Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2902439 times)

0 Members and 5 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4080 on: September 19, 2015, 12:42:46 AM »
Hi bob3160,

Well it was my pleasure checking and going over the script code there and a reassuring all green for you is not bad at all.
Congratulations.
Well I think you did not expect anything else, really  :D

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4082 on: September 20, 2015, 07:19:20 AM »
AVG releases transparent privacy policy: Yes, we will sell your data

http://www.zdnet.com/article/avg-releases-transparent-privacy-policy-yes-we-will-sell-your-data/

Quote
AVG will sell the data of its users to third parties in order to keep basic antivirus software free
« Last Edit: September 20, 2015, 07:21:10 AM by SpeedyPC »
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4083 on: September 20, 2015, 11:42:10 AM »
AVG releases transparent privacy policy: Yes, we will sell your data

http://www.zdnet.com/article/avg-releases-transparent-privacy-policy-yes-we-will-sell-your-data/

Quote
AVG will sell the data of its users to third parties in order to keep basic antivirus software free


It's interesting how AVG thinks of "copies of files or emails" as "non-personal data" just because they were "marked as potential malware".

Quote
We collect non-personal data to improve our products and services, including:
data concerning potential malware threats to your device and the target of those threats, including copies of files or emails marked as potential malware, file names, cryptographic hash, vendor, size, date stamps, associated registry keys, etc.;
...snip...

http://www.avg.com/us-en/privacy-new#what-do-you-collect-that-cannot-identify-me


And,

"We collect non-personal data to make money from our free offerings so we can keep them free, including:
...snip...
Browsing and search history, including meta data;"

even though they also say

"Sometimes browsing history or search history contains terms that might identify you. If we become aware that part of your browsing history might identify you, we will treat that portion of your history as personal data, and will anonymize this information..."

So, AVG users have to trust AVG that AVG can deem what parts of their browsing history or search history contain terms that might identify them! Good luck with that!

Besides, I never like when a privacy policy uses the word "including...". That begs the question: and what else?
« Last Edit: September 20, 2015, 03:02:19 PM by 1234ava »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4084 on: September 21, 2015, 12:45:17 PM »
199 hacked routers SYNful Knock: http://blog.shadowserver.org/2015/09/21/synful-knock/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48586
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4085 on: September 21, 2015, 03:10:23 PM »
Nasty URL bug brings Google Chrome to a screeching halt
Simply add "%%30%30" to the end of any URL in chrome and watch it crash.
« Last Edit: September 21, 2015, 04:14:47 PM by bob3160 »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4086 on: September 21, 2015, 03:59:59 PM »
Hi bob3160,

This string abuse works because the browser actually wants this to execute as  %25%2530%2530
When I give your string in following directly from "https://ad.nl/" the browser url bar shows: http://caja.appspot.com/#https://ad.nl/%25%2530%2530
and this can be abused because my connection is no longer private, your bug code can be used as privacy error and for stealing credentials like passwords messages , creditcards details etc. Did you notice that, bob3160?  :o
What you do with %%30%30 translated into %25%2530%2530 is a certificate hack and the server certificate no longer matches that URL or v.v. and the use of an older Cipher Suite is being flagged. Did you notice that, bob3160?  :o
We stumbled upon something that could lead to indirect abuse on a large scale. Thank you very, very much for reporting this.
Trying this on the nameserver there: -http://ns1-25.akam.net/%25%2530%2530 and then condider this: 10 red out of 10 red Netcraft risk status. This certainly is an issue that goes beyond a mere Google Chrome browser bug, bob3160, you stumbled on something that needs to be analysed further, my good friend. Here the server just opens the main page: http://www.telegraaf.nl//%25%2530%2530

Damian
« Last Edit: September 21, 2015, 04:07:57 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48586
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4087 on: September 21, 2015, 04:07:16 PM »
Not something I stumbled upon simply something I'm reporting.
Follow the link I supplied for more information. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4088 on: September 21, 2015, 04:10:31 PM »
That link is empty, I get an about:blank
Can you provide us with a working link?
Was it reported 21 hours ago here?: http://www.pcworld.com/article/2984907/security/nasty-url-bug-brings-google-chrome-to-a-screeching-halt.html
And the one that detected it originally: http://andrisatteka.blogspot.com/2015/09/a-simple-string-to-crash-google-chrome.html
The %25%2530%2530 translation that actually could play havoc on some https servers was my experiment here  ;D

polonus
« Last Edit: September 21, 2015, 04:14:25 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48586
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4089 on: September 21, 2015, 04:15:13 PM »
OOPS, it's been corrected. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4090 on: September 21, 2015, 04:48:35 PM »
Now when I give in this https://www.security.nl/%2525%252530%252530
1.   https://www.security.nl/%2525%252530%252530   Security.NL   57,992 bytes   641 ms
I get here: https://www.security.nl/?welcome
And there are sources and sinks to consider: http://www.domxssscanner.com/scan?url=https%3A%2F%2Fwww.security.nl%2F%252525%25252530%25252530%09
Results from scanning URL: https://www.security.nl/js/dfp.js?1375741199
Number of sources found: 28
Number of sinks found: 11
Results from scanning URL: https://www.security.nl/js/dfp.js?1375741199
Number of sources found: 1
Number of sinks found: 1
Results from scanning URL: https://www.security.nl/js/dfp.js?1375741199
Number of sources found: 122
Number of sinks found: 60
Indeed equalling these results: http://www.domxssscanner.com/scan?url=https%3A%2F%2Fwww.security.nl%2F%3Fwelcome
Interesting and the results on various servers should be established.

This server is further secured against this and I meet a neat 404 error. This is as it should be:
http://www.huffingtonpost.com/%2525%252530%252530
Oh, Noes! A 404! As I approached this locally.
Here the whole page disappears which kicks up a dev/null: http://www.nu.nl/%2525%252530%252530   :o

polonus
« Last Edit: September 21, 2015, 05:00:23 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4092 on: September 22, 2015, 06:55:57 PM »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4093 on: September 22, 2015, 10:22:07 PM »
Another reason to stick to your Adblocker: https://grahamcluley.com/2015/09/forbes-malvertising/
article author - Graham Cluley
Quote
"Malvertising continues to be an attack vector of choice for criminals making use of exploit kits. By abusing ad platforms – particularly ad platforms that enable Real Time Bidding – attackers can selectively target where the malicious content gets displayed."

"When these ads are served by mainstream websites, the potential for mass infection increases significantly, leaving users and enterprises at risk."

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!