VMware

This Question is Answered

2 "helpful" answers available (6 pts)
1 Replies Last post: Jul 2, 2009 7:24 AM by Texiwill  

Secure VMTools posted: Jul 2, 2009 6:44 AM

Click to view ISYS2's profile Enthusiast 38 posts since
Nov 26, 2007

Is there a way to prevent users from running malicious scripts via VMTools?

We use VMtools for drivers (obviously) and the Time Sync functionality. What we have discovered though is that a non-admin Windows user can make use of the VMTools Script tab to make scripts run under the System account after a reboot of the VM.

Many thanks

Re: Secure VMTools

1. Jul 2, 2009 7:25 AM in response to: ISYS2
Click to view Texiwill's profile Guru 10,212 posts since
Jan 13, 2004
Hello,

Moved to Security Forum.

This is unfortunate but true. Even if you were to disable VMtools by locking down who can actually run the guest daemon (which is a step you should take), anyone can access the VMware backdoor with a little coding. So your best bet is to use the VMware Hardening Guideline and set the appropriate isolation settings to disable the ability for anyone to use the VMware backdoor maliciously.

The DISA STIG Has a larger list than VMware's Hardening Guideline and my book has one that is larger than that.


Best regards,
Edward L. Haletky VMware Communities User Moderator, VMware vExpert 2009, Virtualization Practice Analyst
Now Available: 'VMware vSphere(TM) and Virtual Infrastructure Security: Securing the Virtual Environment'
Also available 'VMWare ESX Server in the Enterprise'
SearchVMware Pro|Blue Gears|Top Virtualization Security Links|Virtualization Security Round Table Podcast

VMware Developer

SDKs, APIs, Videos, Learn and much more in the Developer community.

Learn More

Developer Sample Code

Increase your developer productivity with VMware API sample code.

Learn More

VMworld Sessions & Labs

Online access to the latest VMworld Sessions & Labs and online services.

Learn more

Purchase PSO Credits Online

Purchase credits to redeem training and consulting services online.

Buy Now

Community Hardware Software

View reported configurations or report your own.

Learn More

VMware vSphere

Come witness the next giant leap in virtualization.

Register Today

Communities