05.06.2013 Views

CiscoInTheSkyWithDiamonds

CiscoInTheSkyWithDiamonds

CiscoInTheSkyWithDiamonds

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

VEMs register themselves with the VSM<br />

based on an ESXi host specific ID<br />

Uses the “Hardware UUID”<br />

Bad choice: VMware assigns this ID and<br />

apparently it’s not considered a secret<br />

linux# slptool findattrs service:VMwareInfrastructure://esxi5.foo.tld<br />

(product="VMware ESXi 5.0.0 build-702118"),(hardwareUuid="F49979D6-C5B3-<br />

C161-FC96-001999853110")<br />

Sending heartbeat messages with this<br />

UUID assigns the VEM to the attacker

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!