Recommended Posts

Ok... I got your point.. :)

If virtual machine has no network for access to your host,your host won't get affect by any virus in your guest operating system. :)

What? You're thinking of trojans, viruses don't need internet/network connections to operate.

His point was that if the guest can not access host via network, then its not possible to jump from guest to host. Which is true - guest unless setup has no access to host file system, so if no network access it should not be possible for infection to jump from guest to host.

Unless person with access to host filesystem exe something off guest file system.

His point was that if the guest can not access host via network, then its not possible to jump from guest to host. Which is true - guest unless setup has no access to host file system, so if no network access it should not be possible for infection to jump from guest to host.

Unless person with access to host filesystem exe something off guest file system.

No it's not true, viruses can exploit sandbox/VM things which is why recently as I said on the other page that hyperV, virtualbox, and all the other large-scale VM solutions with the exception of VMware had an exploit leaked that will pass from the guest to the host no problem. You've also got bugs in CPUs that can allow exploits too.

And that is a RARE specific exploit - I run vmware esxi, I have not heard of any guest to host exploits?

Could you link to these exploits from guest to host?

And along with I normally run antivirus on my windows guests. And when I use that to access questionable locations or files, I have a snapshot taken before and after done just rollback to before.

I agree no system is going to be 100% fullproof - but the odds of moving from guest to host has got to be rare. My point was that if the vm has network access or shared access to the host filesystem, then sure it would be easy for something to jump to another box on the network if a worm and other boxes are open to it, and or if guest has write access to host filesystem it could infect/encrypt/delete/etc files on the host filesystem.

Ok - 2nd one is dos attack, not a guest-host escape

"This is a denial of service vulnerability. An attacker who exploited this vulnerability could cause the affected Hyper-V server to stop responding, requiring a restart. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights on the Hyper-V server, but it could cause the affected system to stop accepting requests."

3rd one again is talking about dos, not escape.

Again not saying they don't exist - there was Cloudburst back in 2009. But do you know of any active guest-host escapes in the wild? Other than whitepapers discussing the possibility?

Are you aware of any malware/extortionware/virus that uses such complicated exploits?

Again I will agree that nothing is 100% secure, and yes there always going to be security issues that need to be addressed. But it comes down to is the exploit in the wild? Is it something that you surfing the underbelly of the net, or driveby or even running some keygen or hacked game or application is going to be infecting your machine and jumping to your host?

I would be more concerned with running bad code (worm) that then could then seek out your other vms or physical or even host machine via network than a guest-host escape.

Generally speaking, not talking a targeted attack against your infrastructure - some paid hacker getting into a company through a vm that is exposed to the public net, etc. Just generally speaking its unlikely to have to be worried about a guest-host escape no matter what your running be it virtualbox, vmware workstation (type2) or something like esxi/xen/kvm (type1).

Should you be aware that such things can exist - sure! If your tinfoil hat is a bit tight, maybe you don't run the vm tools on your vm - this is generally going to be the attack vector currently. Must of the stuff I have seen has been against intel, so run amd cpus on your host ;)

But common sense would tell you not to allow your VMs to have rw to your host filesystem via vm sharing tools or setup, etc. And if your playing with bad code - you might want to isolate their network connectivity to the rest of your vms/host/local network.

I don't know of any publically available viruses that utilise it no, but the reason for that is because the people that know about these security flaws will be governments and incredibly sophisticated hackers, they won't be telling OEMs about them nor releasing POCs about them either but will use them discreetly in the shadows without anyone knowing.

"about these security flaws will be governments and incredibly sophisticated hackers"

So you think a virus scanner you got from mcafee or nod or whatever is going to protect against a government backed attack?

So as I was saying, generally speaking guest-host escapes is not something the general user base - say running some vms on my home lab box for example needs to be worried about protecting against. Other than making sure your VM software be it type1 or 2 is updated, and host os are patched and securely configured.

And in this context you could be pretty sure that this form of exploit is not going to be used when you download that keygen or hacked exe of some game or application or surf the dark underbelly of the net. What you should be concerned with is more that you can roll the vm back after you play with something like that. Or that the box does not become infected with the lastest worm that could infect your other vms/local network.

I think we are the same page yes?

Hello,

There was a discussion not too long ago of the Windows version of OSX/Crisis infecting virtual machines, and I though the Koobface malware contained an exploit for VMware that allowed it to escape from the guest OS to the host OS, but I cannot seem to find an exact reference to it. I think this would have been around 2009-2010, though.

Regards,

Aryeh Goretsky

The recent one was fine if you use vmware, it was not vulnerable.

Here's some links to things about the bugs;

http://www.aidanfinn.com/?p=12837

http://technet.micro...lletin/ms11-047

http://blog.coresecu...ploit-ms10-102/

Hello,

I am unsure of why McAfee or ESET of any of the other anti-malware programs would not protect you. They detect various pieces of malware such as ACAD/Medre, OSX/Lamadai, Win32/Duqu, Win32/Flamer, Win32/Georbot, Win32/R2D2 and Win32/Stuxnet which are generally acknowledged to be created (or tacitly approved by) various nation-states around the globe.

While it seems ludicrous that an anti-malware company might be fettered by the intelligence apparatus of the country in which it is headquartered, even if you were not to rule that out of hand, there are anti-malware companies located in countries around the world that are mutually antagonistic towards each other, and I could see a Chinese or a Russian anti-malware company treating malware created by an American or European government as a PR goldmine. The truth of the matter, though, is that governments are going to be pretty unlikely to inform anti-malware companies of malware they have developed or are using, since that violates the whole point of using malware in the first place: Plausible deniability.

Regards,

Aryeh Goretsky

"about these security flaws will be governments and incredibly sophisticated hackers"

So you think a virus scanner you got from mcafee or nod or whatever is going to protect against a government backed attack?

So as I was saying, generally speaking guest-host escapes is not something the general user base - say running some vms on my home lab box for example needs to be worried about protecting against. Other than making sure your VM software be it type1 or 2 is updated, and host os are patched and securely configured.

And in this context you could be pretty sure that this form of exploit is not going to be used when you download that keygen or hacked exe of some game or application or surf the dark underbelly of the net. What you should be concerned with is more that you can roll the vm back after you play with something like that. Or that the box does not become infected with the lastest worm that could infect your other vms/local network.

I think we are the same page yes?

This topic is now closed to further replies.
  • Posts

    • The quantum search for Time's origin had an equally mind-boggling conclusion by Sayan Sen Image by Steve Johnson via Pexels A theoretical study from researchers at the University of Surrey suggested that the direction of time may not be fundamentally fixed in certain quantum systems. The work, published in Scientific Reports, examined how the “arrow of time” could emerge from microscopic physics and found that time-reversal symmetry can remain intact even in models used to describe processes such as energy loss and thermalisation. The arrow of time refers to the observed one-way direction from past to future in everyday life. In macroscopic processes, this is easy to see. Spilled milk spreads across a table and does not gather back into a glass, and heat flows from hotter objects to colder ones. These processes shape the common sense idea that time moves in a single direction. However, at the level of fundamental physics, many equations do not prefer a direction of time. Time-reversal symmetry means that the same physical laws can describe a system whether time moves forward or backward. This has made it difficult to explain why irreversible behaviour appears in the large-scale world even when the underlying rules do not require it. Dr Andrea Rocco, Associate Professor in Physics and Mathematical Biology at the University of Surrey, described this contrast: "One way to explain this is when you look at a process like spilt milk spreading across a table, it's clear that time is moving forward. But if you were to play that in reverse, like a movie, you'd immediately know something was wrong – it would be hard to believe milk could just gather back into a glass. However, there are processes, such as the motion of a pendulum, that look just as believable in reverse. The puzzle is that, at the most fundamental level, the laws of physics resemble the pendulum; they do not account for irreversible processes. Our findings suggest that while our common experience tells us that time only moves one way, we are just unaware that the opposite direction would have been equally possible." The study focused on open quantum systems, which are quantum systems that interact with a surrounding environment. This environment, often described as a heat bath, can exchange energy and information with the system. The researchers used this framework to study how a direction of time might appear even when the underlying physics does not enforce one. A key part of the analysis involved the Markov approximation. This is a simplification used in many models where the system is assumed not to retain memory of its past states. The idea is that changes depend only on the current state, not on earlier history. This is commonly used when studying thermalisation, which is the process where a system settles into equilibrium with its environment. The study also used concepts such as master equations, including the Lindblad and Pauli equations, which describe how probabilities of different quantum states change over time. Another related model discussed was quantum Brownian motion, which describes the random-like movement of a quantum particle interacting continuously with its environment. In these descriptions, a “memory kernel” can appear, which is a mathematical term that accounts for how past states influence current behaviour. The researchers found that applying the Markov approximation did not break time-reversal symmetry. Even when the system interacted with an effectively infinite heat bath, the resulting equations of motion remained symmetric in time. This meant that the same mathematical description could, in principle, run forward or backward in time without contradiction. The study further showed that standard frameworks used in open quantum systems, including quantum Brownian motion and master equations like the Lindblad and Pauli forms, could be written in a time-symmetric way. These equations are typically used to describe processes that look irreversible, such as dissipation and thermalisation, but the results suggested they can also be interpreted as allowing evolution in both time directions. Thomas Guff, Research Fellow in Quantum Thermodynamics, said: "The surprising part of this project was that even after making the standard simplifying assumption to our equations describing open quantum systems, the equations still behaved the same way whether the system was moving forwards or backwards in time. When we carefully worked through the maths, we found that this behaviour had to be the case because a key part of the equation, the "memory kernel," is symmetrical in time. We also found a small but important detail which is usually overlooked – a time discontinuous factor emerged that kept the time-symmetry property intact. It’s unusual to see such a mathematical mechanism in a physics equation because it's not continuous, and it was very surprising to see it appear so naturally." The researchers also noted that deriving a one-way arrow of time from time-reversal symmetric microscopic dynamics remains an open problem across fields such as thermodynamics, statistical mechanics, particle physics, and cosmology. Their results suggested that some standard descriptions of irreversible behaviour in open quantum systems may be better understood using a time-symmetric formulation of Markovianity. According to the study, processes such as thermalisation, which are usually treated as irreversible, could in theory be described in a way that allows evolution in either time direction under the same rules. This does not imply that time reversal occurs in everyday life, but rather that the underlying equations do not strictly enforce a single direction. Overall, the findings suggested that the perceived direction of time may emerge from how physical systems are modelled and approximated, rather than from a fundamental asymmetry in the laws themselves. The researchers noted that this perspective could have implications for ongoing work in quantum mechanics, thermodynamics, and cosmology on the origin of time’s arrow. Source: University of Surrey, Nature This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing
    • A bit premature... 100% Marketing. Bizarre.
    • A $300 price hike is insane! No one is going to want to pay that much!
    • Since the 1st one flopped, there is really no reason to make another one. It's just losing money left and right.
  • Recent Achievements

    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      581
    2. 2
      +Edouard
      182
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      73
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!