Possible data leak via Ethernet
Posted: 27. Feb 2014, 12:47
I'm using Windows guests (XP Pro 32 and 7 Pro 64) on a Mac host. I've just upgraded from Snow Leopard to Mavericks and noticed something new that may be a security problem.
When I transfer data between the host and a guest via network shares, in either direction, the Mac's physical Ethernet socket becomes busy. The Mac is connected to an Ethernet network switch and this confirms activity on the connection. No other connection on the switch is active, so the data flow is not travelling beyond the switch, in my case. Monitoring software that I've long been using on the Mac shows data flowing out of the Mac, but not in, at the same rate at which data is being internally transferred.
Promiscuous mode is set to Deny. I can think of no good reason why internal network traffic should now be being copied to the external Ethernet socket. I know that Apple changed their networking code after Snow Leopard, so I'm guessing that this is related to that.
All software is fully patched and up-to-date, such as VirtualBox 4.3.8 and OS X 10.9.2 .
Has anyone else noticed external network activity during internal network transfers? Any suggestions for how I stop this?
When I transfer data between the host and a guest via network shares, in either direction, the Mac's physical Ethernet socket becomes busy. The Mac is connected to an Ethernet network switch and this confirms activity on the connection. No other connection on the switch is active, so the data flow is not travelling beyond the switch, in my case. Monitoring software that I've long been using on the Mac shows data flowing out of the Mac, but not in, at the same rate at which data is being internally transferred.
Promiscuous mode is set to Deny. I can think of no good reason why internal network traffic should now be being copied to the external Ethernet socket. I know that Apple changed their networking code after Snow Leopard, so I'm guessing that this is related to that.
All software is fully patched and up-to-date, such as VirtualBox 4.3.8 and OS X 10.9.2 .
Has anyone else noticed external network activity during internal network transfers? Any suggestions for how I stop this?
| Edit: I forgot to mention that I'm using bridged mode and paravirtualisation. [Edit2]This bug is now acknowledged and being worked on. |