Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2912945 times)

0 Members and 7 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3300 on: December 19, 2014, 02:00:00 PM »
Hacker hijacks unlocked machines through usb=device: https://github.com/samyk/usbdriveby

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3301 on: December 19, 2014, 09:01:07 PM »
Google "Goliath" versus the Content Industry news leaked out via Sony Hack: http://www.theverge.com/2014/12/12/7382287/project-goliath

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3302 on: December 20, 2014, 03:19:28 PM »
Certain parties will try disable the Tor Network within a couple of days by taking down the "drectory authorities".
Tor users will be warned when the network will be incapicitated.
Who are the alleged attackers is not known so far.
https://blog.torproject.org/blog/possible-upcoming-attempts-disable-tor-network
It is rumored however that Tor will be brought down over the weekend
and a  swoop could be related to the US government's investigation into the Sony Pictures mega-hack
or that this might be used as a pretext to take it down.

polonus

P.S. We will see things like this: ERROR: Gateway Timeout

While trying to retrieve the URL http://128.31.0.39/:

No route to host
Your cache administrator is webmaster.

Generated Sat, 20 Dec 2014 14:25:53 GMT by ::ffff:192.168.177.1 (Mikrotik HttpProxy)
Read: https://news.ycombinator.com/item?id=8774833
« Last Edit: December 20, 2014, 03:39:52 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48610
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3303 on: December 20, 2014, 05:27:56 PM »
It's The Season:


Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3304 on: December 21, 2014, 01:43:21 PM »
NTP versions not stable, not completely tested and with issues and now also found to be  exploitable.
Verdict: stop using it: https://blog.hboeck.de/archives/863-Dont-update-NTP-stop-using-it.html

In stead use: http://chrony.tuxfamily.org/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3305 on: December 23, 2014, 05:28:24 AM »
Staples Provides Update on Data Security Incident
http://staples.newshq.businesswire.com/statement
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3306 on: December 23, 2014, 10:07:25 PM »
As predicted in an earlier post in this thread: http://www.theregister.co.uk/2014/12/22/stay_away_popular_tor_exit_relays_look_raided/
Previous warning from admin: http://article.gmane.org/gmane.network.tor.user/34619
Servers have been blacklistened and form no danger now to Tor-users.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3307 on: December 25, 2014, 01:46:32 PM »
Google Safebrowsing blocked 39.000 infested WP-sites: http://blog.sucuri.net/2014/12/soaksoak-malware-compromises-100000-wordpress-websites.html
Check your site with: https://wordpress.org/plugins/sucuri-scanner/
Lots of sites became infested because the vulnerable plog-in software did not have the latest patches.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3308 on: January 03, 2015, 06:15:08 PM »
Windows: Elevation of Privilege in ahcache.sys/NtApphelpCacheControl
https://code.google.com/p/google-security-research/issues/detail?id=118
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3309 on: January 04, 2015, 01:22:15 PM »
75% of PHP installations unsafe: http://blog.ircmaxell.com/2014/12/php-install-statistics.html
blog link author = Anthony Ferrara 
Remember there is nothing wrong with PHP, but there is so much more wrong with PHP programming.
In combination with outdated CMS and in the hands of/adviced by people with no insight a very, very dangerous code-brew however  ;D
For checking info see this resources: http://php.net/manual/en/function.phpinfo.php   :o
Check version number with exploit and you have a beginner's attack formula.
So PHP and server version number info proliferation is still a big problem.

polonus
« Last Edit: January 04, 2015, 01:33:22 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3310 on: January 06, 2015, 02:27:10 PM »
GoGO in-flight WiFi uses a false Google certificate to filter streaming video -> http://www.theregister.co.uk/2015/01/06/gogo_ssl/

At least where net equality is concerned we know where these guys stand in that discussion - the priviliged and those that can paywill have the fast lane, the others are forced down the slow lane and they force it in by all means.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3311 on: January 06, 2015, 05:54:20 PM »
I'm probably not posting this on the right forum, and I don't know if this is a problem with my Avast software or my other anti-virus program (AdvancedSystemCare by IObit) but--- I keep getting this message window that says - SearchProtection.exe - Fatal Application Exit  Unhandled exception. It then has a ExpCode number, ExpFlag, and Exp address.   The window says I should report it immediately.
What do I do?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89212
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3312 on: January 06, 2015, 06:06:08 PM »
I'm probably not posting this on the right forum, and I don't know if this is a problem with my Avast software or my other anti-virus program (AdvancedSystemCare by IObit) but--- I keep getting this message window that says - SearchProtection.exe - Fatal Application Exit  Unhandled exception. It then has a ExpCode number, ExpFlag, and Exp address.   The window says I should report it immediately.
What do I do?

You're right - this topic isn't correct, this is for security based announcements.

You can start a new topic in the Viruses & Worms sub-forum https://forum.avast.com/index.php?board=4.0. This however may not be necessary as I believe the crux of the matter is your comment "my other anti-virus program, having multiple AVs installed is asking for conflict issues as both dogs fight over one bone.

So I would suggest that you uninstall "AdvancedSystemCare by IObit" - you might also do a search for IObit in the forums as there as some disturbing reports.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3313 on: January 07, 2015, 04:01:08 PM »
In the news – Managed internet devices and biometry
http://blogs.norman.com/2015/business/managed-internet-devices-biometry


Quote
Biometric access control has gained popularity with mobile phones in recent years. We have seen it used in movies for years, where iris- and fingerprint scanners have been portrayed as a fool-proof way of identifying users. There are two problems with this:
– The methods are not fool proof, as demonstrated at the CCC conference.
– Your biometric information cannot be changed. Once copied by a perpetrator, a person cannot use it for identification anymore.


Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48610
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3314 on: January 07, 2015, 06:24:38 PM »
« Last Edit: January 07, 2015, 06:26:10 PM by bob3160 »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet