Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2889328 times)

0 Members and 2 Guests are viewing this topic.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3510 on: March 20, 2015, 10:21:58 PM »
The Company Securing Your Internet Has Close Ties to Russian Spies
www.bloomberg.com/news/articles/2015-03-19/cybersecurity-kaspersky-has-close-ties-to-russian-spies


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3511 on: March 20, 2015, 10:30:45 PM »
Hi Pondus,

Always present two sides of the coin.
That was the one side of the story,
here is the other and then let those that have read this all
just decide for themselves  what they want to believe,

I think that is the only fair presentation:
http://eugene.kaspersky.com/2015/03/20/a-practical-guide-to-making-up-a-sensation/
Source Евге́ний Валенти́нович Каспе́рский's Official Blog

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3512 on: March 20, 2015, 10:58:01 PM »
Once attacked one must defend one's honor and integrity.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3513 on: March 21, 2015, 02:04:04 PM »
Once attacked one must defend one's honor and integrity.
Sometimes defending your honor only results to more criticism.  :(
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3514 on: March 21, 2015, 05:14:50 PM »
Once attacked one must defend one's honor and integrity.
Sometimes defending your honor only results to more criticism.  :(

How true.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3516 on: March 22, 2015, 12:56:40 PM »
HTTPS-Everywhere, nice initiative, but is it overall secure? "Majority of Web sites currently only use HTTPS for logins or transactions where sensitive data is captured," the analyst Ang Poon Wei, stated.
"Trying to access a Web site that doesn't or partially supports HTTPS would generate different user experiences." Quotes taken from an article by  Ellyne Phneah for ZDNet.
This is my experience also. For instance at https://www.on24.com that is trying to load scripts from non-verified sources and older weaker encryption. Even HTTPS-Everywhere green padlocked websites may have security issues the average user may not expect - encryption sequence delivered from the weak end up (misconfiguration),
weakened encryption because excluded from the more secure variety (export restrictions). Security header implementation eikther missing or full of warnings, check with Recx Security Analyser Extension, so often the unaware user is lulled into a sense of security while the online commercial and governmental tracking goes on. Remember we live in the Golden Age of Global Surveillance. My analysis experiments with SSL scanning in combination with Tracker tracker tool result analysis proofs the green padlock may often only present a "bleak or bleached" green  ;D

An example for htxps://www.on24.com/ with Outdated Web Server Apache Found   Vulnerabilities on Apache 2.2   Apache/2.2.26 See for yourselves attached and the security header status report here: http://www.webpagescreenshot.info/img/550eadaa52b736-52877506

polonus
« Last Edit: March 22, 2015, 01:00:00 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3517 on: March 22, 2015, 02:17:08 PM »
Also users may wonder (what if the given situation is that insecure) what then will be our best means of protection?
Overall Avast protection in the first place naturally. Then inside a browser script blocking and third party access blocking with extensions like for the firefox browser NoScript and RequestPolicy and a decent Adblocker. i use uBlock because it also blocks unobtrusive (Google) ads by default.
For the Google Chrome and Sleipnir user the choice is even less complicated while the handling of the extensions is more user-friendly. A combination of SafeScript extension, HTTP Switchboard extension and uBlock or ABP in right configuration here is all you browser users need. Whenever you need more protection for whatever reason read further here: https://prism-break.org/en/

The site we have analyzed above uses a tracking script named Munchkin. Here is how Glen Lipka first employee and designer of marketo's metaphorically describes what the tracking script is supposed to do
Quote
Marketo tracks visitors with a piece of JavaScript called Munchkin.  It pays careful attention to each individual fish.  It watches where every single fish swims and keeps track of every detail.  This is because that fish is going to feed a salesperson one day and he/she will want to know where the fish has been and where it's going so that they can catch the fish effectively.  We even score the fish to give the fisherman/salesperson the best chance of success.
The code is an equivalent of the better known Google Analytics. Marketo cookies the visitor first, then request a 1x1 transparent image from their servers with details of the visit in the parameters of the request. That's how it works all the time all of the time under the hood of your browser, folks.

polonus
« Last Edit: March 22, 2015, 02:58:22 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3518 on: March 22, 2015, 10:00:53 PM »
Another example of such a HTTPS Everywhere website with mixed https/http content - could it be vulnerable to HTTPS Strip Exploits like SSL Strip by Moxie Morlinspike.
Find my tracker tracker report attached for https://www.magellanmodels.com/- do not open links directly into a browser - info provided for research purposes only.

polonus (volunteer website security analyst and website error-hunter)

P.S. Info on the Yotpo Embedded Widget here: http://blog.yotpo.com/2014/03/13/embedded-widget-complete-guide/
cdn6.bigcommerce.com is an analysis tracker
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3520 on: March 24, 2015, 12:02:31 AM »
China is a gigantic market. This must have been the reason that the number of phishing sites now have doubled and now totals 93.000, 40.00 of which had a backdoor  :
http://www.chinadaily.com.cn/china/2015-03/20/content_19869243.htm (source: (Xinhua) China Authorities).

polonus
« Last Edit: March 24, 2015, 12:04:18 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3521 on: March 25, 2015, 03:43:51 PM »
When is enough enough?
22 million PUP detections - http://blog.avira.com/potentially-unwanted-applications-2/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3522 on: March 25, 2015, 10:20:52 PM »
Flash-based SOP circumvention hole coming back to haunt us three years later, thousands of websites affected:
http://www.computerworld.com/article/2901313/flashbased-vulnerability-lingers-on-many-websites-three-years-later.html  article author = Lucian Constantin

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3523 on: March 26, 2015, 07:39:04 PM »
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline abruptum

  • Massive Poster
  • ****
  • Posts: 2460
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3524 on: March 27, 2015, 12:15:12 PM »