Whonix KVM dnsmasq - listen port on host operating system - attack surface reduction

Added pull requests for internal and external:

How to modify the xml and make it work:

Whonix-External:

  • Edit Whonix-External.xml and add <dns enable="no"/> line there:

sudo virsh net-edit Whonix-External

  • Define network Whonix-External with the new changes:

sudo virsh net-define /etc/libvirt/qemu/networks/Whonix-External.xml

  • Restart Whonix-External by Stoping and Starting it:

sudo virsh net-destroy Whonix-External

sudo virsh ne-start Whonix-External

Do the same steps for Whonix-Internal.

1 Like