Showing posts with label vulnerability. Show all posts
Showing posts with label vulnerability. Show all posts

Wednesday, August 15, 2018

Hyperthreading Mitigation Security Warnings

13 hours ago VMware issued critical security patches for VMware vCenter, ESXi, Fusion and Workstation products as part of advisory VMSA-2018-0020 to fix the new CPU vulnerabilities Intel disclosed as well.

After applying the patches (Aug 14, 2018), a warning message showed on patched ESXi hosts: esx.problem.hyperthreading.unmitigated

host summary showing hyperthreading unmitigated error

According to the release notes, VMware introduced a new Advanced Configuration on the hosts to mitigate the new hyperthreading attacks, however, it states there's a performance hit that cannot be ignored.

After applying the patches, you have to manually enable the Hyperthreading mitigation setting in the advanced functions to enable the security fix, otherwise the exclamation mark on the host and the warning above will persist. It's set to manual modification due to the performance impact.

hyperthreading mitigation advanced setting

Change the value of "VMKernel.Boot.hyperthreadingMitigation" to true, then reboot the host for changes to take effect.

Update 1: Aug 15, 2018 - 14:29 UTC+3

After enabling hyperthreading mitigation, some virtual machines that were running HTTPS/443 services weren't accessible anymore. The VM is accessible, but not services on port 443 TCP. After undoing the configuration and rebooting the host, the services functioned again.

Approach this setting and the security vulnerability with caution and do proper testing for every service you have deployed.

Wednesday, August 5, 2009

trixbox security concerns

WARNING: I want to alert everyone to NOT use trixbox due to security concerns.

I've been told by some guys in asterisk-related IRC channels that trixbox has known security problems and is not fixing them.

A quick search turns many results.

Security concerns include (but not limited to):
- Known security risks in their web-GUI and other packages but remain unpatched
- trixbox sends private information to its company without prior consent of users
- trixbox had history of installing scripts on the systems without prior notice of users

There are alternatives and I will document the installation process of one of them in a later post.

Alternatives are: AsteriskNow and PBX in a Flash.