Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] low power home server



On 11 May 2010 12:00, Darren Cook <darren@example.com> wrote:

> I have root access on a VPS. How can I use this to see the other VPS's
> running on the same box? (I.e. have there been any actual exploits along
> these lines?)--

Yes, sometimes there are bugs in the virtualization software that
allow guests to run code on the host. Googling up an arbitrary
example:

"When booting a guest domain, pygrub uses Python exec() statements to process
untrusted data from grub.conf. By crafting a grub.conf file, the root user in a
guest domain can trigger execution of arbitrary Python code in domain 0."

http://bugzilla.xensource.com/bugzilla/show_bug.cgi?id=1068

Edmund Edgar
Founder, KK Social Minds
Educational Technology for the Web and Virtual Worlds

ed@example.com
+81 090 3912 3380
Skype: edmundedgar
Second Life: Edmund Earp
Linked In: edmundedgar
Twitter: @edmundedgar
http://www.socialminds.jp


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links