Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251

Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251

Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
NAP and Virtual Machines
NAP and Virtual Machines

NAP and Virtual Machines

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
NAP and Virtual Machines Dale.Meredith 08-01-2008
Posted by =?Utf-8?B?RGFsZS5NZXJlZGl0aA== on August 1, 2008, 11:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I had a student ask a question I can't answer....

If you deploy NAP can't it be circumvented by bring up a Virtual Machine?
IE If a user fired up a virtual machine and and uses NAT from the host PC to
gain access to the network...wouldn't the NAP environment think that the file
is being requested by host OS?....Yet actually it's the virtual machine
getting the file?

-SuperDale

Posted by S. Pidgorny on August 1, 2008, 9:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
That is a legitimate concern. Yes, in this scenario NAP will be
circumvented. Which is the reason to consider NAP management and not
security feature.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

>I had a student ask a question I can't answer....
>
> If you deploy NAP can't it be circumvented by bring up a Virtual Machine?
> IE If a user fired up a virtual machine and and uses NAT from the host PC
> to
> gain access to the network...wouldn't the NAP environment think that the
> file
> is being requested by host OS?....Yet actually it's the virtual machine
> getting the file?
>
> -SuperDale



Posted by secure-gear.com on August 1, 2008, 11:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
secure-gear.com had written this in response to
http://www.secure-gear.com/microsoft.public.security/7/NAP-and-Virtual-Machines-article24680-.htm
:
NAP cannot be circumvented this way, because the virtual machine will have
a unique MAC and IP address. From the perspective of the Windows Server
2008/NPS, the host system will remain undiagnosed. Only the VM will be
seen as having passed the NAP health check.

The details differ depending on what transport you are using for NAP
(DHCP, 802.1x, VPN etc) but ultimately if you really want to bypass it
you'd need to write a custom TCP/IP stack extension. And even that isn't
going to get past 802.1x because you still need to authenticate.


##-----------------------------------------------##
Delivered via http://www.secure-gear.com
The Internet Knowledge Base for the security industry
no-spam access to your favorite newsgroup -
microsoft.public.security - 24381 messages and counting!
##-----------------------------------------------##

Posted by S. Pidgorny on August 2, 2008, 7:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
G'day:

> secure-gear.com had written this in response to
>
http://www.secure-gear.com/microsoft.public.security/7/NAP-and-Virtual-Machines-article24680-.htm
> :
> NAP cannot be circumvented this way, because the virtual machine will have
> a unique MAC and IP address.

Not necessarily.


--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *



Posted by =?Utf-8?B?RGFu?= on August 3, 2008, 5:22 am
If you were  Registered and logged in, you could reply and use other advanced thread options
True, but we cannot say too much in a public newsgroup. Sorry, it will have
to be part of responsible reporting. see us-cert.gov if you live in the
States.

Similar ThreadsPosted
Virtual Machines September 8, 2008, 6:46 am
Security within Virtual Machine December 5, 2005, 6:16 am
Java Virtual Machine October 17, 2006, 4:19 pm
client OS security under Virtual PC 2007 August 3, 2007, 12:34 pm
adware or spyware called virtual bouncer? January 3, 2006, 11:23 pm
Re: SuS "trojan" in XP -- Changes OS and creates "virtual" remote desk April 29, 2006, 6:08 pm
Re: SuS "trojan" in XP -- Changes OS and creates "virtual" remote desk April 29, 2006, 7:09 pm
Virtual Task Force Nabs 565 Cyber Criminals May 23, 2006, 7:18 pm
Virtual PC 2007 (SP1) silently installs vulnerable MSXML6 May 16, 2008, 1:52 pm
EFS - Machines and certificates March 6, 2007, 12:12 pm

The site map in XML format XML site map

Contact Us | Privacy Policy