Subverting Xen Hypervisor – Is Amazon EC2 really safe?

Well, folks at Google Cloud Group are discussing the Xen Hypervisor vulnerability and exploitpresented Part 1, Part 2, Part 3 at Black Hat conference in Vegas. Amazon EC2 infrastructure uses Xen at the backend for providing virtual instances. So is EC2 vulnerable?

As Cloudscale founder Randy Bias mentions, the dom0 is not accessible outside Amazon, this exploit may not really be a problem, unless of course there is some misconfiguration or somehow dom0 is accessible to someone outside Amazon.

What is Amazon being used for as of today – when we don’t have persistance in an instance – for one – those are compute and processing tasks, typically run on multiple instances and are capable of surviving or resuming after a few instance or node failures. There are others – the web 2.0 folks and they might have issues – if they have a few instances supporting their web 2.0 products and hosted infrastrucutre and this hack causes their instances to go down – they lose business. But then at this stage, chances of this vulnerability getting exploited are about the same as Amazon EC2 or S3 going down due it its own teething problems and I think users are aware of those and prepared for them as well.

About computemeghadoot
Freelance Consultant, Technology Strategist, Software Architect by profession, Computer Engineer by training, 1.5 dozen years in the industry, treaded in mobile computing waters since Windows CE 1.0 days, from 1993 Mac Quadra Motorola 68040 to being 'Parallells'ly enabled on Windows 7 and Mac book Pro Quad core having the power of cloud computing on-fingertips-er-demand, having an inquisitive mind and lot of energy to unearth technological layers to find logical answers that whet my appetite for learning and discovering something new everyday. I am Proud to be an Indian, worked in India and abroad for MNCs, now happily settled in India for over a decade.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.