VMware Hacking
Overview
A critical and often overlooked aspect of migrating to a virtualized environment is security and setting up security properly. Like physical machines, virtualization technologies are not secure “out of the box” and VMware is no exception. The Advanced Virtualization Security course focuses on “where the vulnerabilities lie” and how to reduce the attack surfaces in the virtualized environment. It goes beyond the typical security protocols administrators use to secure their environments and delves much deeper into the actual working (and short comings) of the VMware environment. Students will take a 360 degree look at the potential threats, how to defend and defeat them, and establish a solid foundation to build secure virtual data centers from the ground up.
Course Objectives
- Learn the actual internal workings of VMware, and compare them to physical and virtual devices. - Discover how to securely set up port groups and VLANS. - Understand the aspect of securing failover configurations - Distinguish between Denial of Service Failovers that wide open failovers and closed failovers. - Dive deep into the different layers of security and explore features to include how traffic routes between VM’s and different hosts, common denominators of Physical and Virtual Environments, and how to make the virtual environment the most secure. - Walk away knowing how to secure a VMware environment in a DMZ and how to protect yourself from the common vulnerabilities of VMware attack surfaces from the eyes of an attacker. - Receive in depth information on how to harden you ESX environment, and comprehensively understand all aspects of how to do that. - Demonstrate their proficiency in class working on a state-of-the-art data center and performing hands-on labs to reinforce the learning objectives.
Who Should Attend
System Administrators and Security Administrators using virtualization software.
Prerequisites
VMware 3.5 IC certification or equivalent. In lieu of hands-on classroom training, an in-depth knowledge of VMware’s ESX virtualization environment is required.
Course Length
5 Days
Course developed and taught by a Licensed Penetration Tester who has a long history of vulnerability audits with US National Security Teams and audits of many foreign governments.
Designed and taught from the perspective of how an attacker would get into your Virtual Environment from an attacker who has done JUST THAT!
|