mirror of
https://github.com/nikaiw/VMkatz
synced 2026-09-25 07:51:06 +00:00
Document Python loader for ESXi VIB bypass, add VIB field to bug template
- README: new section explaining vmkatz_loader.py usage when execInstalledOnly is enabled, with command to check VIB status - Bug template: add ESXi VIB protection field asking for execInstalledOnly value and ESXi version
This commit is contained in:
@@ -102,6 +102,15 @@ body:
|
||||
description: For ESXi — VMFS-5 or VMFS-6? (`esxcli storage filesystem list`)
|
||||
placeholder: "VMFS-6, ext4, NTFS, etc."
|
||||
|
||||
- type: input
|
||||
id: esxi-vib
|
||||
attributes:
|
||||
label: ESXi VIB protection (if running on ESXi)
|
||||
description: |
|
||||
Run: `esxcli system settings advanced list -o /User/execInstalledOnly`
|
||||
And: `vmware -v`
|
||||
placeholder: "execInstalledOnly = 1, ESXi 8.0 Update 3"
|
||||
|
||||
- type: textarea
|
||||
id: command
|
||||
attributes:
|
||||
|
||||
@@ -263,6 +263,30 @@ esxcli system settings advanced set -o /User/execInstalledOnly -i 0
|
||||
/tmp/vmkatz /vmfs/volumes/datastore1/MyVM/MyVM-flat.vmdk
|
||||
```
|
||||
|
||||
### Running with VIB protection enabled
|
||||
|
||||
When `execInstalledOnly` is set to 1 (default on ESXi 7.0+), unsigned binaries cannot be executed directly. The included Python loader (`vmkatz_loader.py`) bypasses this by loading vmkatz into anonymous memory pages — ESXi allows `PROT_EXEC` on anonymous mappings while blocking `execve` on unsigned files.
|
||||
|
||||
Python is VIB-signed on all ESXi versions and can execute normally.
|
||||
|
||||
```bash
|
||||
# Upload both files
|
||||
scp vmkatz_loader.py target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
|
||||
|
||||
# Run through the loader (no need to disable execInstalledOnly)
|
||||
python3 /tmp/vmkatz_loader.py /tmp/vmkatz /vmfs/volumes/datastore1/MyVM/snapshot.vmsn
|
||||
|
||||
# Works on ESXi 6.5+ (Python 2.7), 6.7+ (Python 3.5), 8.0+ (Python 3.8)
|
||||
python /tmp/vmkatz_loader.py /tmp/vmkatz --vmfs-list
|
||||
```
|
||||
|
||||
The loader parses the ELF binary, maps segments into anonymous pages, applies relocations, and jumps to the entry point. No files are written to disk, no VIB signature check is triggered.
|
||||
|
||||
To check if VIB protection is active on your ESXi host:
|
||||
```bash
|
||||
esxcli system settings advanced list -o /User/execInstalledOnly
|
||||
```
|
||||
|
||||
## VMFS-6 Raw Device Access (ESXi)
|
||||
|
||||
On ESXi, VMFS locks prevent reading flat VMDK files from running VMs via the mounted filesystem. VMkatz includes a self-contained VMFS-6 parser that reads directly from the raw SCSI device, bypassing file locks entirely — no `vmkfstools`, no `.sbc.sf` access, no unmounting.
|
||||
|
||||
Reference in New Issue
Block a user