TeLeScope is a method to eavesdrop on TLS (hence the specific capitalisation in TeLeScope) communications between a virtualised server and a client without leaving any forensic evidence behind.

The attack capability was discovered by Bitdefender, who suggest that a CIO who outsources their virtualised infrastructure to third party providers should assume that all communications can be or has been snooped on by anyone knowledgeable enough to take advantage of the flaw.

“…we decided to publically disclose this in detail, as the social, economic and political stakes of passive traffic monitoring in virtualised environments are overwhelming”, states Bogdan Botezatu, Senior E-Threat Analyst at Bitdefender.

The following Help Net Security article discusses the ramifications in relatively simple language, while Radu Caragea’s whitepaper discusses the method technically.

References:The Help Net Security article – Hypervisor wiretap feature can leak data from the cloud Radu Caragea’s whitepaper – TeLeScope – real-time peering into the depths of TLS traffic from the hypervisor

Are you protected by a Certified Ethical Hacker?

Terry

Want to learn more about how to protect your IT information and privacy? Attend the EC-Council Certified Ethical Hacker course at DDLS.



Feature Articles


Blog
2024-2025 Government Budget: Focusing investment in cyber security skilling
By Jeremy Daly | 1 July 2024
Blog
AI for Productivity: The 11:11 Tipping Point and Copilot Training
By Leif Pedersen | 19 April 2024
Blog
How to improve communication skills - Power up with Microsoft Copilot training
By Leif Pedersen | 22 April 2024
Blog
Staying on top of AI Trends and Microsoft AI training as a business strategy
By Leif Pedersen | 18 March 2024
eBook
Get your teams up-to-speed with ITIL® 4
22 May 2024
eBook
Elevate your business and career to new heights
22 May 2024
Blog
Understanding PRINCE2 Version 6 vs 7: Themes, risks & issue management
By Fred Carenese | 21 May 2024