives.neohapsis.com/archives/fulldisclosure/2007-09/0356.html" title="Full-disclosure] VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player">a copy here</a> .
</p>
<p>
   Now, is there anyone who <a href="http://advosys.ca/viewpoints/2006/04/virtualization-insecurity/" title="Can virtualization be trusted for security?">still wants to argue</a>  that isolation of VMware guests is just as good as physical servers? Even if the virtualization mechanism itself is sound (which is still an very risky assumption to make), bugs in the guest-to-host communication components or admin components could be exploited.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2007/05/vmware-workstation-6-released/' rel='bookmark' title='Permanent Link: VMware Workstation 6 released'>VMware Workstation 6 released</a></li>
<li><a href='http://advosys.ca/viewpoints/2007/10/cis-vmware-esx-security-guide/' rel='bookmark' title='Permanent Link: CIS releases Vmware ESX security guide'>CIS releases Vmware ESX security guide</a></li>
<li><a href='http://advosys.ca/viewpoints/2007/09/cis-virtualization-security-guide/' rel='bookmark' title='Permanent Link: CIS releases virtual machine security guide'>CIS releases virtual machine security guide</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2007/09/multiple-critical-vulnerabilities-in-all-vmware-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIS releases virtual machine security guide</title>
		<link>http://advosys.ca/viewpoints/2007/09/cis-virtualization-security-guide/</link>
		<comments>http://advosys.ca/viewpoints/2007/09/cis-virtualization-security-guide/#comments</comments>
		<pubDate>Wed, 12 Sep 2007 11:12:53 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Best practices]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[virtualization security]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/2007/09/cis-virtualization-security-guide/</guid>
		<description><![CDATA[The Center for Internet Security (CIS) has published a nice little guideline on hardening virtual machines . The guide covers security issues for both guests and hosts and applies to any virtualization product, not just VMWare. CIS has created a number of guidelines for hardening popular operating systems, routers and server applications such as Apache, [...]]]></description>
			<content:encoded><![CDATA[<p>
   The <a href="http://cisecurity.org/bench_vm.html" title="Center for Internet Security">Center for Internet Security</a>  (CIS) has published a nice little <a href="http://cisecurity.org/bench_vm.html" title="Virtual Machine Security Guidelines">guideline on hardening virtual machines</a> . The guide covers security issues for both guests and hosts and applies to any virtualization product, not just VMWare.
</p>
<p>
   CIS has created a number of guidelines for hardening popular operating systems, routers and server applications such as Apache, IIS, and Oracle. They called them &#8220;benchmarks&#8221; and are developed with input from private industry and government players. The guidelines are not as in-depth as <a href="http://csrc.nist.gov/publications/nistpubs/" title="NIST special publications 800 series">those from NIST</a> , but are very readable and cover the minimum requirements for hardening systems. CIS has also created some automated assessment tools for many products to evaluate how well the guidelines have been applied.
</p>
<p>
   This new virtualization security guide is just 30 pages but manages to broadly cover the issues:
</p>
<ul>
<li>Types of virtual machines (e.g. paravirtualization vs hardware-based VMs)</li>
<li> 	Types of threats (escaping a guest, host compromize, denial of service etc)</li>
<li>Best practices for hardening guests and host OSs</li>
<li>Best practices for managing VMs, including remote managemen</li>
</ul>
<p>
The guide is not specific to one virtualization product so obviously there is no accompanying automated assessment tool. Hopefully in the future CIS will publish a guide specifically for market leader VMWare ESX.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2007/10/cis-vmware-esx-security-guide/' rel='bookmark' title='Permanent Link: CIS releases Vmware ESX security guide'>CIS releases Vmware ESX security guide</a></li>
<li><a href='http://advosys.ca/viewpoints/2007/01/attacks-on-virtual-machines/' rel='bookmark' title='Permanent Link: Attacks on Virtual Machines'>Attacks on Virtual Machines</a></li>
<li><a href='http://advosys.ca/viewpoints/2007/04/fuzzing-virtual-machines/' rel='bookmark' title='Permanent Link: Fuzzing virtual machines'>Fuzzing virtual machines</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2007/09/cis-virtualization-security-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMware Workstation 6 released</title>
		<link>http://advosys.ca/viewpoints/2007/05/vmware-workstation-6-released/</link>
		<comments>http://advosys.ca/viewpoints/2007/05/vmware-workstation-6-released/#comments</comments>
		<pubDate>Thu, 10 May 2007 01:52:48 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/2007/05/vmware-workstation-6-released/</guid>
		<description><![CDATA[The latest edition of VMware Workstation is finally out of beta and available for download. Once again, VMware allows existing users of Workstation 5 to upgrade for a hundred bucks U.S. In addition to the usual incremental improvements and official support for an even greater number of guest operating systems (including Windows Vista as both [...]]]></description>
			<content:encoded><![CDATA[<p>
        The latest edition of VMware Workstation is finally out of beta and available for download. Once again, VMware allows existing users of Workstation 5 to upgrade for a hundred bucks U.S.
</p>
<p>
        In addition to the usual incremental improvements and official support for an even greater number of guest operating systems (including Windows Vista as both host and guest), this iteration of Workstation adds USB 2.0 support, session record/reply, and ability to run VMs without the console also running. See the full  <a href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" title="VMware Workstation 6 release notes">release notes</a> for details.
</p>
<p>
        There are only a few really useful new features I see:
</p>
<ul>
<li>Ability to use <em>all </em>host memory (previous limit was 4GB) and up to 8GB per VM.</li>
<li>Debugger integration with Eclipse and Visual Studio IDEs.</li>
<li>Experimental support for para-virtualized kernels in Linux guests (&#8220;Virtual Machine Interface 3.0 enabled kernels&#8221;, according to the <a href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" title="VMware Workstation 6 release notes">release notes</a>).</li>
<li>a new &#8220;ACE option pack&#8221; add-on that allows Workstation to create guests that can run stand-alone from portable media.</li>
</ul>
<p>
       It&#8217;s not clear whether the guests created with the &#8220;option pack&#8221; are equally as protected from the host as they are with <a href="http://www.vmware.com/solutions/desktop/endpoint.html">VMware ACE</a>. Looks like I&#8217;ll find out soon&#8230; until May of 2006, VMware is offering the ACE option pack free both for new purchases and for users upgrading from Workstation 5.5.<span id="more-149"></span>
</p>
<p>
  It&#8217;s painful to think how we ever got anything done before VMware Workstation (and later VMware Server) became available. Five years ago for research, testing, and supporting clients we had several boxes with one or two removable hard drive caddies, and a closet full of drives containing flavors of Linux, BSD, Windows, and Solaris all ready to boot when needed. Dedicated servers ran the OSs we needed to access the most.
</p>
<p>
  Now we have a library of images stored on one file server, ready to boot up under VMware Server or copy to a laptop to run under Workstation, and a couple of production VMs always running. We keep images of some client&#8217;s production servers on hand for support and for testing upgrades. No need to decide what to keep either&#8230; obsolete OS images get burned to DVD in case they&#8217;re ever needed again (I think we even have an image of SCO Unix in the vault).
</p>
<p>
  It&#8217;s become fantastically easier (and cheaper) to get things done thanks to virtualization tools. The trade press concentrates heavily on &#8220;revolutionary&#8221; benefits of virtualization for consolidating physical servers, but I think the real revolution for most organizations has been in using tools like VMWare Workstation for research, development and support.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2007/09/multiple-critical-vulnerabilities-in-all-vmware-products/' rel='bookmark' title='Permanent Link: Multiple critical vulnerabilities in all VMware products'>Multiple critical vulnerabilities in all VMware products</a></li>
<li><a href='http://advosys.ca/viewpoints/2007/10/cis-vmware-esx-security-guide/' rel='bookmark' title='Permanent Link: CIS releases Vmware ESX security guide'>CIS releases Vmware ESX security guide</a></li>
<li><a href='http://advosys.ca/viewpoints/2009/03/xenserver-essentials-virtualization-free/' rel='bookmark' title='Permanent Link: XenServer virtualization to go free today'>XenServer virtualization to go free today</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2007/05/vmware-workstation-6-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

