[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xense-devel] xenwatch and xenswitch processes



I have the following question. I've used xen what i see in a DomU is the
xenswitch and xenwatch processes. When i have users on a system or a
firewall on DomU is hacked they know it's running on xen. Is there a way
to not show/hide these processes?
While you might be able to hide the processes (e.g., using a  
rootkit), I think that there's a larger issue here.  It sounds like  
you're goal is to completely hide the fact that a machine is running  
in a domU.  And, for better or worse, this is very hard to do.
Consider, for example, Red Pill.  This small program can detect when  
it's running in a virtualized environment:
http://invisiblethings.org/papers/redpill.html

Cheers,
bryan


-
Bryan D. Payne
Graduate Student, Computer Science
Georgia Tech Information Security Center
http://www.bryanpayne.org



Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Xense-devel mailing list
Xense-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xense-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.