I was playing and testing with some VMs using VirtualBox, when I noticed that the default (virtual) networking configuration completely bypasses the host firewall, exposing all running services to the guest VMs.

Even the services only listening in the loopback interface are accessible. 😓

At first, I thought I had done something very wrong, but no... it seems there is an old issue marked as #wontfix

https://forum.virtualbox.org/ticket/17914

You can never be too careful.

#security #virtualbox #netsec

Reply to this note

Please Login to reply.

Discussion

According to the documentation, it is the intended behavior. I'm not sure if it is a good decision.