LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-09-2006, 06:21 PM   #1
Peufelon
Member
 
Registered: Jul 2005
Posts: 164
Blog Entries: 1

Rep: Reputation: Disabled
Any grave security issues with Xen?


Hi all,

I am thinking of installing SUSE 10.0 and MEPIS 3.4-2 under Xen on a desktop home machine which would be connected (off and on) via dial-up. I did search past threads and didn't turn up anything, but I just thought I'd ask if anyone has heard of any grave security issues with Xen which might make me reconsider my plan.

My interest in Xen is two-fold, incidentally:
1. allegedly it can run two distros at once, so I can get the best of the debian and redhat/suse worlds (I mostly install packages the apt and rpm way)
2. improve security by running certain services on a virtual machine (probably not a huge issue on the typical desktop; however, I am considering offering some services such as Mediawiki).
 
Old 04-10-2006, 09:05 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,417
Blog Entries: 55

Rep: Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627
Any grave security issues with Xen?
Did some digging around but couldn't come up with any "grave security issues" in Xen-current.
Not to spread FUD, but that is not to say there might not be any. As always: secure and harden,
and check the Security Considerations from the Xen User Guide with respect to treating dom0.
 
Old 04-10-2006, 09:51 PM   #3
Peufelon
Member
 
Registered: Jul 2005
Posts: 164

Original Poster
Blog Entries: 1

Rep: Reputation: Disabled
Thanks, unSpawn! I think I found the user guide you mean at http://www.linuxtopia.org/online_boo...ide/index.html, and this looks to be very helpful!

Thanks to http://foldoc.org/ for telling me the meaning of FUD, heh :-/
 
Old 04-11-2006, 07:19 AM   #4
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
For general xen info, this might interest you:
http://www.debian-administration.org/?search=xen&go=Go
http://www.steve.org.uk/Software/xen-tools/

I haven't found reference to security problem on xen. But version 3.0 is very new (beginning of this year).
It should be integrated soon in future Linux kernel, I'm impatient for this.

Here you can find someone using xen as a honeypot (sorry for .ppt format..) :
https://www.eusecwest.com/slides06/esw06-nguyen.ppt
At the end he gives few remarks about hardening DomU and Dom0.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
accent grave ague in kde suse 10!! how??? Randall Slack SUSE / openSUSE 6 01-19-2006 12:47 PM
grave locale problems with mandriva 10.2 exa Mandriva 1 10-04-2005 01:37 PM
Security Issues? Xon Linux - Security 3 10-04-2004 11:45 PM
security issues with a RH 9.2 merlin Linux - Security 1 02-24-2004 04:13 PM
security issues with compilers? complus Linux - Security 2 09-11-2003 12:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration