WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

RE: [Xen-users] xen in hosting envoroment

To: "Azrul Rahim" <write2me@xxxxxxxxx>, <xen-users@xxxxxxxxxxxxxxxxxxx>
Subject: RE: [Xen-users] xen in hosting envoroment
From: "James Harper" <james.harper@xxxxxxxxxxxxxxxx>
Date: Sun, 3 Feb 2008 22:46:44 +1100
Delivery-date: Sun, 03 Feb 2008 03:47:29 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <5c7a514e0802030141m334e2e4g6a00dc35862184a3@xxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <5c7a514e0802030141m334e2e4g6a00dc35862184a3@xxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AchmSTHHvZHzJL4/Ta2DoHnJJoq8ngADtlpA
Thread-topic: [Xen-users] xen in hosting envoroment
> Hi,
> 
> I am planning to offer a hosted xen server within my locality. My
> question is, is there any security issue that I should be aware of. I
> am currently letting user to choose which kernel they want to boot.
> 
> Is there any possibility, that with, say a recompiled kernel or kernel
> module, a user can actually gain access to the Dom0?

I've been developing Xen drivers for Windows, and I can tell you first
hand that it is definitely possible to crash at least some versions of
Xen by doing things wrong on a DomU. I'm talking about causing the
machine to hang or to reboot.

Even now, with the PV drivers working nicely, when I bring up the PV
network driver it will often kill all the tcp connections I have to
Dom0. I can re-establish them almost immediately, but there's still the
potential for a DomU to cause trouble. I'm not sure what the cause of
this is, possibly just a problem of having the same MAC address in two
locations causing the bridge to hiccup.

James

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>