public inbox for kvm@vger.kernel.org
 help / color / mirror / Atom feed
* Bug - IP Address
@ 2014-04-19  9:41 Ivan Stojcevic (Tronyx)
  2014-04-22 13:25 ` Stefan Hajnoczi
  0 siblings, 1 reply; 2+ messages in thread
From: Ivan Stojcevic (Tronyx) @ 2014-04-19  9:41 UTC (permalink / raw)
  To: kvm

 
Hello,
 
I just found a very sensitive bug in KVM and Xen platforms. Easily if you have VPS hosted on Xen or KVM you can assign yourself a IPv4 address for free and bypass regular system with billing.
I tried this on many VPS hosting companies and it work on all. If you would like to talk with me about this, you can get me on skype: ivans2901
 
Regards,

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Bug - IP Address
  2014-04-19  9:41 Bug - IP Address Ivan Stojcevic (Tronyx)
@ 2014-04-22 13:25 ` Stefan Hajnoczi
  0 siblings, 0 replies; 2+ messages in thread
From: Stefan Hajnoczi @ 2014-04-22 13:25 UTC (permalink / raw)
  To: Ivan Stojcevic (Tronyx); +Cc: kvm

On Sat, Apr 19, 2014 at 11:41:33AM +0200, Ivan Stojcevic (Tronyx) wrote:
> I just found a very sensitive bug in KVM and Xen platforms. Easily if you have VPS hosted on Xen or KVM you can assign yourself a IPv4 address for free and bypass regular system with billing.
> I tried this on many VPS hosting companies and it work on all. If you would like to talk with me about this, you can get me on skype: ivans2901

This doesn't sound like a bug in Xen or KVM.  Rather it's an issue with
the VPS providers you tested.  They should lock down their network
appropriately (i.e. only allow MACs and IPs assigned to the guest).

Similar issues can also happen with dedicated servers if the provider
has not configured their routers correctly.

Please get in touch with the VPS providers or post more details here if
you think the issue lies in QEMU/KVM.

Stefan

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2014-04-22 13:25 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-04-19  9:41 Bug - IP Address Ivan Stojcevic (Tronyx)
2014-04-22 13:25 ` Stefan Hajnoczi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox