Virtualization: Hardening Xen
2008 December 9 - By Steve Maresca
Coming soon in this entry, details about hardening your xen installations.
Topics to be discussed include:
-paravirtual framebuffer: intended function, patch sets, and practical considerations. 3.0.4 and up.In progress and coming your way as time permits. Check back soon.
-pygrub
-xenstore denial of service
-networking (ebtables, iptables, etc)
-vnc over SSL
-xenapi over SSL
-minios, stubdomains, pvgrub
-driver domains
-pci passthrough (why DMA spells disaster when lacking an IOMMU)
http://www.zentific.com :)