* Bug - IP Address
@ 2014-04-19 9:41 Ivan Stojcevic (Tronyx)
2014-04-22 13:25 ` Stefan Hajnoczi
0 siblings, 1 reply; 2+ messages in thread
From: Ivan Stojcevic (Tronyx) @ 2014-04-19 9:41 UTC (permalink / raw)
To: kvm
Hello,
I just found a very sensitive bug in KVM and Xen platforms. Easily if you have VPS hosted on Xen or KVM you can assign yourself a IPv4 address for free and bypass regular system with billing.
I tried this on many VPS hosting companies and it work on all. If you would like to talk with me about this, you can get me on skype: ivans2901
Regards,
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: Bug - IP Address
2014-04-19 9:41 Bug - IP Address Ivan Stojcevic (Tronyx)
@ 2014-04-22 13:25 ` Stefan Hajnoczi
0 siblings, 0 replies; 2+ messages in thread
From: Stefan Hajnoczi @ 2014-04-22 13:25 UTC (permalink / raw)
To: Ivan Stojcevic (Tronyx); +Cc: kvm
On Sat, Apr 19, 2014 at 11:41:33AM +0200, Ivan Stojcevic (Tronyx) wrote:
> I just found a very sensitive bug in KVM and Xen platforms. Easily if you have VPS hosted on Xen or KVM you can assign yourself a IPv4 address for free and bypass regular system with billing.
> I tried this on many VPS hosting companies and it work on all. If you would like to talk with me about this, you can get me on skype: ivans2901
This doesn't sound like a bug in Xen or KVM. Rather it's an issue with
the VPS providers you tested. They should lock down their network
appropriately (i.e. only allow MACs and IPs assigned to the guest).
Similar issues can also happen with dedicated servers if the provider
has not configured their routers correctly.
Please get in touch with the VPS providers or post more details here if
you think the issue lies in QEMU/KVM.
Stefan
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2014-04-22 13:25 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-04-19 9:41 Bug - IP Address Ivan Stojcevic (Tronyx)
2014-04-22 13:25 ` Stefan Hajnoczi
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox