Xen is a type-1 hypervisor with a privileged control domain, dom0, that manages the unprivileged guest domains (domU). Offensive targets are dom0 itself, the guest-to-host escape surface (hypercalls, grant tables, paravirtualized backend drivers, and the QEMU device models used for HVM guests), the XCP-ng and XenServer management plane, and the virtual disks on the storage repository. Xen powers cloud platforms and Citrix products.
Subtopics#
- Host access and shell: reaching dom0.
- Guest to host escape: breaking out to dom0 or the hypervisor.
- Management plane: XCP-ng, XenServer, and xapi.
- Disk and snapshot theft: reading guest disks.
- Known escape exploits: named Xen breakouts.