[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xense-devel] xenwatch and xenswitch processes



I have the following question. I've used xen what i see in a DomU is the
xenswitch and xenwatch processes. When i have users on a system or a
firewall on DomU is hacked they know it's running on xen. Is there a way
to not show/hide these processes?

While you might be able to hide the processes (e.g., using a rootkit), I think that there's a larger issue here. It sounds like you're goal is to completely hide the fact that a machine is running in a domU. And, for better or worse, this is very hard to do.

Consider, for example, Red Pill. This small program can detect when it's running in a virtualized environment:

http://invisiblethings.org/papers/redpill.html

Cheers,
bryan


-
Bryan D. Payne
Graduate Student, Computer Science
Georgia Tech Information Security Center
http://www.bryanpayne.org



Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Xense-devel mailing list
Xense-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xense-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.