linux isnt immune to viruses even though its not as bad as windows
what should i do to be safe if i have a safe browser, vm, but pirate and download risky things? i know its a vm but i still dont want to have to delete everything in the vm if something happens. also the malware doesnt go to the router and spread rigt???


Take regular VM snapshots and never forget that exploits can breach the VM
very rare for exploits that can breach a VM. Like once-every-10-years kind of rare.
One important thing to be aware of. By default your VM will have access to the same network resources as the host. So, say, if you use tailscale or some other secure VPN to protect your NAS, but you give your host access, the VM will be able to access it too! You can use firewall rules or bridge networking to fix this, but tbh it isn’t trivial.
Depends on your VM. qemu, by default, isolates each VM on a subnet. It’s a PITA when you actually need the VM to be able to see the LAN.
It’s been a while since I’ve tested the defaults, but if your VM has internet access it would also have access to the LAN right? From the perspective of the VM it’s all the same, just sending requests to the router. Unless QEMU specifically blocks requests to LAN network ranges.
I’m not sure what the mechanism is, but I discovered the issue by empirical testing a few months ago, and I’m still trying to sort it out and make the LAN visible to that VM. Granted, I haven’t been able to put much time into it, but I keep ending up down among the weeds of iptables/nftables, with all the documentation either out of date or not intended for a host using netifrc for network management (or both). I’ll probably have to ask on the Gentoo boards eventually.
what do u do to stop it (before it happens) tho??
Don’t download shady shit
but i wanaaaaa (((((
Rather, malware detect the vm, assume a security lab testing environment and hold still. Don’t take that stuff outside.