Crawling through several manuals and blogs i cant find any answer how customization tools (sysprep) or the information find their way into the VM.
By mounting the boot disk over some API (would make sense as the customization depends on scsi0:0 as boot disk - but a Guest on IDE disk can be customized too) ?
A backdoor in the vm-tools (would mean a security threat) ?
Mounting a CDROM or Floppy (unlikely as it works on VMs without floppy or IDE controller) ?
Adding temporarly a disk ?