realbasic-nug
[Top] [All Lists]

Re: ClamXav & REALbasic - trojans?

To: REALbasic NUG <realbasic-nug@lists.realsoftware.com>
Subject: Re: ClamXav & REALbasic - trojans?
From: Bart Silverstrim <bsilver@chrononomicon.com>
Date: Mon, 29 Dec 2008 13:51:32 -0500
Authentication-results: mx.google.com; spf=neutral (google.com: 74.124.194.228 is neither permitted nor denied by best guess record for domain of realbasic-nug-bounces@lists.realsoftware.com) smtp.mail=realbasic-nug-bounces@lists.realsoftware.com
Delivered-to: listarchive@realsoftware.com
In-reply-to: <3FD6BD56-9895-423A-A31E-C2C2354B6952@mac.com>
References: <C57EB496.52399%markus_winter@online.de> <C4AC60B2-15C2-40FE-B68F-015477F0FC3A@mac.com> <495913B1.8070109@chrononomicon.com> <B0141D75-8A0B-4D90-8065-72EB29C60134@mac.com> <495917FC.7080108@chrononomicon.com> <3FD6BD56-9895-423A-A31E-C2C2354B6952@mac.com>
Reply-to: REALbasic NUG <realbasic-nug@lists.realsoftware.com>
Sender: realbasic-nug-bounces@lists.realsoftware.com
User-agent: Thunderbird 2.0.0.18 (X11/20081125)


Arnaud Nicolet wrote:
Le 29 déc. 08 à 19:33 (soir), Bart Silverstrim a écrit:

I was pointing out one reason why it wouldn't happen. With most VM systems you have it sandboxed to a degree...there's no reason to expose the Applications folder to a Windows VM on the Mac. Those files are useless to the virtual machine guest.

Well, there's an option to just share the entire startup disk. Many users may share it to avoid asking themselves what to share in case of multiple folders needed to be shared (sometimes humans prefer the easier way, sadly).

Haven't used Parallels, but I'd believe it. Have used VMWare, Virtalbox, and a few others. They didn't share an entire startup disk...silly option.

If he shared and/or exposed the entire filesystem to the Windows guest, then in my opinion it's asking for problems. But the malware still would be scratching its' head at most of the filesystem peculiarities it would encounter with a shared drive, it would be limited to infecting just what it knows how to infect via (probably) cifs, the file sharing protocol. The raw filesystem would not work with the guest.

Hmm... I think the share is "converted" in FAT32 (otherwise, the guest OS wouldn't be allowed to write).

Again, haven't used it, but doubt that...if it is, it's lying to the VM. Fat32 isn't anything like HFS...

The implementations I have seen normally used CIFS (windows sharing protocol) which does allow read and write permissions.

_______________________________________________
Unsubscribe or switch delivery mode:
<http://www.realsoftware.com/support/listmanager/>

Search the archives:
<http://support.realsoftware.com/listarchives/lists.html>


<Prev in Thread] Current Thread [Next in Thread>