Sandbox security threat with VMWare Workstation 6


Recommended Posts

Hi. This is my situation. On the same pc, I would like to do some Internet banking but son want to use it to play games and go to questionable website. Security wise, these 2 things do not mix and that got me thinking about VMWare virtual pc. And very much appreciate experience VMWare users? advise on this.

Can I set up a virtual pc and let my son uses that? And any securities threats will be sand boxed in VM virtual pc and not infest the host pc?

Alternatively, can I set up a virtual pc and I use that to do my banking stuff and any virus in the host pc will not get into?

I have some doubt about this because I tried setting up a virtual pc for the very 1st time and found I could drag & drop files from the host to the virtual pc and vice versa at ease. If files could move so easily between host and guest, couldn?t virus do the same?

Thanks.

The only reason you could move files between the host and guest so easy, is you setup that feature in vmware workstation.

So playing games -- that he bought from a store? You feel is a security issue?

As to questionable websites? Have him sandbox any connections he makes to "questionable" websites http://www.sandboxie.com/

Playing "games" in a vmware normally is a huge performance hit on the game, the newer games require as much of the computers cpu and memory and video card to play the game as it was meant to be played... Trying to run it in a vm is going to be a hit on that performance.

Thank you BudMan,

This Sandboxie looks perfect for the job.

Assuming my host pc is infested with virus or malware or keylogger. If I go open up a sandbox and do my internet banking stuff inside it, would security be compromised? i.e., nothing comes out or go into the sandbox from the host pc.

Thank you.

I would assume if the host pc has a key logger installed it?s still going to log whatever you type in as your keystrokes are been logged before they even get to the sandbox application.

You could always boot a Linux live cd such as Ubuntu and do your banking like that, this way you know you will be virus free and any sensitive information you enter will be erased once you power the pc down as it will all be saved in the ram.

Hi. I was wondering, how to do the proper setup
What do you mean "proper" You either allow for sharing files between host and guest or you do not.. Either way would be proper.

The use of the sandbox would be so your box does not get compromised, not for use on a compromised system, etc.

If you are so worried that your box is infected with keyloggers and such -- heres an idea, clean it!

Is this paranoia medically induced, or is your tinfoil hat just a bit loose? If you feel your box has been compromised -- then freaking nuke it from orbit and start over..

If your so worried your son will get your machine infected -- then don't let him use it!

Booting a liveCD every time you want to look at the balance of your checkbook or pay a bill seems a bit over the top if you ask me. Its not like this is a public computer or anything -- just take steps to make sure its clean and practice safe computing, and tighten up your tinfoil hat and you will be fine ;)

because it is questionable with sandboxie and vmware for elminating viruses, spyware, trojans, keyloggers....it's skeptible if both use the same OS...the banking host must be locked down but at what cost?

this is where an old laptop comes in useful....for banking/accounting and nothing else...

I have created a vm virtual pc. I have disabled "Shared Folder", disabled Guest Isolation (so there will be no dragging of file from host to guest and vice versa). But I have trouble setting Ethernet to Bridged mode. So I am using NAT instead. Would there be any security compromises in this area?

My son likes to go watch TV programs and movies at sites like www.pipifilm.com or www.xunlei.com or www.ppstream.com

Friends who have been to those sites told me they get fed up with viruses and nasty stuffs coming in after watching those programs. Hence my concerns. So either surf those sites in virtual pc or do online banking in virtual pc.

Any advise appreciated.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • HOLY THREAD REVIVAL   But yes, look for browser.nova.enabled and set it to true
    • 5-year subscription to AdGuard VPN price-dropped now 90% off by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can save 88% off a 5-year subscription to AdGuard VPN. In the digital age where internet privacy is paramount, AdGuard VPN emerges as an essential tool. This virtual private network (VPN) is your encrypted gateway to the internet, helping your data stay secure and your online activities remain private, regardless of your location. More than just a privacy tool, AdGuard VPN is a robust solution packed with features that cater to a variety of internet needs. Why AdGuard VPN subscription deal over other VPNs: Exhaustive List of Locations: With 60+ locations available worldwide, you have the freedom to connect from anywhere you want, effectively bypassing geographically restricted content. Check complete list of servers here. Advanced Security Protocol: AdGuard VPN uses its own security protocol, guaranteeing a faster and safer VPN connection. This means you can browse, stream, and download with peace of mind knowing your data is secure. Zero-Logging Policy: Rest assured, your personal data is not collected and your internet traffic stays private at all times, thanks to AdGuard's strict zero-logging policy. Simultaneous Connections: Connect up to 10 devices simultaneously, providing protection for all your devices under just one account. Trusted Developer: AdGuard is a renowned name in the world of computer security, bringing their expertise and commitment to privacy and security to their VPN service. What You Get: Up to 10 devices connected simultaneously All locations Light-speed servers Unlimited data No logs policy Trusted developer Available on all platforms Privacy Created by a team from Russia, AdGuard software Limited is headquartered in Limassol, Cyprus. While the country does follow European privacy laws, it's not part of the 5/9/14 Eyes Alliance. Adguard may not properly work in China. Good to know Length of access: 5 years This plan is only available to new users Redemption deadline: redeem your code within 30 days of purchase Device per license: 10 Access options: desktop & mobile Updates included 5- years of AdGuard VPN normally costs $359.40 without discounts, but it can be yours just $39.97, that's a saving of $324.43 (90%) off. For full terms, specifications, and license info please click the link below. Get this 5-year AdGuard VPN deal for just $34.97 (was $359.40) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • KillerPDF 1.5.1 by Razvan Serea KillerPDF is a lightweight, portable PDF editor for Windows built for users who want full control without subscriptions, installers, or telemetry. It runs as a single executable, making it ideal for USB use and field work. You can view PDFs with smooth PDFium rendering, navigate quickly with thumbnails, zoom, and shortcuts, and reorganize pages using drag-and-drop. It supports merging multiple PDFs, splitting documents, and extracting selected pages. KillerPDF also allows inline text editing with font matching to preserve the original layout, plus annotations like text boxes, freehand drawing, highlights, and reusable signatures. You can search full text, copy content easily, and print documents with flattened annotations. Designed as a free and open alternative to bloated PDF tools, it works fully offline on Windows 10/11 x64. No runtimes install. Everything needed is inside the EXE (targets .NET Framework 4.8, which ships with every supported Windows release). KillerPDF key features: High-quality PDF rendering via PDFium Edit PDF text inline (double-click to modify text) Page thumbnails and fast navigation with zoom and shortcuts Merge multiple PDFs into one Split PDFs and extract selected pages Drag-and-drop page reordering Font matching to preserve original document appearance Text boxes for notes Freehand drawing tools Highlight overlays with adjustable color, size, opacity Undo actions and clear per-page annotations Create, draw, and save reusable signatures Click-to-place signatures anywhere Full-text search with highlighted results Drag-select or Ctrl+A to copy text Print with annotations flattened Portable single-file app (~10 MB) No installer, no admin rights required No account, no telemetry KillerPDF 1.5.1 changelog: Performance Save Flattened PDF now uses multiple CPU cores. Page rasterization is parallelized (PNG encoding runs across cores; the PDFium render step stays serialized since the library isn't thread-safe), so large documents flatten significantly faster while the UI stays responsive (#68). Fixed PDFs that failed to open with "Unexpected EOF" now open (#72). The failure was PdfSharpCore's Flate inflater (SharpZipLib) rejecting the FlateDecode cross-reference stream on multi-revision PDFs - files that open fine in browsers, Acrobat, and Foxit. KillerPDF now detects this and re-opens the file losslessly through PDFium, preserving selectable text. Thanks to @javajon for the report and a detailed reproduction. Grid view renders every page. It was capped at the first 26 pages, so longer documents stopped loading partway through. Tiles also stream in progressively now instead of blocking until the whole document is rendered. Grid Ctrl+Scroll no longer reloads every page when the zoom is already at its limit and nothing would change. Removed a stray horizontal scrollbar (a thin green line) that could appear across the bottom of grid view. Files on UNC / network shares (including the WSL \\wsl$ filesystem) are copied locally before opening, avoiding partial-read failures on network filesystems. Changed Minimum zoom lowered from 10% to 5%, so grid view can pack more columns (helpful for wide/landscape pages) and single-page view can zoom out further. Download: KillerPDF 1.5.1 | 6.3 MB (Open Source) Link: KillerPDF Home Page | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • You can enable the Nova redesign in Firefox 152 stable, under about:config.
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      520
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      111
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!