VirtualBox

Changeset 38666 in vbox for trunk/doc


Ignore:
Timestamp:
Sep 6, 2011 4:39:38 PM (13 years ago)
Author:
vboxsync
Message:

doc/manual: language changes

Location:
trunk/doc/manual/en_US
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/doc/manual/en_US/user_GuestAdditions.xml

    r38662 r38666  
    11851185            linkend="generalsettings" />).<note>
    11861186            <para>
    1187               Enabling 3D acceleration may expose security holes to malicious
    1188               software running in the guest. The 3D host graphics drivers
    1189               are often known to contain bugs and might crash with certain
    1190               operations. VirtualBox is not hardened enough to prevent every
    1191               risky 3D operation on the host. But a VirtualBox guest can not induce
    1192               any more harm to the host than any other malicious host application
    1193               using the 3D graphics API.
     1187              Untrusted guest systems should not be allowed to use
     1188              VirtualBox's 3D acceleration features, just as untrusted host
     1189              software should not be allowed to use 3D acceleration.  Drivers
     1190              for 3D hardware are generally too complex to be made properly
     1191              secure and any software which is allowed to access them may be
     1192              able able to compromise the operating system running them.  In
     1193              addition, enabling 3D acceleration gives the guest direct access
     1194              to a large body of additional program code in the VirtualBox
     1195              host process which it might conceivably be able to use to crash
     1196              the virtual machine.
    11941197            </para>
    11951198            </note></para>
  • trunk/doc/manual/en_US/user_Security.xml

    r38665 r38666  
    100100    </para>
    101101    <para>
    102       On Windows hosts, the installer allows to disable USB support, support
     102      On Windows hosts, the installer allows for disabling USB support, support
    103103      for bridged networking, support for host-only networking and the Python
    104104      language bindings, see <xref linkend="installation_windows"/>.
     
    106106      of them could be appropriate if the corresponding functionality is not
    107107      required by any virtual machine. The Python language bindings are only
    108       required if the VirtualBox API should be used by external Python
     108      required if the VirtualBox API is to be used by external Python
    109109      applications. In particular USB support and support
    110       for the two networking modes induce the installation of Windows kernel
    111       drivers at the host. Therefore disabling those selected features can
    112       not only be used to restrict the user to a certain functionality but
    113       also to minimize the surfaces provided to a potential attacker.     </para>
    114     <para>
    115       The regular case is to install the complete VirtualBox package. The
     110      for the two networking modes require the installation of Windows kernel
     111      drivers on the host. Therefore disabling those selected features can
     112      not only be used to restrict the user to certain functionality but
     113      also to minimize the surface provided to a potential attacker.     </para>
     114    <para>
     115      The general case is to install the complete VirtualBox package. The
    116116      installation must be done with system privileges. All VirtualBox binaries
    117117      should be executed as a regular user and never as a privileged user.
     
    122122      <xref linkend="intro-installing"/>. As for the base package, the SHA256
    123123      checksum of the extension pack should be verified. As the installation
    124       requires system privileges, the VirtualBox GUI will ask for the system
     124      requires system privileges, VirtualBox will ask for the system
    125125      password during the installation of the extension pack.
    126126    </para>
     
    317317          which the data is transferred could therefore intercept that
    318318          data. An SSH tunnel could be used to secure the connection between
    319           the two host. But when considering to teleport a VM over an untrusted
     319          the two hosts. But when considering teleporting a VM over an untrusted
    320320          network the first question to answer is how both VMs can securely
    321321          access the same virtual disk image(s) with a reasonable performance. </para>
Note: See TracChangeset for help on using the changeset viewer.

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette