Disk and backup theft

Proxmox stores VM disks as qcow2, raw, or LVM volumes on the node's configured storage, and it takes full-guest backups with vzdump, commonly to an NFS share or a Proxmox Backup Server. Both are offline paths to guest data: mount a disk image, or restore and read a backup, without booting or authenticating to the guest.

bash
ls /var/lib/vz/images/<vmid>/              # local VM disks
ls /var/lib/vz/dump/                        # vzdump backup archives (vma/tar)
# Mount a disk image offline to extract secrets
guestfish --ro -a vm-disk.qcow2 -i

Exploitation notes#

  • vzdump archives are complete guest images; a reachable backup share or Proxmox Backup Server holds every protected VM's data.
  • Offline disk access sidesteps the guest OS: pull Linux shadow files or Windows SAM/NTDS.dit.
  • Backup credentials and encryption keys in /etc/pve or the backup client config widen access to the whole backup store.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more