Mostrando entradas con la etiqueta AppVMs. Mostrar todas las entradas
Mostrando entradas con la etiqueta AppVMs. Mostrar todas las entradas

VENOM (CVE-2015-3456) is (Virtualized Eniroment Negleted Operations Manipulation), lo que viene a decir, que se ha descubierto una vulnerabilidad que permite acceder por completo al entorno de ejecución del hipervisor desde una máquina virtual cualquiera, lo que significa acceder por completo al entorno de ejecución del resto de máquina virtuales que tiene el Host en ejecución.


Xen Security Advisory CVE-2015-3456 / XSA-133
version 2
Privilege escalation via emulated floppy disk drive


A continuación un ejemplo gráfico que ilustrará en que consiste la vulnerabilidad, y ayudará para evaluar el nivel de riesgo que tiene tu organización, si estas afectado por VENOM:

Crowdstrike - VENOM vulnerability

This vulnerability may allow an attacker to escape from the confines of an affected virtual machine (VM) guest and potentially obtain code-execution access to the host.

Pero ¿Qué sistema de virtualización se encuentra afectado por dicha vulnerabilidad?

The bug is in QEMU’s virtual Floppy Disk Controller (FDC). This vulnerable FDC code is used in numerous virtualization platforms and appliances, notably Xen, KVM, and the native QEMU client.

Sabemos por tanto que no todas VM se encuentran en riesgo, sino aquellas que están "running" en sistema virtuales basado en XEN, KVM y QEMU.

Las máquinas virtuales sobre VMware, Microsoft Hyper-V y  Bochs  no se encuentran afectadas por esta vulnerabilidad.

UPDATE: Si trabajas con KVM, QEMU y XEN Hypervisor, consulta las novedades en parches y actualizaciones de seguridad, aquí os dejo una muestra:

CrowdStrike is aware of the following vendor patches, advisories, and notifications.
We recommend you reach out to your vendors directly to get the latest security updates.
¿Qué pasa con QubesOS?

Hasta que no salga la versión 3.0 ésta se encuentra desarrollada sobre un hypervisor XEN, por lo que consulta la página oficial para conocer si esta disponible el parche.

Referencia: http://venom.crowdstrike.com/ | http://xenbits.xen.org/xsa/advisory-133.html
#ST2Labs - www.st2labs.com

Desde hace tiempo llevo haciendo un seguimiento a este proyecto de la gente de InvisibleThings Labs, capitaneados por .

QubesOS era en principio un sistema operativo (ver más sobre lo qué es Qubes aquí) diseñado para ser seguro desde su diseño, utilizando la virtualización como una herramienta para proporcionar "seguridad" en la capa más alta, las aplicaciones - Apps -, así cada uno podría crear espacios virtuales aislados los unos de los otros para evitar que las acciones o eventos sucedidos en uno afectará a los otros, por ejemplo que la navegación por Internet pudiera significar una amenaza o riesgo para el usuario.

Con la versión R2 RC1 llegan importantes mejoras en la parte gráfica, donde la plantilla por defecto para la interfaz gráfica ha sido actualizada a Fedora 20, y además se han solucionado numerosos fallos de la versión anterior. Además ya soporta virtualización de aplicaciones windows en pantalla completa, una de las características más esperadas en QubesOS.

Download
http://sourceforge.net/projects/qubesos/files/Qubes-R2-rc1-x86_64-DVD.iso/download
http://wiki.qubes-os.org/trac/wiki/QubesDownloads

Instalación de QubesOS R2 RC1
http://wiki.qubes-os.org/trac/wiki/InstallationGuideR2rc1

#ST2Labs
www.st2labs.com

No es la primera vez que hablo sobre Qubes en el blog (aquí y aquí), es un proyecto muy interesante que intento seguir de cerca. En esta ocasión voy a contaros que es lo que están preparando la gente de InvisibleThings Labs, capitaneados por .

En marzo, Joanna escribió un artículo muy interesante en su blog, donde explica que era Qubes y qué no es Qubes, y hacia donde se dirige, es decir, en que se ha convertido.

¿Qué es Qubes?

Para empezar Qubes no es una distribución de Linux, solo lo parece debido a que utiliza Fedora 18 como plantilla base para establecer el entorno de ventanas (interfaz de usuario) de control y/o dominio principal. Tampoco es un hypervisor, al uso, basado en XEN, este solo se utiliza para garantizar el aislamiento de las aplicaciones durante su ejecución, creado contenedores aislados seguros mediante la tecnología de  virtualización de XEN.

Bien, entonces ¿Qué es Qubes?

  • Una forma sencilla de como se puede configurar de forma segura y usar virtualización para trabajar con entornos (dominios) seguros de trabajo y minimizar al máximo los riesgos.

  • Proporciona un interfaz de usuario (insolated) segura, mientras se ejecutan al mismo tiempo múltiples aplicaciones en diferentes entornos virtualizados todos juntos y manejados bajo el dominio principal y/o de escritorio.

  • Garantiza el intercambio de información entre dominios (entornos virtuales (AppsVM)) de forma segura con una gestión centralizada de las políticas, como por ejemplo el intercambio de ficheros.

  •  Incluye un modulo para crear servicios adicionales (addons / plugins) que amplian las funcionalidades y características de framework. Por ejemplo, TorVM, Split GPG, o conversor seguro de documentos PDF, etc.

  • Posibilidad de manejar múltiples sistemas operativos ejecutándose en diferentes entornos seguros y aislados, según las necesidades de cada uno.
Esto es solo el principio, según palabras de la propia Joanna, Qubes se ha transformado en un framework que pretender revolucionar la forma de entender la gestión de los sistemas operativos y/o aplicaciones.

La próxima versión de Qubes (v3) dará paso a Qubes Odyssey Framework, donde se introducirá un nuevo concepto que permitirá abstraer la capa que proporciona la seguridad de los entornos en ejecución, es decir, el hypervisor, lo que se le conoce como Qubes HAL: Hypervisor Abstraction Layer.

Pero de ello (Qubes HAL) os hablaré en otro artículo.

Un Saludo.
Introducción

Hace un tiempo escribí un artículo donde os presentaba el proyecto Qubes-OS, un sistema operativo seguro, donde cada aplicación/sistema se ejecuta en un entorno virtualizado totalmente independiente del resto del sistema, es lo que los propios desarrolladores bautizaron con las siglas NOSG (Next OS Generation), o lo que es lo mismo, la próxima generación de Sistemas Operativos.

[Qubes-OS] Tres dominios independientes entre si ejecutándose al mismo tiempo.

Desde el lanzamiento de la segunda versión del mismo, la novedad más interesante fue la posibilidad de ejecutar máquinas virtuales Windows, por lo que ya no hay excusas para no darle una oportunidad a este fantástico sistema.

[Qubes-OS R2b2] Running Windows 7 in a Virtual Secure Domain.
Con Qubes-OS puedes crear diferentes escritorios, o más bien dominios, cada dominio esta totalmente aislado de los otros, incluso a nivel de red, esto ultimo siempre que se cumplan algunos de los requisitos en el hardware,como por ejemplo, disponer de la tecnología de virtualización Intel-VT-d o AMD IOMMU (ejemplos: Cores i5, i7).

Novedades: Qubes-OS R2b2

Las principales novedades de la versión R2 Beta 2 que hace una semana fue lanzada, es la incorporación de:

  • Nueva compatibilidad para los últimos hardware gráficos (GPU drivers).
  • Se ha incluido la capacidad de elegir la interfaz gráfica KDE4 (4.9) o Xcfe 4.10.
  • Nuevas funcionalidad como por ejemplo, convertir potenciales PDF peligrosos en PDF seguros.
La nueva funcionalidad es muy interesante, voy a poner un ejemplo para introducir y explicar la nueva capacidad.

Imaginemos que estamos utilizando un "dominio Internet", normalmente este dominio, será peligroso, es decir, tenemos el dominio de Internet activado con Firefox o Chrome, y lo usamos para poder navegar libremente por Internet sin preocuparnos las páginas que visitamos, porque si llegase a comprometerse con una vulnerabilidad (ej: JAVA), esta quedaría aislada a ese entorno (dominio / sandbox) y cuando finalizaramos la sesión, desaparecería cualquier #malware que hubiera podido ejecutarse.

Pero digamos, que durante nuestra navegación por Internet, descargamos varios PDFs que necesitamos para nuestro trabajo, ¿cómo sabemos que esta seguros? o mejor aún, ¿sería posible pasar dichos documentos a un entorno seguro de trabajo sin correr riesgo alguno? La respuesta es SI, en esta versión se ha incluido la capacidad de convertir PDF no "confiables" a PDF seguros.

[Qubes-OS PDF Converter] | MECANISMO

El mecanismo es extremadamente sencillo, cuando se abre un fichero del tipo PDF, DOC, etc este se procesará dentro de un entorno VM independiente, es decir, se ejecutará dentro de un entorno seguro y controlado, similar a un sandbox, el tiempo aproximado de espera es de 5 segundos. Una penalización muy pequeña comparado con el peligro de convertir nuestro equipo en un "zombie" miembro de una botnet, o exponer nuestros datos a cualquier "atacante". ¿No creéis que 5 segundo de retardo en la apertura del documento bien lo merecen, si estamos seguros?

[Qubes-OS] Convertir PDF "inseguros/peligrosos" a PDF seguros

Download



Más Información
Qubes-OS Website
The Invisible Things Lab's blog | Qubes 2 Beta 2 has been released!

The last January, I was wrote about Qubes-OS in two post (The Next Security OS Generation and Creating a WiFi pen-testing VM). Now I have just been released the beta3 version of this.

Beta 3 fixes lots of annoying problems discovered in Beta 2 and earlier releases, and also implements a bunch of useful feature.






There are some new tools, one of this, is qvm-block, it has been introduced that makes mounting USB devices to any user AppVM very easy, no matter which actual VM is handling the USB controller


So, this allows to have untrusted USB domain(s), almost seamlessly integrated in the desktop system. One can consider to use it in order to preventvarious USB attacks. The next release (the 1.0) will bring this feature to the Qubes GUI manager as well, making it easy to use for non-command-line users too.
Furthermore, now you can do the deployment your "own Qubes-OS distro" more easily, with the new capability implemented in beta 3:

... have now introduced fully automatic Qubes build system, that allows to build all the Qubes packages, and also create the installation ISO, with just one command. More information on this system and on how to use it can be found in the ...ç
Installation and Downloading, all you need to know will find in the "Installation Guide". Or if you prefer, you can download the new ISO now.

The ISO and the digital signature for the ISO from here:


Via | Jorge Sanz and The Invisible Things Labs
Today I'm gonna write about Qubes-OS, the amazing project that provide you a Strong Security Desktop (SSD). I'm wishing to try it out. 

This project can become in the Next Generation Security OS. Sincerely I will bet for that.


What is Qube?

Qubes is an open source operating system designed to provide strong security for desktop computing. Qubes is based on Xen, X Window System, and Linux, and can run most Linux applications and utilize most of the Linux drivers. In the future it might also run Windows apps.

Architecture

Qubes implements Security by Isolation approach. To do this, Qubes utilizes virtualization technology, to be able to isolate various programs from each other, and even sandbox many system-level components, like networking or storage subsystem, so that their compromise don’t affect the integrity of the rest of the system.

Qubes lets the user define many security domains implemented as lightweight Virtual Machines (VMs), or “AppVMs”. E.g. user can have “personal”, “work”, “shopping”, “bank”, and “random” AppVMs and can use the applications from within those VMs just like if they were executing on the local machine, but at the same time they are well isolated from each other. Qubes supports secure copy-and-paste and file sharing between the AppVMs, of cours

Who doesn't want to try it out now?? I wanna try it out... so Where can I obtain it?

Screenshots: Amazing
In this example, the word processor runs in the “work” domain, which has been assigned “green” label, and is fully isolated from other domains, such as the “red” domain (assigned the “red” label -- “Watch out!”, “Danger!”) used for random Web browsing, news reading, etc. Apps from different domains run in different AppVMs and have different X servers, filesystems, etc. Notice the different color frames (labels), and VM names in the titlebar -- these are drawn by the trusted Window Manager running in Dom0 and apps running in domains cannot fake them.


Different Security AppVMs Domains.

This feature is one of my favorites:
All the networking runs in a special, unprivileged NetVM (notice the red frame around the NetworkManager dialog box on the screen bellow). Thanks to this, a potential compromise of your network card driver, or WiFi stack, or DHCP client, would not affect the integrity of the rest of the system! This feature requires Intel VT-d or AMD IOMMU hardware (e.g. Core i5/i7 systems)
Network Managed in Insolation NetVM.

Downloading


The most important documentation about the project is store and share it in the following wiki system:  http://wiki.qubes-os.org/trac

The Installation guide provide all you need to know for install and prepare your equipment before start the configuration process.

You can download the ISO and the digital signature for the ISO from here:
See this page for more info about how to download and verify our GPG keys. Then, verify the downloaded ISO:
gpg -v <iso>.asc
It's so important to know the System requeriments:

Minimum:
  • 4GB of RAM
  • 64-bit Intel or AMD processor (x86_64 aka x64 aka AMD64)
  • Intel GPU strongly preferred (if you have Nvidia GPU, prepare for some troubleshooting; we haven't tested ATI hardware)
  • 10GB of disk (Note that it is possible to install Qubes on an external USB disk, so that you can try it without sacrificing your current system. Mind, however, that USB disks are usually SLOW!)
  • Fat SSD disk strongly recommended
Additional requirements:
  • Intel VT-d or AMD IOMMU technology (this is needed for effective isolation of your network VMs)
----

How Can I install Qube-OS in an USB Stick? The response to this cuestion can be find out in the following guide.

This is all! Do you like this OS? I suppose that is yes! ...