OpenVZ and rootkits [message #42786] |
Fri, 27 May 2011 18:11 |
curtis_isparks
Messages: 14 Registered: April 2011
|
Junior Member |
|
|
Because OpenVZ does not have a hypervisor layer (where guests run their own kernel), it does make me wonder about security. Does it still provide protection for the HN against most rootkits that might be run inside a container? In other words, do rootkits that have no knowledge that they are being run inside a container also cause problems for the HN? Are there rootkits that are built specifically to break out of OpenVZ containers?
Thanks,
Curtis
|
|
|