Now to add complexity to this question, could websites go beyond VMware and see any information beyond that?
I ask only because when you have bridged a network etc. on a VM, even smart viruses cant go beyond the VM and into the main computer. In other words, it not really a 'sandbox'.
The complete step-by-step guide to get back to selling today!
I've heard viruses can infect VMware and get on to the host. I'm using a Mac, running Windows 7, and I use the isolated selection on VMware. So I guess if a really good programmer wants to write a program that executes in Windows 7, then can also execute in a Mac, that would be some really hard work.
Now to add complexity to this question, could websites go beyond VMware and see any information beyond that?
I ask only because when you have bridged a network etc. on a VM, even smart viruses cant go beyond the VM and into the main computer. In other words, it not really a 'sandbox'.
That's improbable. Even if that's possible, it must be some multi-level exploit. I don't believe any non-shady website (e.g. amazon, ebay and such) would ever employ such techniques even if they were possible
I've heard viruses can infect VMware and get on to the host. I'm using a Mac, running Windows 7, and I use the isolated selection on VMware. So I guess if a really good programmer wants to write a program that executes in Windows 7, then can also execute in a Mac, that would be some really hard work.
In "theory" VMs are "isolated" because they are being virtualized, but anything is possible in the world of computer if vulnerability is found. Programming is done by humans, humans have flaws. It's a matter of finding them.
That's improbable. Even if that's possible, it must be some multi-level exploit. I don't believe any non-shady website (e.g. amazon, ebay and such) would ever employ such techniques even if they were possible
Never say nothing is possible. Anything is possible. Just because you don't know about it or might think another way doesn't make it untrue..
The Following User Says Thank You to empirestate For This Useful Post:
i think all these are just client side scripts which the server aint aware of, you ONLY the client side see these informations not the websites you visit , the only thing which the website knows about you is your IP plus the user Agent data like these
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.36 Safari/535.7
if you only visit that site and switch to console view you will see its only java script code running ,and you will notice some errors due to deprecated functions.
Never say nothing is possible. Anything is possible. Just because you don't know about it or might think another way doesn't make it untrue..
I never said it was impossible. I said even if such vulnerabilities existed, Amazon and similar websites exploiting them would be an unlikely (improbable) event.
im no expert on vmware but i would say tha yes anything can be done.
your vmware im certain it could be infected if someone wanted to go that far. i dont know that the technology exists or not but i would err on the side of caution and say that yes it certainly is possible.
my fav is 'ask to activate' flash setting, UA control add-on, to amend user string - I do not use much else.....I check on panopticklick to check what is showing and nothing much is....well except for resolution....
when I use mobile wifi, whatsmyip can never pinpoint me...but on my home wifi - it hovers over my block.....
FMI - what is no-script going to block in reality? I'm talking about on a fresh windows user per acc, with not much running...
my fav is 'ask to activate' flash setting, UA control add-on, to amend user string - I do not use much else.....I check on panopticklick to check what is showing and nothing much is....well except for resolution....
when I use mobile wifi, whatsmyip can never pinpoint me...but on my home wifi - it hovers over my block.....
FMI - what is no-script going to block in reality? I'm talking about on a fresh windows user per acc, with not much running...
If im not mistaken, no script blocks the scripts which could potentially find your mac address.
Personally I use VMware + noscript + prevent webrtc leak + 24vc (few accounts)...
Some may say I go too extreme... but then again I hardly ever lose my accounts.
i think all these are just client side scripts which the server aint aware of, you ONLY the client side see these informations not the websites you visit , the only thing which the website knows about you is your IP plus the user Agent data like these
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.36 Safari/535.7
if you only visit that site and switch to console view you will see its only java script code running ,and you will notice some errors due to deprecated functions.
If the data can be displayed on screen it can be stored by the host and used against you.