<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Storage Time Bomb?</title>
	<atom:link href="http://blog.scottlowe.org/2007/02/21/storage-time-bomb/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2007/02/21/storage-time-bomb/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<lastBuildDate>Tue, 07 Feb 2012 13:34:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2007/02/21/storage-time-bomb/comment-page-1/#comment-30171</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Sat, 03 Mar 2007 14:49:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=417#comment-30171</guid>
		<description>J.Cruz,

I suppose that is a possibility, but even then you have a VMDK involved, and that VMDK is associated with a LUN ID (the VMDK in this case just stores metadata, not real data).  If that is the case, you don&#039;t even need a DRS/HA cluster to be vulnerable--remember that simple VMotion requires access to the back-end SAN LUN as well.

I&#039;ll have to dig into RDMs a bit more to see if you could be right.  Any RDM experts want to chime in here?</description>
		<content:encoded><![CDATA[<p>J.Cruz,</p>
<p>I suppose that is a possibility, but even then you have a VMDK involved, and that VMDK is associated with a LUN ID (the VMDK in this case just stores metadata, not real data).  If that is the case, you don&#8217;t even need a DRS/HA cluster to be vulnerable&#8211;remember that simple VMotion requires access to the back-end SAN LUN as well.</p>
<p>I&#8217;ll have to dig into RDMs a bit more to see if you could be right.  Any RDM experts want to chime in here?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J.Cruz</title>
		<link>http://blog.scottlowe.org/2007/02/21/storage-time-bomb/comment-page-1/#comment-29864</link>
		<dc:creator>J.Cruz</dc:creator>
		<pubDate>Fri, 02 Mar 2007 14:45:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=417#comment-29864</guid>
		<description>Hey, Scott.  The only thing I can think of is that they are referring to Raw Device Mappings, which bypasses the virtualization layer.  Is it possible to another host inyour ESX Farm that shares the same LUN mappings as the one that hosts your VM-with-RDM, to be compromised, and another VM-with-RDM brought online with those same RDMs and then, bam, you&#039;ve got access to the SAN LUNs you shouldn&#039;t have?</description>
		<content:encoded><![CDATA[<p>Hey, Scott.  The only thing I can think of is that they are referring to Raw Device Mappings, which bypasses the virtualization layer.  Is it possible to another host inyour ESX Farm that shares the same LUN mappings as the one that hosts your VM-with-RDM, to be compromised, and another VM-with-RDM brought online with those same RDMs and then, bam, you&#8217;ve got access to the SAN LUNs you shouldn&#8217;t have?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J.Cruz</title>
		<link>http://blog.scottlowe.org/2007/02/21/storage-time-bomb/comment-page-1/#comment-29862</link>
		<dc:creator>J.Cruz</dc:creator>
		<pubDate>Fri, 02 Mar 2007 14:43:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=417#comment-29862</guid>
		<description>The only thing I can think of is that they are specifically referring to Raw Device Mappings in VMWare.  But then, you&#039;re bypassing the virtualization layer, right?  Which means you are conciously choosing to break out of that layer and grant raw access to the LUN?

I suppose if a host in your HA Cluster was compromised, which would necessarily have to see the same LUNs as the RDM VM, is it possible that a VM could be brought online with access to those LUNs?</description>
		<content:encoded><![CDATA[<p>The only thing I can think of is that they are specifically referring to Raw Device Mappings in VMWare.  But then, you&#8217;re bypassing the virtualization layer, right?  Which means you are conciously choosing to break out of that layer and grant raw access to the LUN?</p>
<p>I suppose if a host in your HA Cluster was compromised, which would necessarily have to see the same LUNs as the RDM VM, is it possible that a VM could be brought online with access to those LUNs?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

