ESXI5-VM-000008 - The system must disable virtual disk erasure

Information

Shrinking and wiping (erasing) a virtual disk reclaims unused space in it. If there is empty space in the disk, this process reduces the amount of space the virtual disk occupies on the host drive. Normal users and processes-that is, users and processes without root or administrator privileges-within virtual machines have the capability to invoke this procedure. However, if this is done repeatedly, the virtual disk can become unavailable while this shrinking is being performed, effectively causing a denial-of-service. In most datacenter environments, disk shrinking is not done, so this feature should be disabled. Repeated disk shrinking can make a virtual disk unavailable. Capability is available to nonadministrative users in the guest.

Solution

As root, log in to the ESXi host and locate the VM's vmx file.
find / | grep vmx

Add the following to the VM's vmx file.
keyword = 'keyval'

Where:
keyword = isolation.tools.diskWiper.disable
keyval = TRUE

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Virtual_Machine_V1R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|I, CCI|CCI-000366, Group-ID|V-39449, Rule-ID|SV-51307r1_rule, STIG-ID|ESXI5-VM-000008, Vuln-ID|V-39449

Plugin: VMware

Control ID: 65db26479e6b7600c44ec30bf0160231f082ec76f0decee27866adbdfcbaf1c0