• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Use VM to sandbox browser?

cditty

Limp Gawd
Joined
Apr 12, 2001
Messages
504
Hi all.

I am trying to setup internet browsing on an important system in my office. I need to trap the browser, so that it can't do any damage to the host. Can I simply put a wireless NIC in the machine and let the VM connect to my wireless DMZ with all the shares off?

My thought is to still run a restricted browser environment, but just in case, have it sandboxed so that the worst case scenario is that I recopy a vhd if they get malware, etc?

Will what I am proposing work? Do any of you have a better idea you would like to share?

Any and all input is welcome.

Thanks.
 
Ultimate goal?
While I don't understand why you would want to put it in the DMZ,
your overall concept should work - no problem.

You running a honeypot?

If you just want "safer" browsing ... you could get a "LiveCD"
and throw it in a PC without any writeable storage.
 
Ultimate goal is this:

I have an audio workstation in each of my radio studios. It is used for recording phone bits, etc... It also needs to be able to get on Facebook, etc... for our social media initiative. I want to make the browsing experience as safe as I can to the rest of the network. I can't pull them off of my primary audio network, because I have vital apps that need access to my audio servers.

I want to try to greatly reduce the malware risk. I have a Ubuntu vhd that I made a while back. I was going to put a separate NIC in the machines and give it to the VM. The host NIC would still have extremely restricted Net access, but the VM would have a more liberal selection.
 
Back
Top