Virtualisation: There Is No Spoon

No ratings

Presented at TROOPERS 2008 by

Virtualised technologies are being lapped up left, right and centre by corporates committed to the cash savings they promise. Sadly the savings that can be gleaned are not without the attendant risk. Instead of nice normal networks that people can understand, many vendors are offering networks in a box. As well as being lovely single points of failure, they have a number of risks that remain largely unexplored. Research has already been conducted around VMWare, but there still exists a fundamental flaw that no-one seems to have spotted. This talk will illustrate why and how virtualisation works, what the difference is between what the vendors say and how it is being implemented in RL, and discusses a theoretical vulnerability that if it can be exploited can bring down the house of cards. Additionally if it can be made to work pre-con a significant vulnerability in Active Directory will be demonstrated, not for any particular reasons of relevance, but because it is very, very amusing.