Recommended Posts

Ok... I got your point.. :)

If virtual machine has no network for access to your host,your host won't get affect by any virus in your guest operating system. :)

What? You're thinking of trojans, viruses don't need internet/network connections to operate.

His point was that if the guest can not access host via network, then its not possible to jump from guest to host. Which is true - guest unless setup has no access to host file system, so if no network access it should not be possible for infection to jump from guest to host.

Unless person with access to host filesystem exe something off guest file system.

His point was that if the guest can not access host via network, then its not possible to jump from guest to host. Which is true - guest unless setup has no access to host file system, so if no network access it should not be possible for infection to jump from guest to host.

Unless person with access to host filesystem exe something off guest file system.

No it's not true, viruses can exploit sandbox/VM things which is why recently as I said on the other page that hyperV, virtualbox, and all the other large-scale VM solutions with the exception of VMware had an exploit leaked that will pass from the guest to the host no problem. You've also got bugs in CPUs that can allow exploits too.

And that is a RARE specific exploit - I run vmware esxi, I have not heard of any guest to host exploits?

Could you link to these exploits from guest to host?

And along with I normally run antivirus on my windows guests. And when I use that to access questionable locations or files, I have a snapshot taken before and after done just rollback to before.

I agree no system is going to be 100% fullproof - but the odds of moving from guest to host has got to be rare. My point was that if the vm has network access or shared access to the host filesystem, then sure it would be easy for something to jump to another box on the network if a worm and other boxes are open to it, and or if guest has write access to host filesystem it could infect/encrypt/delete/etc files on the host filesystem.

Ok - 2nd one is dos attack, not a guest-host escape

"This is a denial of service vulnerability. An attacker who exploited this vulnerability could cause the affected Hyper-V server to stop responding, requiring a restart. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights on the Hyper-V server, but it could cause the affected system to stop accepting requests."

3rd one again is talking about dos, not escape.

Again not saying they don't exist - there was Cloudburst back in 2009. But do you know of any active guest-host escapes in the wild? Other than whitepapers discussing the possibility?

Are you aware of any malware/extortionware/virus that uses such complicated exploits?

Again I will agree that nothing is 100% secure, and yes there always going to be security issues that need to be addressed. But it comes down to is the exploit in the wild? Is it something that you surfing the underbelly of the net, or driveby or even running some keygen or hacked game or application is going to be infecting your machine and jumping to your host?

I would be more concerned with running bad code (worm) that then could then seek out your other vms or physical or even host machine via network than a guest-host escape.

Generally speaking, not talking a targeted attack against your infrastructure - some paid hacker getting into a company through a vm that is exposed to the public net, etc. Just generally speaking its unlikely to have to be worried about a guest-host escape no matter what your running be it virtualbox, vmware workstation (type2) or something like esxi/xen/kvm (type1).

Should you be aware that such things can exist - sure! If your tinfoil hat is a bit tight, maybe you don't run the vm tools on your vm - this is generally going to be the attack vector currently. Must of the stuff I have seen has been against intel, so run amd cpus on your host ;)

But common sense would tell you not to allow your VMs to have rw to your host filesystem via vm sharing tools or setup, etc. And if your playing with bad code - you might want to isolate their network connectivity to the rest of your vms/host/local network.

I don't know of any publically available viruses that utilise it no, but the reason for that is because the people that know about these security flaws will be governments and incredibly sophisticated hackers, they won't be telling OEMs about them nor releasing POCs about them either but will use them discreetly in the shadows without anyone knowing.

"about these security flaws will be governments and incredibly sophisticated hackers"

So you think a virus scanner you got from mcafee or nod or whatever is going to protect against a government backed attack?

So as I was saying, generally speaking guest-host escapes is not something the general user base - say running some vms on my home lab box for example needs to be worried about protecting against. Other than making sure your VM software be it type1 or 2 is updated, and host os are patched and securely configured.

And in this context you could be pretty sure that this form of exploit is not going to be used when you download that keygen or hacked exe of some game or application or surf the dark underbelly of the net. What you should be concerned with is more that you can roll the vm back after you play with something like that. Or that the box does not become infected with the lastest worm that could infect your other vms/local network.

I think we are the same page yes?

Hello,

There was a discussion not too long ago of the Windows version of OSX/Crisis infecting virtual machines, and I though the Koobface malware contained an exploit for VMware that allowed it to escape from the guest OS to the host OS, but I cannot seem to find an exact reference to it. I think this would have been around 2009-2010, though.

Regards,

Aryeh Goretsky

The recent one was fine if you use vmware, it was not vulnerable.

Here's some links to things about the bugs;

http://www.aidanfinn.com/?p=12837

http://technet.micro...lletin/ms11-047

http://blog.coresecu...ploit-ms10-102/

Hello,

I am unsure of why McAfee or ESET of any of the other anti-malware programs would not protect you. They detect various pieces of malware such as ACAD/Medre, OSX/Lamadai, Win32/Duqu, Win32/Flamer, Win32/Georbot, Win32/R2D2 and Win32/Stuxnet which are generally acknowledged to be created (or tacitly approved by) various nation-states around the globe.

While it seems ludicrous that an anti-malware company might be fettered by the intelligence apparatus of the country in which it is headquartered, even if you were not to rule that out of hand, there are anti-malware companies located in countries around the world that are mutually antagonistic towards each other, and I could see a Chinese or a Russian anti-malware company treating malware created by an American or European government as a PR goldmine. The truth of the matter, though, is that governments are going to be pretty unlikely to inform anti-malware companies of malware they have developed or are using, since that violates the whole point of using malware in the first place: Plausible deniability.

Regards,

Aryeh Goretsky

"about these security flaws will be governments and incredibly sophisticated hackers"

So you think a virus scanner you got from mcafee or nod or whatever is going to protect against a government backed attack?

So as I was saying, generally speaking guest-host escapes is not something the general user base - say running some vms on my home lab box for example needs to be worried about protecting against. Other than making sure your VM software be it type1 or 2 is updated, and host os are patched and securely configured.

And in this context you could be pretty sure that this form of exploit is not going to be used when you download that keygen or hacked exe of some game or application or surf the dark underbelly of the net. What you should be concerned with is more that you can roll the vm back after you play with something like that. Or that the box does not become infected with the lastest worm that could infect your other vms/local network.

I think we are the same page yes?

This topic is now closed to further replies.
  • Posts

    • Flameshot 14.0 Final by Razvan Serea Flameshot is a free and open-source, cross-platform tool to take screenshots with many built-in features to save you time. Using Flameshot is as simple as launching, dragging the selection box to cover the area you want to capture, making annotations as needed in on-screen and saving the shot to your computer, all with a very simple and straightforward interface. Flameshot allows users to simply upload their screenshots directly to the cloud in order to easily share it with others. You can upload your image directly to Imgur with a single click and share the URL with others. In-app screenshot editing - You can choose to add an arrow mark, highlight text, blur a section (blur or pixelate an area), add a text, draw something, add a rectangular/circular shaped border, add an incrementing counter number, and add a solid color box with Flameshot's built-in editing tools. Command-line interface (CLI) - Flameshot has several commands you can use in the terminal without launching the GUI via a command line interface. The command line interface lets you script Flameshot and use it as the subject of key binds. Flameshot 14.0 release notes: This release brings major improvements to multi-monitor support, fractional scaling support, new capture workflows, and a long list of bug fixes across all platforms. Changelog: New Multi-Monitor Capture Workflow New monitor selection screen before capture for better multi-monitor and mixed-scaling support. Option to auto-capture the monitor under the cursor (X11 & Windows). Tray menu can directly select a monitor. Linux Improvements XDG Desktop Portal is now the primary screenshot method. Added legacy X11 fallback option for minimal window managers. New D-Bus capture API for scripting and automation. Windows Enhancements Global screenshot hotkeys now supported (not limited to Print Screen). New portable mode stores settings next to the executable. Clipboard now always uses PNG format for better compatibility. CLI & Platform Updates Redesigned flameshot screen command with per-monitor capture support. Added native Nix Flake support. More compact launcher UI and improved update notifications. Major Fixes Multiple Wayland stability fixes, including KDE Plasma crash fixes. Clipboard compatibility improvements for GNOME, Wayland, X11, Windows, and macOS. Fixed D-Bus hangs, capture crashes, and HiDPI region issues. Other Changes Dropped Ubuntu 20.04 (Focal) support. Updated translations and build infrastructure. Intel macOS builds are no longer provided. [full release notes] Download: Flameshot 14.0 | 18.1 MB (Open Source) Download: Flameshot Portable | 53.0 MB Links: Flameshot Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Helium Browser 0.13.4.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.4.1 changelog: 0a4f1149 revision: bump to 4 (#1969) 4848de1f helium/core: enable the chromium screenshot feature (#1968) e0dec3f5 onboarding: integrate strings to i18n system (#1948) 417fa5bc i18n: fix newline parsing for onboarding 7a339b39 i18n: add foraged translations for onboarding 4f090cff i18n/generate: add handling for onboarding strings bfe48d58 i18n_apply: manually override parent grd logic for onboarding strings ab214e3c onboarding: bump in deps, wire up grdp afa6a059 helium/core: disable pdf infobar feature (#1965) eba585e7 helium/ui/vertical: fix new tab button alignment and icon size (#1964) 6ecfc9e0 helium/ui/tabs: fix horizontal tab hover background color (#1963) 3db87dc0 helium/ui/tabs: fix new tab button hover/press colors (#1962) 6bbdcc3e helium/ui: improve tab group UI in all layouts (#1961) 53deb314 helium/ui/tabs: enable tab group hover cards e93aece7 helium/ui/vertical: fix tab group appearance, prevent line overlap 629f5495 helium/ui/tabs: restore solid group header colors, enable new colors 961c962e helium/ui/tabs: move horiz tab group underline to bottom, make it thick c96deab6 merge: update to chromium 149.0.7827.155 (#1959) 36db56b4 i18n: update source.gen.json 5ce006ae patches: refresh for chromium 149.0.7827.155 b4c1ea62 merge: update ungoogled-chromium to 149.0.7827.155 4e5e8671 Update to Chromium 149.0.7827.155 08a3e7da helium/ui/layout: disable mute on collapsed vertical tabs (#1778) a0a5bbaf helium/core: simplify context menu and prevent huge widths (#1951) c4732aac devutils/i18n: add forage command (#1944) 11d16986 devutils/i18n: add an option to translate using local CLI tools (#1942) d820c3a2 i18n/prompt: tighten translation rules to prevent common errors (#1940) cf827007 Update to Chromium 149.0.7827.114 6e3d5164 Update to Chromium 149.0.7827.102 Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      579
    2. 2
      +Edouard
      183
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      74
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!