<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2990507292761341672.post254878759061687572..comments</id><updated>2011-09-30T10:20:40.578-07:00</updated><category term='shares'/><category term='cdrom'/><category term='alarm'/><category term='cli'/><category term='cbrc'/><category term='ssh keys'/><category term='vMA.db'/><category term='api'/><category term='dca'/><category term='upgrade'/><category term='vGhetto'/><category term='hardening guide'/><category term='lopsided bootbank'/><category term='ghettovcb-restore'/><category term='vmx'/><category term='vSphere 4.1'/><category term='web client'/><category term='vhv'/><category term='guest os'/><category term='eam'/><category term='busybox'/><category term='traceroute'/><category term='vcsa'/><category term='ipmi'/><category term='eagerzeroedthick'/><category term='vpxa'/><category term='vix api'/><category term='vcops-admin'/><category term='vexpert'/><category term='ssd'/><category term='boot option'/><category term='dcui'/><category term='vpxd_servicecfg'/><category term='cos'/><category term='manifest file'/><category term='vscsiStats'/><category term='guest'/><category term='esxhpcli'/><category term='vShield 5'/><category term='srm5'/><category term='ruby vsphere console'/><category term='root'/><category term='capiq'/><category term='vkernel'/><category term='orchestrator'/><category term='web access'/><category term='vsphere sdk for perl'/><category term='vesxi'/><category term='vmdk'/><category term='vmkfstools'/><category term='vCenter Operations'/><category term='storage drs'/><category term='vimsh'/><category term='mac'/><category term='embotics'/><category term='unmap'/><category term='vmworld'/><category term='vgz'/><category term='vIN'/><category term='sha1'/><category term='gpt'/><category term='veeam'/><category term='vix'/><category term='vmtoolsd'/><category term='cluster'/><category term='esx4.1'/><category term='perl'/><category term='das'/><category term='tag'/><category term='capacityiq'/><category term='zeroedthick'/><category term='snapshot'/><category term='osx'/><category term='powercli'/><category term='sqlite3'/><category term='distributed virtual switch'/><category term='fdm'/><category term='mob'/><category term='charity'/><category term='plugin'/><category term='acknowledge alarm'/><category term='vSphere 4'/><category term='vdi'/><category term='cow'/><category term='hbrsvc'/><category term='nested ft'/><category term='hp rgs'/><category term='firewall'/><category term='vamp'/><category term='vifp'/><category term='hardware'/><category term='vCO'/><category term='host profile'/><category term='ruleset'/><category term='vSphere 5'/><category term='vcenter'/><category term='login'/><category term='ghetto'/><category term='vMA5'/><category term='credentialstore'/><category term='dpm'/><category term='host cache'/><category term='trainsignal'/><category term='vnc'/><category term='vmkchdev'/><category term='moref'/><category term='guestinfo'/><category term='vaai'/><category term='vcap'/><category term='vmha'/><category term='REST API'/><category term='vmware-cmd'/><category term='vibddi'/><category term='vma'/><category term='pod'/><category term='vmware view 5'/><category term='vstorage api'/><category term='kickstart'/><category term='vmtar'/><category term='active directory'/><category term='amazon ec2'/><category term='dvs'/><category term='ghettoVCB'/><category term='opvizor'/><category term='rsync'/><category term='vmdumper'/><category term='/var/log'/><category term='vcloud director'/><category term='ovftool'/><category term='custom drivers'/><category term='vsel'/><category term='fcoe'/><category term='esxhpedit'/><category term='reset alarm'/><category term='lockdown mode'/><category term='idle'/><category term='esxi 5'/><category term='performance'/><category term='vSphere'/><category term='drs'/><category term='esxi4.1'/><category term='vmotion'/><category term='vcd'/><category term='vmrc'/><category term='e1000e'/><category term='hyper-v'/><category term='fdmmob'/><category term='vmware'/><category term='security'/><category term='hbr'/><category term='role'/><category term='vum'/><category term='cvp'/><category term='oracle'/><category term='vcc'/><category term='vim-cmd'/><category term='nested'/><category term='vmfs'/><category term='esx4'/><category term='ha'/><category term='iscsi'/><category term='session'/><category term='partedUtil'/><category term='dropbox'/><category term='ks.cfg'/><category term='esxvm'/><category term='remote console'/><category term='wavemaker'/><category term='esxi5'/><category term='vft'/><category term='lwid'/><category term='workflow'/><category term='sioc'/><category term='SDRS'/><category term='vsish'/><category term='fault tolerance'/><category term='vi-fastpass'/><category term='vadp'/><category term='phd'/><category term='esxi4'/><category term='sdk'/><category term='python'/><category term='vib'/><category term='storage io control'/><category term='vcops'/><category term='dropbear'/><category term='esxcli'/><category term='ghettoVCBg2'/><category term='growl'/><category term='vcli'/><category term='evc'/><category term='vasrm'/><category term='privilege'/><category term='vstorage api for array intergration'/><category term='infrastructure navigator'/><category term='rvc'/><category term='likewise'/><category term='php'/><category term='thin'/><category term='vswitch'/><category term='mount'/><category term='syslog'/><category term='managed object reference'/><category term='bootbank'/><category term='windows8'/><category term='monitoring'/><category term='resxtop'/><category term='management interface'/><category term='sponsor'/><category term='health check script'/><category term='restrictedversion'/><category term='vilogger'/><category term='vcva'/><category term='gsutil'/><category term='vsa'/><category term='gid'/><category term='svmotion'/><category term='cim'/><category term='vcloud connector'/><category term='vmware tools'/><category term='esxtop'/><title type='text'>Comments on virtuallyGhetto: ESXi 4.1 - Major Security Issue</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.virtuallyghetto.com/feeds/254878759061687572/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html'/><author><name>William</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2990507292761341672.post-32158029294578591</id><published>2011-09-30T10:20:40.578-07:00</published><updated>2011-09-30T10:20:40.578-07:00</updated><title type='text'>William, I read this article a year ago and applie...</title><content type='html'>William, I read this article a year ago and applied the patch and thought that was the end of it.  Fast forward to ESXi5 and it reapper on my network, here&amp;#39;s what I mean http://toti3.wordpress.com/2011/09/30/esxi-password-vulnerability-reborn/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/32158029294578591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/32158029294578591'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html?showComment=1317403240578#c32158029294578591' title=''/><author><name>Totie Bash</name><uri>http://www.blogger.com/profile/16953197798450317159</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html' ref='tag:blogger.com,1999:blog-2990507292761341672.post-254878759061687572' source='http://www.blogger.com/feeds/2990507292761341672/posts/default/254878759061687572' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-200751440'/></entry><entry><id>tag:blogger.com,1999:blog-2990507292761341672.post-4665296037900386500</id><published>2010-07-18T15:45:44.720-07:00</published><updated>2010-07-18T15:45:44.720-07:00</updated><title type='text'>Hi Didier,

I just got back from the weekend and n...</title><content type='html'>Hi Didier,&lt;br /&gt;&lt;br /&gt;I just got back from the weekend and noticed the post! Great job, I did not have a lot of time to spend trying to find the solution, but it looks like it was a pretty straight forward one. &lt;br /&gt;&lt;br /&gt;I also updated my blog post with the link to yours for the solution. One method of ensuring the file is preserved is just edit the auto-backup script to also backup this specific file. I would still recommend waiting for VMware to provide a true fix via a patch/update.&lt;br /&gt;&lt;br /&gt;--William</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/4665296037900386500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/4665296037900386500'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html?showComment=1279493144720#c4665296037900386500' title=''/><author><name>William</name><uri>http://www.blogger.com/profile/07056477666904240209</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html' ref='tag:blogger.com,1999:blog-2990507292761341672.post-254878759061687572' source='http://www.blogger.com/feeds/2990507292761341672/posts/default/254878759061687572' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-792371310'/></entry><entry><id>tag:blogger.com,1999:blog-2990507292761341672.post-8527161621147165298</id><published>2010-07-17T19:46:05.371-07:00</published><updated>2010-07-17T19:46:05.371-07:00</updated><title type='text'>Hi William, I did also some researches on this iss...</title><content type='html'>Hi William, I did also some researches on this issue and came with back with a workaround... Read more at http://deinoscloud.wordpress.com/2010/07/18/esxi-4-1-major-security-issue-the-sequel-and-the-workaround/&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Didier</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/8527161621147165298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/8527161621147165298'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html?showComment=1279421165371#c8527161621147165298' title=''/><author><name>PiroNet</name><uri>http://deinoscloud.wordpress.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html' ref='tag:blogger.com,1999:blog-2990507292761341672.post-254878759061687572' source='http://www.blogger.com/feeds/2990507292761341672/posts/default/254878759061687572' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-166004215'/></entry><entry><id>tag:blogger.com,1999:blog-2990507292761341672.post-1050312364905364948</id><published>2010-07-17T14:39:32.662-07:00</published><updated>2010-07-17T14:39:32.662-07:00</updated><title type='text'>I can vouch for this issue too - it was my colleag...</title><content type='html'>I can vouch for this issue too - it was my colleague who posted that to the VMware community ;-)&lt;br /&gt;&lt;br /&gt;He got me to test it, and the problem exists for sure.&lt;br /&gt;&lt;br /&gt;Scott Vessey</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/1050312364905364948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/1050312364905364948'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html?showComment=1279402772662#c1050312364905364948' title=''/><author><name>Scott Vessey</name><uri>http://www.blogger.com/profile/06276460042238377305</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://4.bp.blogspot.com/_fpqM6K0LhjY/SmTF-fMAGAI/AAAAAAAAAA8/KkpDvkHXkVo/S220/portrait.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html' ref='tag:blogger.com,1999:blog-2990507292761341672.post-254878759061687572' source='http://www.blogger.com/feeds/2990507292761341672/posts/default/254878759061687572' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-946862884'/></entry><entry><id>tag:blogger.com,1999:blog-2990507292761341672.post-1642462908799585908</id><published>2010-07-17T14:20:40.755-07:00</published><updated>2010-07-17T14:20:40.755-07:00</updated><title type='text'>The problem does not append with AD auth</title><content type='html'>The problem does not append with AD auth</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/1642462908799585908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/1642462908799585908'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html?showComment=1279401640755#c1642462908799585908' title=''/><author><name>NiTRo</name><uri>http://www.blogger.com/profile/09781737231499981455</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html' ref='tag:blogger.com,1999:blog-2990507292761341672.post-254878759061687572' source='http://www.blogger.com/feeds/2990507292761341672/posts/default/254878759061687572' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1712980984'/></entry><entry><id>tag:blogger.com,1999:blog-2990507292761341672.post-4912112518412834192</id><published>2010-07-17T13:19:08.686-07:00</published><updated>2010-07-17T13:19:08.686-07:00</updated><title type='text'>What if you use the AD integration, is that affect...</title><content type='html'>What if you use the AD integration, is that affected?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/4912112518412834192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/4912112518412834192'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html?showComment=1279397948686#c4912112518412834192' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html' ref='tag:blogger.com,1999:blog-2990507292761341672.post-254878759061687572' source='http://www.blogger.com/feeds/2990507292761341672/posts/default/254878759061687572' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-509706876'/></entry><entry><id>tag:blogger.com,1999:blog-2990507292761341672.post-7533792647967759494</id><published>2010-07-17T11:30:21.190-07:00</published><updated>2010-07-17T11:30:21.190-07:00</updated><title type='text'>Mike,

Good find, I did not notice this earlier wh...</title><content type='html'>Mike,&lt;br /&gt;&lt;br /&gt;Good find, I did not notice this earlier while looking in the shadow file. This would make sense as DES crypt is limited to 8 character password + salt. I suspect the password is just being truncated or being encrypted by DES vs MD5 as you mentioned.&lt;br /&gt;&lt;br /&gt;Thanks&lt;br /&gt;&lt;br /&gt;--William</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/7533792647967759494'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/7533792647967759494'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html?showComment=1279391421190#c7533792647967759494' title=''/><author><name>William</name><uri>http://www.blogger.com/profile/07056477666904240209</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html' ref='tag:blogger.com,1999:blog-2990507292761341672.post-254878759061687572' source='http://www.blogger.com/feeds/2990507292761341672/posts/default/254878759061687572' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-792371310'/></entry><entry><id>tag:blogger.com,1999:blog-2990507292761341672.post-4225915186012105514</id><published>2010-07-17T11:19:28.080-07:00</published><updated>2010-07-17T11:19:28.080-07:00</updated><title type='text'>I was looking at a change I made on a newly upgrad...</title><content type='html'>I was looking at a change I made on a newly upgraded 4.1 system...&lt;br /&gt;&lt;br /&gt;And it looks like things have reverted to DES for the /etc/shadow files from a previous setting of MD5 hashes.&lt;br /&gt;&lt;br /&gt;Not good...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/4225915186012105514'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2990507292761341672/254878759061687572/comments/default/4225915186012105514'/><link rel='alternate' type='text/html' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html?showComment=1279390768080#c4225915186012105514' title=''/><author><name>Mike Horwath</name><uri>http://www.geekandi.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.virtuallyghetto.com/2010/07/esxi-41-major-security-issue.html' ref='tag:blogger.com,1999:blog-2990507292761341672.post-254878759061687572' source='http://www.blogger.com/feeds/2990507292761341672/posts/default/254878759061687572' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2055299239'/></entry></feed>
