| --- | Log | opened Tue Mar 13 00:00:12 2007 |
| 00:17 | |-| | DoberMann_ [~james@AToulouse-156-1-50-165.w90-16.abo.wanadoo.fr] has joined #xen |
| 00:19 | |-| | hollisb [~hollisb@user-0vvdf2d.cable.mindspring.com] has quit [Quit: Leaving] |
| 00:19 | |-| | DoberMann[ZZZzzz] [~james@AToulouse-156-1-78-133.w86-196.abo.wanadoo.fr] has quit [Ping timeout: 480 seconds] |
| 00:57 | |-| | Shaun2222 [~shaun@ip68-4-212-221.oc.oc.cox.net] has quit [Ping timeout: 480 seconds] |
| 00:59 | <Basic_py> | Any known issues with xen and a switch with vlan active? |
| 01:11 | |-| | kalden [~kalden@fac34-3-82-231-26-11.fbx.proxad.net] has quit [Remote host closed the connection] |
| 01:15 | |-| | paelzer [~kvirc@blueice4n1.de.ibm.com] has joined #xen |
| 01:36 | |-| | mastermind [~mastermin@mastermind.kaltenbrunner.cc] has quit [Quit: Client exiting] |
| 01:43 | |-| | dhendrix [~dhendrix@c-24-7-121-175.hsd1.ca.comcast.net] has joined #xen |
| 01:48 | |-| | mulix [~mulix@87.69.40.180.cable.012.net.il] has quit [Remote host closed the connection] |
| 02:21 | |-| | DoberMann_ changed nick to DoberMann |
| 02:23 | |-| | gthouvenin [~gthouveni@129.184.84.11] has quit [Quit: Leaving] |
| 02:34 | |-| | visik7 [~visi@host96-108-dynamic.56-82-r.retail.telecomitalia.it] has quit [Read error: Operation timed out] |
| 02:50 | |-| | aliguori [~anthony@cpe-72-179-63-62.austin.res.rr.com] has quit [Read error: Connection reset by peer] |
| 03:17 | |-| | gthouvenin [~gthouveni@129.184.84.11] has joined #xen |
| 03:20 | |-| | DoberMann changed nick to DoberMann[PullA] |
| 06:02 | |-| | buggs [~noidentd@shadow.splashground.de] has quit [Read error: Connection reset by peer] |
| 06:03 | |-| | buggs [~noidentd@shadow.splashground.de] has joined #xen |
| 06:09 | |-| | jwb_gone [~jwboyer@71-36-216-66.roch.qwest.net] has quit [Remote host closed the connection] |
| 06:21 | |-| | michal` [~michal@www.rsbac.org] has quit [Ping timeout: 480 seconds] |
| 06:26 | |-| | michal` [~michal@www.rsbac.org] has joined #xen |
| 06:48 | |-| | pea [~pea@adsl-75-52-166-182.dsl.dytnoh.sbcglobal.net] has quit [Ping timeout: 480 seconds] |
| 06:56 | |-| | jwb_ [~jwboyer@rchp4.rochester.ibm.com] has joined #xen |
| 06:58 | |-| | pea [~pea@adsl-68-73-101-14.dsl.dytnoh.sbcglobal.net] has joined #xen |
| 08:18 | |-| | jimix [~jimix@192.88.159.81] has joined #xen |
| 08:22 | |-| | danp1 [~berrange@pool-72-93-188-166.bstnma.east.verizon.net] has joined #xen |
| 08:37 | |-| | hollisb [~hollisb@192.88.159.81] has joined #xen |
| 08:39 | |-| | clalance [~clalance@nat-pool-bos.redhat.com] has joined #xen |
| 09:02 | |-| | bestorga [~bestorga@71-222-114-20.ptld.qwest.net] has joined #xen |
| 09:13 | <icblenke> | none. |
| 09:13 | |-| | tomas [tomas@twin.jikos.cz] has joined #xen |
| 09:15 | <tomas> | hi all, what do I get when I issue sidt instruction at domU? or do you know where can I find answer? :) |
| 09:25 | |-| | rharper [~rharper@bi01p1.co.us.ibm.com] has joined #xen |
| 09:28 | |-| | aliguori [~anthony@cpe-72-179-63-62.austin.res.rr.com] has joined #xen |
| 09:39 | |-| | gerrit [~gerrit@c-67-160-146-170.hsd1.or.comcast.net] has joined #xen |
| 09:48 | |-| | gerrit [~gerrit@c-67-160-146-170.hsd1.or.comcast.net] has quit [Ping timeout: 480 seconds] |
| 09:54 | |-| | KriP [~kp@yancey.unixworld.dk] has joined #xen |
| 09:58 | |-| | gerrit [~gerrit@c-67-160-146-170.hsd1.or.comcast.net] has joined #xen |
| 10:03 | <icblenke> | tomas: Have you tried Redpill or Scoopy? |
| 10:06 | |-| | sputhenp [~sputhenp@202.80.58.210] has quit [Quit: Leaving] |
| 10:12 | <tomas> | icblenke: no I don't know what those are |
| 10:14 | |-| | jimix_ [~jimix@192.88.159.81] has joined #xen |
| 10:14 | |-| | jimix [~jimix@192.88.159.81] has quit [Read error: Connection reset by peer] |
| 10:15 | <tomas> | icblenke: but yeah I have read the redpill (http://invisiblethings.org/papers/redpill.html) a time ago, thanks for reminding :) |
| 10:18 | |-| | jimix [~jimix@192.88.159.81] has joined #xen |
| 10:18 | |-| | jimix_ [~jimix@192.88.159.81] has quit [Read error: Connection reset by peer] |
| 10:18 | |-| | gerrit [~gerrit@c-67-160-146-170.hsd1.or.comcast.net] has quit [Ping timeout: 480 seconds] |
| 10:18 | |-| | jimix [~jimix@192.88.159.81] has quit [Read error: Connection reset by peer] |
| 10:19 | |-| | jimix [~jimix@192.88.159.81] has joined #xen |
| 10:35 | |-| | aw [~awilliam@c-24-9-84-32.hsd1.co.comcast.net] has quit [Remote host closed the connection] |
| 10:43 | |-| | gerrit [~gerrit@c-67-160-146-170.hsd1.or.comcast.net] has joined #xen |
| 10:45 | |-| | aw [~awilliam@c-24-9-84-32.hsd1.co.comcast.net] has joined #xen |
| 10:46 | <aliguori> | tomas: what are you tryng to do? |
| 10:47 | |-| | stephan [~stephan@141.76.44.131] has joined #xen |
| 10:48 | <icblenke> | aliguori: I read your blog post while googling to sidt to assist tomas. I don't think I've seen a timing approach to detecting virtualization yet. |
| 10:49 | <aliguori> | icblenke: is he trying to detect being in xen? |
| 10:49 | <icblenke> | That's what I deduced from his question. |
| 10:49 | <aliguori> | there's a tool in tools/misc specifically for that purpose |
| 10:50 | <icblenke> | or perhaps he was asking "how does Xen behave with sidl so that I can use it to fingerprint what virtualization my detection tool might be running under" |
| 10:51 | <aliguori> | looking at where the idt is is a silly way to detect a VM fwiw |
| 10:51 | <aliguori> | vt/svm doesn't require a shadow idt |
| 10:51 | <aliguori> | so it won't work even in vmware on newer processors |
| 10:52 | <aliguori> | vmware doesn't try to hide itself.. just look at the pci bus |
| 10:54 | <icblenke> | likewise, Xen has a PCI device for the XenBus. |
| 10:55 | <aliguori> | right, but we go out of our way to have an "official" detection mechanism |
| 10:55 | <aliguori> | so it's best to use that |
| 10:55 | <aliguori> | if you want a bullet proof "am i in a vm" test you have to do a timing attack |
| 10:58 | <icblenke> | that would be an interesting tool to write. |
| 11:00 | <danp1> | icblenke: in Xen you can just look for 'Xen' in the SMBIOS data (eg, run dmidecode) for fullvirt |
| 11:00 | <danp1> | or for paravirt just look for presence of /sys/hypervisor or /proc/xen |
| 11:00 | <danp1> | VMWare can also be detected from the SMBIOS data |
| 11:00 | |-| | aliguori [~anthony@cpe-72-179-63-62.austin.res.rr.com] has quit [Quit: Leaving] |
| 11:01 | <danp1> | no hypervisor really goes out of its way to hide itself, because its useful to management apps to be able to detect what the host is |
| 11:01 | <tomas> | I was trying to install suckit in xen guest, I am testing a rootkit detector |
| 11:02 | <icblenke> | BluePill "emulates" the SVM instructions? Crazy. |
| 11:03 | <tomas> | icblenke: what blogpost are you referring to? |
| 11:03 | <icblenke> | nesting VT/SVM by emulating them.. interesting. |
| 11:03 | <icblenke> | tomas: google "virtualization timing attack", first hit. |
| 11:03 | <tomas> | thanks |
| 11:04 | <icblenke> | that's aligouri's blog. |
| 11:05 | |-| | guillth [~guill@129.184.84.11] has joined #xen |
| 11:07 | |-| | guillth [~guill@129.184.84.11] has quit [Remote host closed the connection] |
| 11:14 | <icblenke> | aligouri: there is much talk about intercepting the RDTSC/RDMSR instructions to avoid timing attacks at detection. |
| 11:15 | |-| | aliguori [~anthony@bi01p1.co.us.ibm.com] has joined #xen |
| 11:15 | <icblenke> | it doesn't seem practical for general full system virtualization though |
| 11:23 | |-| | jerone [~jerone@bi01p1.co.us.ibm.com] has joined #xen |
| 11:32 | |-| | Basic_py [~Basic@warden.real-time.com] has quit [Quit: Leaving] |
| 11:47 | |-| | vivierl [~vivierl@129.184.84.11] has quit [Remote host closed the connection] |
| 11:48 | |-| | gthouvenin [~gthouveni@129.184.84.11] has quit [Remote host closed the connection] |
| 11:57 | |-| | vivierl [~vivierl@129.184.84.11] has joined #xen |
| 11:57 | |-| | gthouvenin [~gthouveni@129.184.84.11] has joined #xen |
| 12:15 | |-| | paelzer [~kvirc@blueice4n1.de.ibm.com] has quit [Quit: KVIrc 3.2.0 'Realia'] |
| 12:16 | |-| | mejlholm [~mejlholm@port79.ds1-abc.adsl.cybercity.dk] has joined #xen |
| 12:18 | |-| | Basic_py [~Basic@gatekeeper.real-time.com] has joined #xen |
| 12:39 | |-| | mastermind [~mastermin@mastermind.kaltenbrunner.cc] has joined #xen |
| 12:51 | |-| | hbaum [~hbaum@bi01p1.co.us.ibm.com] has joined #xen |
| 13:14 | |-| | cableman [~cableman@3e6b3c0a.rev.stofanet.dk] has joined #xen |
| 13:45 | |-| | jerone [~jerone@bi01p1.co.us.ibm.com] has quit [Quit: jerone] |
| 13:47 | |-| | stephan [~stephan@141.76.44.131] has quit [Quit: stephan] |
| 14:02 | <icblenke> | http://wiki.xensource.com/xenwiki/UbuntuDapperHowTo <-- How to rebuild glibc under Ubuntu Dapper 6.06 with -mno-tls-direct-seg-refs |
| 14:02 | <icblenke> | it's amazing how often that question is asked. |
| 14:02 | |-| | hbaum_ [~hbaum@bi01p1.co.us.ibm.com] has joined #xen |
| 14:08 | |-| | jerone [~jerone@adsl-71-145-184-88.dsl.austtx.sbcglobal.net] has joined #xen |
| 14:09 | |-| | DoberMann[PullA] changed nick to DoberMann |
| 14:49 | |-| | bestorga [~bestorga@71-222-114-20.ptld.qwest.net] has quit [Quit: Leaving] |
| 15:02 | |-| | mejlholm [~mejlholm@port79.ds1-abc.adsl.cybercity.dk] has quit [Quit: Leaving] |
| 15:05 | |-| | hbaum_ [~hbaum@bi01p1.co.us.ibm.com] has quit [Ping timeout: 480 seconds] |
| 15:06 | <aw> | hollisb: are you in yorktown? recommendations for closest/easiest airport? |
| 15:08 | <aw> | jimix: ^^^ |
| 15:08 | <jimix> | AW: for summit? |
| 15:08 | <aw> | yeah |
| 15:09 | <jimix> | white plains airport (HPN) |
| 15:09 | <aw> | jimix: great, thanks |
| 15:09 | <jimix> | but depending on where you are it won't be a direct flight |
| 15:09 | <aw> | ooh |
| 15:10 | <jimix> | if you want a direct fligh JFK or LGA is fine but expect 40minute drive from the airport |
| 15:10 | <aw> | ok, sounds good. thanks |
| 15:13 | |-| | mulix [~mulix@87.69.40.180.cable.012.net.il] has joined #xen |
| 15:22 | |-| | aw [~awilliam@c-24-9-84-32.hsd1.co.comcast.net] has quit [Quit: Leaving] |
| 15:36 | |-| | aw [~awilliam@156.153.254.66] has joined #xen |
| 15:43 | <hollisb> | aw: I'm in Austin btw |
| 15:43 | <aw> | ah, nice |
| 15:43 | |-| | msinhore [~msinhore@correio.samurai.com.br] has joined #xen |
| 15:57 | |-| | sunnyDay [~sunnyDay@DSL217-132-33-33.bb.netvision.net.il] has joined #xen |
| 16:01 | <sunnyDay> | Does anybody know: when receiving /sending packets, are the net front drivers work in interrupt/softinterrupt mode ? |
| 16:01 | <sunnyDay> | by soft interrupt i mean of course soft_irq |
| 16:19 | |-| | visik7 [~visi@host96-108-dynamic.56-82-r.retail.telecomitalia.it] has joined #xen |
| 16:36 | |-| | jwb_ changed nick to jwb_gone |
| 16:38 | |-| | cableman [~cableman@3e6b3c0a.rev.stofanet.dk] has quit [Remote host closed the connection] |
| 16:52 | |-| | jimix_ [~jimix@192.88.159.81] has joined #xen |
| 16:52 | |-| | jimix [~jimix@192.88.159.81] has quit [Read error: Connection reset by peer] |
| 17:02 | <sunnyDay> | I am repeating my question from 2 hours ago in the hope that maybe somebody have a clue... |
| 17:02 | <sunnyDay> | Does anybody know: when receiving /sending packets, are the net front drivers work in interrupt/softinterrupt mode ? |
| 17:02 | <sunnyDay> | and by soft interrupt i mean of course soft_irq |
| 17:04 | |-| | jimix [~jimix@192.88.159.81] has joined #xen |
| 17:04 | |-| | jimix_ [~jimix@192.88.159.81] has quit [Read error: Connection reset by peer] |
| 17:06 | |-| | jimix_ [~jimix@192.88.159.81] has joined #xen |
| 17:06 | |-| | jimix [~jimix@192.88.159.81] has quit [Read error: Connection reset by peer] |
| 17:07 | |-| | jimix [~jimix@192.88.159.81] has joined #xen |
| 17:07 | |-| | jimix_ [~jimix@192.88.159.81] has quit [Read error: Connection reset by peer] |
| 17:10 | |-| | aliguori [~anthony@bi01p1.co.us.ibm.com] has quit [Remote host closed the connection] |
| 17:14 | |-| | sunnyDay [~sunnyDay@DSL217-132-33-33.bb.netvision.net.il] has quit [Quit: Leaving] |
| 17:16 | |-| | clalance [~clalance@nat-pool-bos.redhat.com] has quit [Quit: Leaving] |
| 17:17 | |-| | KriP [~kp@yancey.unixworld.dk] has quit [Quit: Leaving] |
| 17:25 | |-| | hbaum [~hbaum@bi01p1.co.us.ibm.com] has quit [Quit: Client exiting] |
| 17:27 | |-| | schultmc [~schultmc@zealot.progeny.com] has quit [Quit: Client exiting] |
| 17:29 | |-| | schultmc [~schultmc@zealot.progeny.com] has joined #xen |
| 17:38 | |-| | aliguori [~anthony@cpe-72-179-63-62.austin.res.rr.com] has joined #xen |
| 17:43 | |-| | hollisb [~hollisb@192.88.159.81] has quit [Quit: leaving] |
| 17:45 | |-| | jdmason [~jonmason@65-115-68-194.dia.static.qwest.net] has quit [Remote host closed the connection] |
| 17:48 | |-| | jimix [~jimix@192.88.159.81] has quit [Quit: jimix] |
| 17:48 | |-| | gerrit [~gerrit@c-67-160-146-170.hsd1.or.comcast.net] has quit [Ping timeout: 480 seconds] |
| 17:52 | |-| | gerrit [~gerrit@c-67-160-146-170.hsd1.or.comcast.net] has joined #xen |
| 17:52 | |-| | DoberMann changed nick to DoberMann[ZZZzzz] |
| 18:04 | |-| | rharper [~rharper@bi01p1.co.us.ibm.com] has quit [Quit: Leaving] |
| 18:07 | |-| | Basic_py [~Basic@gatekeeper.real-time.com] has quit [Quit: Leaving] |
| 18:15 | |-| | aw [~awilliam@156.153.254.66] has quit [Quit: Leaving] |
| 18:31 | |-| | ivan [~ikelly@skynet.skynet.ie] has quit [Quit: Lost terminal] |
| 19:06 | |-| | visik7 [~visi@host96-108-dynamic.56-82-r.retail.telecomitalia.it] has quit [Remote host closed the connection] |
| 19:13 | |-| | aw [~awilliam@c-24-9-84-32.hsd1.co.comcast.net] has joined #xen |
| 19:40 | |-| | msinhore [~msinhore@correio.samurai.com.br] has quit [Ping timeout: 480 seconds] |
| 19:51 | |-| | msinhore [~msinhore@mail.samurai.com.br] has joined #xen |
| 20:28 | |-| | jimix [~jimix@12.145.0.2] has joined #xen |
| 21:14 | |-| | jimix [~jimix@12.145.0.2] has quit [Quit: jimix] |
| 21:21 | |-| | aliguori [~anthony@cpe-72-179-63-62.austin.res.rr.com] has quit [Quit: Leaving] |
| 21:24 | |-| | tessier [~treed@wsip-68-15-4-17.sd.sd.cox.net] has joined #xen |
| 21:25 | |-| | hollisb [~hollisb@user-0vvdf2d.cable.mindspring.com] has joined #xen |
| 22:12 | |-| | lazyb0y_ [~henning@v683.vanager.de] has quit [Remote host closed the connection] |
| 22:36 | |-| | aliguori [~anthony@cpe-72-179-63-62.austin.res.rr.com] has joined #xen |
| 22:40 | |-| | hollisb [~hollisb@user-0vvdf2d.cable.mindspring.com] has quit [Quit: leaving] |
| 22:48 | |-| | danp1 [~berrange@pool-72-93-188-166.bstnma.east.verizon.net] has left #xen [] |
| 23:26 | |-| | gerrit [~gerrit@c-67-160-146-170.hsd1.or.comcast.net] has quit [Read error: Connection reset by peer] |
| 23:32 | |-| | m0rg0th [~manugarg@220.225.228.97] has joined #xen |
| 23:46 | |-| | m0rg0th [~manugarg@220.225.228.97] has quit [Ping timeout: 480 seconds] |
| 23:58 | |-| | m0rg0th [~manugarg@220.225.228.97] has joined #xen |
| 23:59 | |-| | VS_ChanLog [~stats@ns.theshore.net] has left #xen [Rotating Logs] |
| 23:59 | |-| | VS_ChanLog [~stats@ns.theshore.net] has joined #xen |
| --- | Log | closed Wed Mar 14 00:00:12 2007 |