Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
K.N Cloud — High-Performance KVM VPS in Miami,Frankfurt and Amsterdam
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Neutralizing the security risk of QEMU Guest Agent without removing it

2

Comments

  • Talk about coincidence! Just when I decided to stop and mask qemu-guest-agent completely on all my VPS, this forum post appears out of nowhere. What perfect timing! Really appreciate the guide, this is exactly the kind of information I was looking for.

    Thanked by 1forest
  • jadenjaden Member

    Thanks for posting this. I just updated my Ansible playbooks. I look forward to your next installment :)

    Thanked by 1forest
  • DartNodeDartNode Member, Patron Provider

    @forest said:

    @rpqu said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    That sounds like shellbox.dev. If you want to run a host, I'd recommend to lease hypervisor from:
    US: @crunchbits / @DartNode / @TierNet / @georgedatacenter (For hot SSD backup, I have told you the host, right?)
    APAC: @bbmmsvr4u / @trumvps / @Advin / @ddps
    EU: too many lol

    I was considering colo at a local datacenter if I end up doing it (so in the US), since I have hardware already.

    Feel free to reach out if Houston, Texas is an option for you. Happy to help! dartnode.com/colocation/houston

    Thanked by 2forest oloke
  • beanman109beanman109 Member, Host Rep, Megathread Squad

    @rpqu said: But it's better if you could borrow identity from someone. Maybe @beanman109

    let me just stop you right there

  • rpqurpqu Member

    @beanman109 said:

    @rpqu said: But it's better if you could borrow identity from someone. Maybe @beanman109

    let me just stop you right there

    Hmm? It's a good vessel, right?

  • beanman109beanman109 Member, Host Rep, Megathread Squad

    @rpqu said:

    @beanman109 said:

    @rpqu said: But it's better if you could borrow identity from someone. Maybe @beanman109

    let me just stop you right there

    Hmm? It's a good vessel, right?

    get your own identity, mines being used

  • rpqurpqu Member

    @beanman109 said:

    @rpqu said:

    @beanman109 said:

    @rpqu said: But it's better if you could borrow identity from someone. Maybe @beanman109

    let me just stop you right there

    Hmm? It's a good vessel, right?

    get your own identity, mines being used

    :D :D :D The identity part is a joke. My advice for @forest to use BEANSUMMERHOST NEXTGEN SHED HOSTING SOLUTIONS LLC AS is real

  • beanman109beanman109 Member, Host Rep, Megathread Squad
    edited August 11

    @rpqu said:

    @beanman109 said:

    @rpqu said:

    @beanman109 said:

    @rpqu said: But it's better if you could borrow identity from someone. Maybe @beanman109

    let me just stop you right there

    Hmm? It's a good vessel, right?

    get your own identity, mines being used

    :D :D :D The identity part is a joke. My advice for @forest to use BEANSUMMERHOST NEXTGEN SHED HOSTING SOLUTIONS LLC AS is real

    Tor and Freedom of speech in general is not allowed on AS206540 - https://as206540.beanman.net/

  • forestforest Member
    edited August 11

    What about non-free speech in general on your "No Speech Hosting".

    Thanked by 1RIYAD
  • beanman109beanman109 Member, Host Rep, Megathread Squad

    @forest said:
    What about non-free speech in general?

    Yes we are the worlds first no-speech host, if you can commit to not making any form of speech on our network we may be able to make an arrangement

    Thanked by 3rpqu forest RIYAD
  • rpqurpqu Member

    @beanman109 said:
    Tor and Freedom of speech in general is not allowed on AS206540 - https://as206540.beanman.net/

    Thanked by 2beanman109 forest
  • forestforest Member

    @forest said:

    @rpqu said:
    If average LET hosts shared best practices like @forest, security incidents will be fewer

    Just wait until I post a guide on how to tell if a host is leaking your traffic to other tenants and how to determine if it's possible to use ARP spoofing to completely redirect traffic from another VM to yours. :D

    It's actually a lot of hosts...

    Speaking of which... I currently have two hosts that I can run tcpdump on and see other tenants' DNS responses and HTTP responses (at about 50 Mbps total), one of which claims to be ISO 27001 certified. :D

  • rpqurpqu Member
    edited August 11

    @forest said:

    @forest said:

    @rpqu said:
    If average LET hosts shared best practices like @forest, security incidents will be fewer

    Just wait until I post a guide on how to tell if a host is leaking your traffic to other tenants and how to determine if it's possible to use ARP spoofing to completely redirect traffic from another VM to yours. :D

    It's actually a lot of hosts...

    Speaking of which... I currently have two hosts that I can run tcpdump on and see other tenants' DNS responses and HTTP responses (at about 50 Mbps total), one of which claims to be ISO 27001 certified. :D

    ISO is just guidance... Oh no, you relapsed

  • emghemgh Veteran, Megathread Squad

    @forest said:

    @rpqu said:
    If average LET hosts shared best practices like @forest, security incidents will be fewer

    Just wait until I post a guide on how to tell if a host is leaking your traffic to other tenants and how to determine if it's possible to use ARP spoofing to completely redirect traffic from another VM to yours. :D

    It's actually a lot of hosts...

    On LiteServer I didn’t have to do anything to accomplish this, it was the default and also counted towards my bw quota😂

  • @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    Please don’t

  • atklatkl Member

    @forest said:
    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    Maybe then you should set-up a small one for Tor nodes vps only or similar? With first, priority seats for the LET most active users, to not bring too much headache?

    Personally am learning by doing, no programming or server background.
    Although I would not qualify, i would love to tag along for the learning experience while renting vps/helping tor community along the way

  • forestforest Member
    edited August 11

    @Motion3549 said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    Please don’t

    Why not? I've done similar at my work. Only difference is there are no MJJs there (and unlike a hosting project, I expect to make money at work, not lose it!).

    @atkl said: With first, priority seats for the LET most active users, to not bring too much headache?

    Yeah, that was my thought. Maybe even invite-only. Just something to let people play around with.

    But again, no specific plans.

  • rpqurpqu Member
    edited August 11

    @forest said:

    @Motion3549 said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    Please don’t

    Why not? I've done similar at my work. Only difference is there are no MJJs there (and unlike a hosting project, I expect to make money at work, not lose it!).

    *heavy breathing*

    @atkl said: With first, priority seats for the LET most active users, to not bring too much headache?

    Yeah, that was my thought. Maybe even invite-only. Just something to let people play around with.

    But again, no specific plans.

    Lovely, let's ♟

  • stable_geniusstable_genius Member
    edited August 11

    @forest said:

    @Motion3549 said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    Please don’t

    Why not? I've done similar at my work. Only difference is there are no MJJs there (and unlike a hosting project, I expect to make money at work, not lose it!).

    @atkl said: With first, priority seats for the LET most active users, to not bring too much headache?

    Yeah, that was my thought. Maybe even invite-only. Just something to let people play around with.

    But again, no specific plans.

    If you want to test the real merits of this approach you cannot pre select your "customers," you must let it loose in the wild and see how it performs. You need real adversaries.

    Very useful post by the way, your karma just got a bump

    👍

  • kuroitkuroit Member, Host Rep, Megathread Squad

    @VirtFusion maybe you can implement these on VF if not already.

    You're always one step ahead, but mentioning you anyway haha. <3

    Thanked by 2VirtFusion oloke
  • @rpqu said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    That sounds like shellbox.dev.

    Meh, I was expecting to be greeted by an emulated SSH interface at shellbox.dev but got a mere SSH themed website instead. What a disappointment!

  • rpqurpqu Member

    @stable_genius said:

    @rpqu said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    That sounds like shellbox.dev.

    Meh, I was expecting to be greeted by an emulated SSH interface at shellbox.dev but got a mere SSH themed website instead. What a disappointment!

    You can though ssh shellbox.dev help --json

  • @rpqu said:

    @stable_genius said:

    @rpqu said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    That sounds like shellbox.dev.

    Meh, I was expecting to be greeted by an emulated SSH interface at shellbox.dev but got a mere SSH themed website instead. What a disappointment!

    You can though ssh shellbox.dev help --json

    That's a data dump not an interface. They could build an SSH terminal interface for this.

  • rpqurpqu Member

    @stable_genius said:

    @rpqu said:

    @stable_genius said:

    @rpqu said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    That sounds like shellbox.dev.

    Meh, I was expecting to be greeted by an emulated SSH interface at shellbox.dev but got a mere SSH themed website instead. What a disappointment!

    You can though ssh shellbox.dev help --json

    That's a data dump not an interface. They could build an SSH terminal interface for this.

    My bad, remove the --json flag

    Thanked by 1stable_genius
  • stable_geniusstable_genius Member
    edited August 11

    @rpqu said:

    @stable_genius said:

    @rpqu said:

    @stable_genius said:

    @rpqu said:

    @forest said:

    @s0n1c said:
    @forest if you ever start a VPS host, let me know. You seem like you're more competent than most hosts here

    I've actually been considering setting up a very small one. Not to earn money of course (no way I can compete in this market), just to learn. I was thinking of using a gimmick to increase the expert-to-MJJ ratio, like having the entire purchase process, tickets, and configuration be done exclusively over an interactive SSH session (no WHMCS or anything like that). No templates, just installation via an ISO URL and serial over SSH. Maybe I'll offer heavy discounts for anyone who runs a Tor middle relay on their home internet or something. But so far it's just a vague idea, no concrete plans.

    That sounds like shellbox.dev.

    Meh, I was expecting to be greeted by an emulated SSH interface at shellbox.dev but got a mere SSH themed website instead. What a disappointment!

    You can though ssh shellbox.dev help --json

    That's a data dump not an interface. They could build an SSH terminal interface for this.

    My bad, remove the --json flag

    Great, that's what I was expecting. The website is just a glorified manual page for the terminal interface, even better than what I expected.

    Thanks!

    👍

  • drivexdrivex Member

    When tutorial for traffic sniffing? You doing simple tcpdump, right?

  • A valuable contribution to the community

  • vicayavicaya Member

    @forest said:
    And if you want to allow nothing at all beyond graceful shutdown support, you would do:

    [general]
    allow-rpcs=guest-sync-delimited,guest-sync,guest-ping,guest-shutdown
    

    It's August 2026. People who care can now quickly build a minimal guest agent in Rust that only implements this minimal set of commands, so that you have no chance to shoot yourself in the foot by f*cking up the configuration.

    Caveats

    You can get data-at-rest security by using full-disk encryption (FDE), but even that does not protect from the host directly tampering with guest memory. It's still a good idea on its own, though!

    One way to trade performance for more security is to use nested FDE with 2 or more vendors, so that vendors have to collude to decrypt your disks at rest.

    To fully protect from a malicious host, you would need a host that supports running the guest in a confined trusted execution environment (TEE) where memory content itself is encrypted, such as a host that supports AMD SEV-SNP. You'd additionally need to set up remote attestation and use FDE. The big hyperscalars often support this (well, kind of...), but the only provider on LET which can do this, to the best of my knowledge, is Onidel (@onidel and @oloke). SEV-SNP can only be broken by sophisticated attackers with physical access.

    It's important to avoid Intel TDX at all cost, as it's broken beyond mitigations. AMD SEV-SNP on Turin (Zen5 or later) with external HSM signers is still OK if you know what you're doing.

    And Cloudinit is another subject altogether...

    Cloud-init could allow host to run any commands inside the guest. If you already use TEEs, you should use UKIs anyway without the possibility of host controlled cloud-init. You can still do secure cloud-init with your own cloud-init servers if you know what're doing.

    Thanked by 2stable_genius 0xC7
  • forestforest Member

    @drivex said:
    When tutorial for traffic sniffing? You doing simple tcpdump, right?

    I was doing tcpdump -nqi ens3 -Q in "not ip dst $myip and not multicast and not arp". It doesn't sniff relay traffic, it just displays unknown-unicast traffic and leaking L2 management plane traffic.

    @vicaya said: It's August 2026. People who care can now quickly build a minimal guest agent in Rust that only implements this minimal set of commands, so that you have no chance to shoot yourself in the foot by f*cking up the configuration.

    No way! The only way to do that is by vibe-coding it, and it's because of vibe-coding that Rust projects are now often some of the most insecure, despite the language itself being memory safe. It's much better to use the official agent and use its official filtering facility.

    @vicaya said: One way to trade performance for more security is to use nested FDE with 2 or more vendors, so that vendors have to collude to decrypt your disks at rest.

    Are we talking about open source or closed source FDE? I was thinking LUKS, which uses dm-crypt under the hood. It can't decrypt your disk without you giving it the key.

    @vicaya said: Cloud-init could allow host to run any commands inside the guest.

    Yup, but at least Cloudinit is often only present on templates. QEMU Guest Agent, on the other hand, auto-installs even if you install from ISO manually. But yes, Cloudinit is another problem that I'll write about later.

    Thanked by 2drivex 0xC7
  • vicayavicaya Member

    @forest said:

    @vicaya said: It's August 2026. People who care can now quickly build a minimal guest agent in Rust that only implements this minimal set of commands, so that you have no chance to shoot yourself in the foot by f*cking up the configuration.

    No way! The only way to do that is by vibe-coding it, and it's because of vibe-coding that Rust projects are now often some of the most insecure, despite the language itself being memory safe. It's much better to use the official agent and use its official filtering facility.

    I have August there for a reason. Ask Fable 5 (high to do the coding and xhigh to do the review) to do the work and report back :D

    @vicaya said: One way to trade performance for more security is to use nested FDE with 2 or more vendors, so that vendors have to collude to decrypt your disks at rest.

    Are we talking about open source or closed source FDE? I was thinking LUKS, which uses dm-crypt under the hood. It can't decrypt your disk without you giving it the key.

    Host can easily dump guest memory and use findaes to get your DEKs directly without using LUKS passphrases. They only need to do that once and then decrypt the disks offline at their leisure. Nested LUKS would require coordinated effort from different vendors, assuming the correct setup.

    @vicaya said: Cloud-init could allow host to run any commands inside the guest.

    Yup, but at least Cloudinit is often only present on templates. QEMU Guest Agent, on the other hand, auto-installs even if you install from ISO manually. But yes, Cloudinit is another problem that I'll write about later.

    Not if you use the official (non-cloud-init) version of the iso or install from netboot. The guest agent is not installed by default, e.g., ubuntu server minimal iso.

Sign In or Register to comment.