Recommended Posts

no, it's not necessary, the VM is completely isolated from the host as long as you don't have shared folders turned on (even then it's highly unlikely that any virus would know to make use of that)

That very much depends on what you are using the VM for. The VM can definitely still get a virus. And the VM isn't completely isolated from the host if it's on the same network. You could easily spread the virus back to the host over that network, just like any other two computers on the same network. If it's just a temporary VM that you are going to tear down, or can afford to wipe out and replace if it does get a virus, then maybe you don't care. If it's a VM that's going to stay running and is daily use, you'll probably want to put AV on it. AV on your host has nothing to do with your VM, so treat it as if it is it's own machine.

^ i was talking completely isolated as in file system wise, the fact that it's still using the same network should (i at least hope) be a given

though i definitely agree with you that it also depends on how the VM is being used

^ i was talking completely isolated as in file system wise, the fact that it's still using the same network should (i at least hope) be a given

though i definitely agree with you that it also depends on how the VM is being used

Oh, right, it won't spread from the VM's HDD to the host's HDD. But it can still propagate over the network.

Well actually, if you're using VirtualBox there's an exploit for that... ;)

:laugh: Really? I'm really not that surprised. If the files are on the same hard drive, I suppose there's always the possibility. You could say that's what you get for using a free VM. Any issues like that on more trusted VMs?

:laugh: Really? I'm really not that surprised. If the files are on the same hard drive, I suppose there's always the possibility. You could say that's what you get for using a free VM. Any issues like that on more trusted VMs?

Most hypervisors are free. vmware, microsoft hyperv, for example are free.

Most hypervisors are free. vmware, microsoft hyperv, for example are free.

From what I remember of the intel advisory that remixedcat posted, it effects hyperV, virtualbox and nearly every other VM system except vmware.

I actually meant to say open source, not free, but either way, that exploit is obviously much more complex than I originally thought. Judging from what I read, it looks like everyone has it patched by now though.

It really depends what your host's AV can do. I know at a vmware class I was at last week, they have antivirus plugins (vSphere 5.1) at the hypervisor level which scan and monitor the VMs instead of clients on each VM. Why? To prevent scan storms... you know, when all your VMs suddenly decide to run antivirus scans at the same time and murder your storage and performance... yea.

From what I remember of the intel advisory that remixedcat posted, it effects hyperV, virtualbox and nearly every other VM system except vmware.

VMWare isn't immune from host->VM viruses, however: https://blogs.vmware.com/workstation/2012/08/crisis-virus-attempts-to-infect-vmware-workstation-or-player-virtual-machines-on-windows.html

Hello,

Yes. You could download a file over a connection the host OS doesn't scan (SSL) and then would be unable to scan the guest OS for malware from the host OS. It would essentially be a "black box" in terms of the host OS not being able to scan inside of it for threats.

Regards,

Aryeh Goretsky

More or less proper system and network configuration, firewall, access control and safe browsing practices over antivirus cascade every day.

Antiviruses are reactive measures - a virus must already be inside the system to be detected by one. If there is such a hole, however, anything else can get in, given time.

I upgraded from ESXi 5.0 to 5.1 yesterday and ironically there's an interesting section in the upgrade guide about some modular AV for guests and the host machine, not sure if you need the paid version or just free but it might do exactly as you want, http://www.vmware.com/files/pdf/products/vsphere/vmware-what-is-new-vsphere51.pdf

? VMware vShield EndpointTM ? Delivers a proven endpoint security solution to any workload with an approach that is simplified, efficient, and cloud-aware. vShield Endpoint enables 3rd party endpoint security solutions to eliminate the agent footprint from the virtual machines, offload intelligence to a security virtual appliance, and run scans with minimal impact.

Remixedcat will know more about it.

^ you can run endpoint shield vm on esxi - but you can not do it for free. In a nutshell the guest vms hand off the work of scanning and such to a different VM. A central point for all your vms antivirus/malware scanning.

You then only need to update 1 location for new signatures/dats - and work is done on 1 vm vs every vm having to use resources to scan, etc.

post-14624-0-93543300-1351525213.jpg

This is not something you would normally have available in a "home" lab sort of setup. But if you have budget, and you have enough vms then it does make sense to go this route.

But I do believe that the agent is now part of 5.1 (free) so I guess if you had a FREE dedicated VM appliance that would do the scanning you could do it for free? I would also assume you need vcenter, the few companies I looked at that supply appliances, etc. State you need vcenter - which is not free again.

Sandbox ,which protect your host from virus.A sandbox is use for separating two programs , so that one cannot affect the other. It's a form of security for when there is uncertainty of one program's effect on the other. :)

NO! People assume a sandbox protects them well NO! IT DOES NOT!

Sandbox traps calls and emulates functions, but if someone wants to bypass it then they can and will.

Here's one that targets sandboxie for example http://www.wilderssecurity.com/showthread.php?t=251456

It's good practise to use but do NOT assume it gives you 100% protection or any kind of protection.

This topic is now closed to further replies.
  • Posts

    • foobar2000 2.25.10 by Razvan Serea foobar2000 is an advanced freeware audio player for the Windows platform. It features the simplest, most minimalistic interface you'll ever see in this kind of program. Other features include full unicode support, ReplayGain support and native support for several popular audio formats. foobar2000 features: Supported audio formats: MP3, MP4, AAC, CD Audio, WMA, Vorbis, FLAC, WavPack, WAV, AIFF, Musepack, Speex, AU, SND... and more with additional components. Gapless playback. Full unicode support. Easily customizable user interface layout. Advanced tagging capabilities. Support for ripping Audio CDs as well as transcoding all supported audio formats using the Converter component. Full ReplayGain support. Customizable keyboard shortcuts. Open component architecture allowing third-party developers to extend functionality of the player foobar2000 2.25.10 changelog: Improved implementation of built-in UPnP Media Renderer, implemented gapless playback compatible with popular UPnP control apps. Enabled discovery of OpenHome UPnP devices as output devices. Enabled TLS v1.3 encryption for HTTPS connections. Fixed Ogg/Opus files with single chapter not showing correct track numbers. Fixed Direct2D visualizations getting stuck after GPU driver reinitialization. Updated 7-Zip library to 26.01. Updated UnRAR library to 7.2.6. Download: foobar2000 64-bit | 7.3 MB (Freeware) Download: foobar2000 32-bit | 6.4 MB Links: Home Page | foobar2000 for Mac | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Pick up Babbel Language Learning lifetime subscription at 47% off with code by Steven Parker Learn all 14 languages and access more than 10,000 hours of high-quality language education online. Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can pick up a lifetime subscription to Babbel Language Learning at 47% off. Note: Available to U.S. customers & NEW users only. Learn Spanish, French, Italian, German, and many more languages with Babbel, the #1 top-grossing language-learning app in the world. Developed by over 100 expert linguists, Babbel is helping millions of people speak a new language quickly and with confidence. After just one month, you will be able to speak confidently about practical topics, such as transportation, dining, shopping, directions, making friends and socializing and much more! Get lifetime access to learn all 14 languages Practice with 10-15 minute bite-sized lessons that fit conveniently into your schedule Cover a wide range of useful real-life topics, from travel to family, business, food & more Use speech recognition technology to keep your pronunciation on point Learn at a variety of skill levels, from beginner to advanced Get personalized review sessions to reinforce what you learn so it really sticks Study whenever & wherever you want and your progress will be synchronized across your devices Use offline mode to access courses, lessons & review items when not on Wi-Fi—just download them beforehand Languages Available: Spanish (Spain), German, Italian, French, Portuguese, Swedish, Turkish, Dutch, Polish, Indonesian, Norwegian, Danish, Russian, Spanish (Latin America) Good to know Length of access: lifetime Valid for New Users in the USA Only Redemption deadline: redeem your code within 30 days of purchase Please note redemption is required via Web Browser. Access to the mobile app will be available after redemption has been completed via web browser Max number of devices: Unlimited Access options: desktop & mobile Number of languages: 14 (all current languages) Updates included Babbel Language Learning: Lifetime Subscription (All Languages) normally costs $299, but you can pick it up for just $159 for a limited time - that represents a saving of $140. For a full description, specs, and license info, click the link below. Deal Price $159.00 with code LEARN (was $299) NOTE: For NEW users in the US only. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • AltSendme 0.4.2 is out.
    • Simple answer is yes, you will still get the Windows updates and as long as browser is up to date, you will be good. Only thing secure boot does is protect you against boot level threats and make it harder to install other OS's. I've been looking into this pretty thoroughly lately myself as wifes computer has secure boot disabled plus my other, older computers that run Linux, don't have secure boot enabled. Have seen all kinds of questions about this on the Linux Mint and MX Linux forums. Just don't suddenly enable secure boot now.
    • How many other companies will follow Ford's lead? Or, have they already gotten lazy and become enslaved to AI--and now can't figure out how to get out of that mess.
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      494
    2. 2
      +Edouard
      225
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      75
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!