a popular libvirt-based VPS panel does not bother to run customer workloads under separate UIDs. oh dear.
a popular libvirt-based VPS panel does not bother to run customer workloads under separate UIDs. oh dear. 5 comments
@ariadne@treehouse.systems yes, this is terrible. The best approach (even if it can be effective only if the exploit is in the user part, not the kernel part) is the one I generally use in FreeBSD: putting every different client's VM inside a jail.
|
this is bad, really bad. it is bad because an attacker can exploit qemu, and then break into a user account which has direct access to other customers' data.