Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2891568 times)

0 Members and 5 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3570 on: April 15, 2015, 11:23:36 AM »
Microsoft Security Bulletin Summary for April 2015
https://technet.microsoft.com/library/security/ms15-apr
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3571 on: April 15, 2015, 11:26:24 AM »
Microsoft Update, Java Update, and Flash player update. Don't forget to update

https://krebsonsecurity.com/2015/04/critical-updates-for-windows-flash-java/
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3574 on: April 16, 2015, 05:06:21 PM »
Adware epidemic and what firefox plans to do to add-ons, only signed add-ons allowed: https://blog.mozilla.org/addons/2015/04/15/the-case-for-extension-signing/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3575 on: April 16, 2015, 09:24:15 PM »
Critical Windows vulnerability affects at least 70 million websites:
http://news.netcraft.com/archives/2015/04/16/critical-windows-vulnerability-affects-at-least-70-million-websites.html  link article author = Netcraft's Paul Mutton.

The vulnerability test for this: https://lab.xpaw.me/MS15-034/

Mind that in China there are an enormous amount of vulnerable MS servers!  :o

polonus
« Last Edit: April 16, 2015, 09:27:52 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3576 on: April 17, 2015, 11:38:07 AM »
Oracle does not comment on bundling Ask-toolbar
Ask-toolbar a very unwelcome guest that can be very persisitent.
Read: http://www.latimes.com/business/la-fi-lazarus-20150417-column.html
link article author = David Lazarus

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48567
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3577 on: April 17, 2015, 02:59:03 PM »
Oracle does not comment on bundling Ask-toolbar
Ask-toolbar a very unwelcome guest that can be very persisitent.
Read: http://www.latimes.com/business/la-fi-lazarus-20150417-column.html
link article author = David Lazarus

polonus
Install Unchecky, it will uncheck the authorization to install the Ask Toolbar
and prevent it from getting to your computer.
Always use a custom install and read before you click on that Big Button.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3578 on: April 17, 2015, 03:01:26 PM »
Good Advice, bob3160, unchecky a must nowadays.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3579 on: April 17, 2015, 03:11:08 PM »
Beware of Chrome extensions, the mantra of the safest browser is now just cant (read the same for Firefox) 

Quote
It seems that the adware creates a fake extension with other legit extension ID present in Google Chrome Web Store (only those are allowed in stable Chrome), which uses a manifest.json loading the ads script. I don't know, if an extension ID is picked randomly

e.g. CHR Extension: (bmejphbfclcpmpohkggcjeibfilpamia) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmejphbfclcpmpohkggcjeibfilpamia [2015-04-06]
Note that the ID itself is legit and refers to Netcraft Extension officially hosted on Chrome Web Store:

But that is NOT the Netcraft Extension, but a false copy:

I will not post the code as Avast alerts on it

The problem is with the amount of extensions people have on Chrome and Firefox it is impossible to check them all.  So from now on if only "legitimate" ID appear in either browser I will be asking for an uninstall

Something similar is happening on Firefox 

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3583 on: April 19, 2015, 07:51:36 PM »
Security through obscurity to win?  Read: https://www.eff.org/deeplinks/2015/04/united-airlines-stops-researcher-who-tweeted-about-airplane-network-security   link article author =  ANDREW CROCKER

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3584 on: April 20, 2015, 11:03:04 PM »
Interesting website on the European Privacy Debate -
How lobbyists weaken user's data protection for the Safe Harbor big data grabbers:

http://lobbyplag.eu/governments/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!