Virtualization has turned the IT world upside down. It is used everywhere these days from desktops to servers and datacenters to the “cloud”. It’s also presented itself as a double-edged sword to security professionals.
On one hand, it makes building a lab and testing things easier; on the other, it’s letting sysadmins deploy many servers of varying security silos on one hardware platform exposing a secure server to more risk. While it’s easy to go on and on about the security issues surrounding virtualization, I’d rather focus on something more positive that I’m working on right now–custom virtual machines for penetration testing.
I’ve extolled the virtues of using virtual machines for creating test labs in the past. It makes it easy to have different operating systems with snapshots at differing patch levels to test exploits out to make sure they work as expected. If the virtual machine… Read the rest
Read More...
