Matthias Luft, Enno Rey, Pascal Turbing and Daniel Mende (ERNW GmbH)
PRESENTATION TITLE: Smashing VMDK Files for Fun and Profit
PRESENTATION ABSTRACT:
A number of cloud service providers allow customers to upload VMDK files.
In order to evaluate input validation mechanisms of cloud service providers, we will dissect the VMDK file format, provide analysis of support file systems, less-known ”features” of the specification as well as potential attack vectors. This information will be used to illustrate why the knowledge about virtualization file formats is crucial for cloud service providers and why the unvalidated upload might not be a good idea.
Participants will learn about potential attack vectors, feasible attacks against certain types of virtualization infrastructures, and similarities to other virtualization file formats.
ABOUT MATTHIAS LUFT
Matthias Luft is a seasoned auditor and pentester with vast experience in corporate environments. Over the years, he developed his own approach in evaluating and reviewing all kinds of applications, technologies, and securtiy concepts. He’s one of the first researchers who revealed major design flaws and vulnerabilities in the approach of Data Leakage Prevention. During the last years, he focused on the area of cloud security and presented both approaches for scalability and trust assessment of cloud service providers. He is a regular speaker at international security conferences and will happily share his knowledge with the audience.
ABOUT ENNO REY
Enno Rey is a long time network geek who loves to explore network devices & protocols and to break flawed ones.
ABOUT PASCAL TURBING
Pascal Turbing is a long time network geek, pentester, and security researcher who loves to explore network devices & protocols and to break flawed ones.
ABOUT DANIEL MENDE
Daniel Mende is a long time network geek who loves to explore network devices & protocols and to break flawed ones.