Potential shared folder security risk?

Discussion in 'Parallels Desktop for Mac' started by [email protected], Feb 2, 2007.

  1. MuckSavage@mac.com

    [email protected] Bit poster

    Messages:
    4
    Just downloaded the latest build (3150).

    I noticed under the icon on the windows desktop "Parallels shared folder" that there are two folders. One is the shared folder I already set up (a subfolder of my user folder). The other is named ".Mac" It is basically my hard drive. Which means when I am running windows, it has full access to my entire hard drive. I know for a fact I never set it up to share my hard drive, and I can't remember seeing this folder before 3150. I also see no way of getting rid of it. Dragging it to the trash gives an error, and there is no option under shared folders to get rid of it. This seems like a huge security risk, given windows security problems. It would seem that if a vm windows has access to my entire hard drive, any windows malicious programs could potentially wipe out the OS X drive. Any thoughts?
     
  2. darkone

    darkone Forum Maven

    Messages:
    804
    already a huge thread on that here :- http://forum.parallels.com/showthread.php?t=8127

    on a side note tho, it cant comepletely destroy the osx partition as standard unix permissioning rules still apply. if only root has read or write access, then you wont be able to read or write/delete anything in that dir.
     
  3. MuckSavage@mac.com

    [email protected] Bit poster

    Messages:
    4
    Thanks for the link - did a search but didn't see the thread. Thanks!
     
  4. dkp

    dkp Forum Maven

    Messages:
    1,367
    You have to halt the VM and edit it's properties. The specific subject is shared folders, and you need to disable global sharing. Despite what you read it is entirely possible to lose all your personal data, or to have that data harvested by Windows malware. A DOS of OS X is also trivial to accomplish.
     
  5. MuckSavage@mac.com

    [email protected] Bit poster

    Messages:
    4
    Yeah, I've been reading that thread. Seems to be some misinformation in there.
     

Share This Page