SUN Solaris 10 will virtualize

Release number 10 of SUN’s Unix is coming and it will introduce many new features. One of the most interesting is so called N1 Grid Containers:

N1 Grid Containers is a breakthrough approach to virtualization with multiple software partitions per single instance of the OS. N1 Grid Containers make consolidation simple, safe and secure.
Superior Resource Utilization. N1 Grid Containers dynamically adjust resources to business goals within and across the container. With little management overhead (less than 1%), it offers over 4,000 containers per system.
Increased Uptime. With N1 Grid Containers, applications are isolated from each other and from system faults. Using Instant Restart, each Container can be restarted in just seconds. Boot time in large systems can be reduced by as much as 70%.
Reduced Costs. N1 Grid Containers simplifies and accelerates consolidation. It also significantly reduces system, admin and maintenance overhead.

Ashlee Vance, one The Register writer, said:

“The containers are Sun’s answer to logical partitions (LPARs) on AIX and HP-UX and the virtual machines touted by VMware/EMC for Windows and Linux servers. The software permits users to carve up a server into multiple partitions and to set up processing, memory and bandwidth limits for each partition.”

Virtual Infrastructure connecting IT to the Business

Googlin’ around I just found a very interesting official VMware presentation about Virtual Infrastructure. I seached in official site but it doesn’t seem to be public (nor in whitepapers neither in webinars). Since it includes Virtual Center prices I think it’s a sales presentation.

It resides on Tomato website (a VMware Virtual Partner) and you can find it here.

Egenera announces agreement with VMware

Yes, I know this is a very old news (November 2003) but just discovered and seems interesting enough to publish it:

Egenera Inc., the leader in next-generation datacenter infrastructure, today announced an alliance with VMware, the global leader in virtual infrastructure software for Intel®-based systems. Under the terms of the agreement, Egenera will offer customers VMware GSX Server bundled with the EgeneraTM BladeFrame® system and will fully support the solution.

“With its innovations in PAN architecture, Egenera has moved the systems market into its next generation,” said Peter Sonsini, senior director of alliances, VMware. “Combining VMware’s virtual computing technology with the BladeFrame system enables enterprise customers to improve resource utilization, consolidate servers and streamline administration to lower total cost of ownership”.

Looking at Egenera website you’ll notice they also have a cooperative alliance with EMC, among others.

Dell & EMC preparing low-end SAN

Taken from Neowin:

Dell VP Russ Holt today said the company is working on a “sub-entryâ€� SAN platform for release later this year. Speaking to analysts on a conference call, Holt described the elements of the product: “Aligning with that platform is the delivery of a low-cost HBA solution and a low-cost switch solution, so we we’ll see a much lower cost of entry for SAN solutions.â€�

The small to medium-sized business (SMB) market is considered fertile ground for storage vendors. SAN makers obviously want in: Hewlett-Packard Co. and Network Appliance Inc. are already attacking the market, and startup XIOtech Corp. recently announced a new entry-level SAN.

Holt gave few details about the low-end system, but there have been whispers that Dell and EMC will co-brand two lower-end versions of the Clariion SAN they currently sell. Dell, which manufactures the lowest end of three current Clariion systems that it co-brands with EMC, would manufacture the new system. The two companies earlier this month announced an upgrade of the existing Clariion line.

EMC spokesman Dave Farmer would not confirm a lower-end Clariion is on the way. “We have said we will continue to scale our platform up and down,� he said.

At my eyes this means that EMC is preparing to gain maximum profit from VMware acquisition and is launching a small SAN to eventually bundle with ESX and GSX servers.
This move, if I’m right, will disrupt IBM affairs, usually offering well-known bundle: ESX Server + xSeries + FastT.

Microsoft Virtual Server 2004 enters in Beta phase

VS finally left the long customer preview phase (just a month was left before license expiration, after already an extension) and entered in beta phase. Many (long awaited) new features are included and few disappeared.
It’s becoming much clearer what VS will be and what place will have on virtualization market.

Repackaging applications 6 times faster using InstallShield AdminStudio and VMware Workstation

With AdminStudio, you can leverage InstallShield’s knowledge of industry-standard installation formats to precisely and rapidly package your script-based setups authored with InstallShield technology. AdminStudio comes with automated InstallShield SmartScan technology that automatically extracts information that other packaging tools miss

InstallShield’s AdminStudio now seamlessly integrates with VMware Workstation, saving system administrators significant time during repackaging and application migration projects.
Read this whitepaper here.

Virtual PC Services Insecure Temporary File Creation

Application: Connectix Virtual PC 6.0.x / Microsoft Virtual PC 6.1
Platform: Mac OS X
Severity: Local privilege escalation
Author: George Gal Vendor Status: Vendor has updated version of the software CVE Candidate: CAN-2004-0115
Reference: www.atstake.com/research/advisories/2004/a021004-1.txt


Overview:

Virtual PC is a popular x86 virtual machine emulator capable running several guest operating systems under the Mac OS X and Windows platforms. Virtual PC provides a set of services for managing network sharing capabilities under Mac OS X. These services are spawned from the setuid root binary, VirtualPC_Services, which creats several temporary files when it is executed. The VirtualPC_Services does not check for several unsafe conditions prior to creation of these temporary files. As a result an attacker with interactive login access to the system may leverage insecure temporary files to become root or overwrite critical system files.

Details:

@stake has identified a vulnerability within the setuid root binary,
VirtualPC_Services, due to its inability to check for dangerous
conditions prior to temporary file creation. This vulnerability
allows an attacker to truncate and overwrite arbitrary files in
addition to creation of arbitrary files with insecure file
permissions.

Using this vulnerability it is feasible for an attacker to gain root
privileges on the system. The VirtualPC_Services binary creates a
log file upon startup as /tmp/VPCServices_Log. An attacker may
create a symbolic link in the /tmp/ directory as VPCServices_Log
pointing to an arbitrary file to be overwritten when the
VirtualPC_Services binary is executed. However, when the symbolic
link points to a non-existent file a new file is created with file
permissions determined by the unprivileged user’s umask(2) settings.

Vendor Response:

Microsoft has an updated version of the software available.

Download information available at:

http://www.microsoft.com/technet/security/bulletin/MS04-005.asp

Recommendation:

If possible install the updated version of Virtual PC.

Do not install Virtual PC on a multi-user machine. If this is a
requirement, only allow users with in a particular group to access
Virtual PC.