Network Tunneling with QEMU
securelist.com
securelist.com
<qemu:commandline>
<qemu:arg value='-netdev'/>
<qemu:arg value='socket,id=mynet0,listen=10.6.0.1:12200'/>
<qemu:arg value='-device'/>
<qemu:arg value='virtio-net-pci,netdev=mynet0,id=net1,mac=58:a4:c0:a8:bf:51,bus=pci.0,addr=0x3'/>
</qemu:commandline>
On the other endpoint, a Linux TAP tunnel daemon is responsible for encapsulating packet to the Length-Value data as the article said.In this way, I can create a L2 tunnel from remote site to the VM, also keep the VM untainted.
Does xml suck. Meh yea it mostly does. Was it a crappy format for everything. Yes, XML over the wire, not so great.
Would I rather have xml configs than yaml, or json... The more I think about it, yes, I would.
1. The dom sucks in a browser, it's gross when it gets huge. If your config files are THAT large then, we have OTHER problems.
2. Validation. It validates. Not only on a syntax level (is this document complete, does it have a final close tag). You can also run checks against a DTD, an xml schema and XSD(??? its been a while, I think this was a way).
3. XSLT: I have mixed feelings on this, but there was a way to merge, change and transform... IT was powerful and testable, way better than templated config files.
Maybe I am looking at it wrong, maybe this is me having rose colored glasses for an ex. But I sure would like all those features BACK.
1. Plain old hash maps and arrays. No special stuff required 2. JSON schema exists and works pretty well 3. JSON path and json patch cover this. Though because json follows a plain object model there just isn’t as much need.
Contrary to xml having clean object structure and not having to worry about using nested data or props makes all of the above easier and require fewer special tools. Additionally in the qemu example you can see problems with xml right away look at this extra “qemu:” structures, yay more stuff to parse. Then the args come in as repeated elements, are those an array or not?
https://theuniguide.com.au/news/anu-releases-details-of-data...
- AllSnap v1.33.2
- Comodo Internet Security v5.0.163652.1142 (requires reboot)
- DirectX 9c June 2010
- Everything v1.2.1.371
- Foxit PDF Reader Pro v3.0.1301
- GetDiz v4.4.0.0
- HashCheck v2.1.11
- Prio v1.9.9.2091
- Visual-C++ Runtimes 2005 and 2008
- WinRAR v3.91
and even the Archive entry is tagged 691MBThe "MicroXP" variant (also from the same ISO) installs in <10 minutes and takes about 250 Mb if you disable the page file. It can even be reduced a bit more if you know you're not going to use some components (e.g. a browser), I assume.
I just ran `osslsigncode verify qemu-w64-setup-20231224.exe` and it appears it's signed but the 1 year cert expired in December 2023. Still, I would expect that QEMU releases tend to be trusted fairly quickly assuming a decent number of users.
[0]: open source options available for free[1] or ~$50/year[2]. If you get your app on the Microsoft App Store, they'll sign it for you which is also free ($19 lifetime account IIRC).
[2]: https://shop.certum.eu/data-safety/code-signing-certificates...
securelist.com also states the tunnel made by qemu is not encrypted
I would assume that the attacker's destination IP would show up on some dashboards somewhere though...