Host access and shell

A bhyve host is a FreeBSD machine running one bhyve process per guest. Control of the host is control of the guests: bhyvectl and the management wrappers (vm-bhyve, or an appliance UI) start, stop, and inspect them, and the guest disks are image files or ZFS volumes on the host. Reaching the host is ordinary FreeBSD compromise.

sh
ls /dev/vmm/                               # running bhyve VMs
bhyvectl --vm=<name> --get-all             # VM state
vm list                                    # vm-bhyve wrapper, if used
zfs list -t volume                         # ZFS-backed guest disks

Exploitation notes#

  • The host owns every guest's disk image or ZFS volume, so host access leads directly to offline guest data.
  • Appliances built on bhyve often expose a management UI or API that fronts the host; compromising it reaches the host shell.
  • ZFS-backed guests can be snapshotted and read from the host without touching the running guest.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more