Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2899565 times)

0 Members and 4 Guests are viewing this topic.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37541
  • Not a avast user

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4741 on: July 14, 2016, 11:31:25 AM »
Microsoft Security Bulletin Summary for July 2016
https://technet.microsoft.com/library/security/ms16-jul
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline abruptum

  • Massive Poster
  • ****
  • Posts: 2460
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4742 on: July 14, 2016, 05:33:06 PM »
Microsoft wins federal appeal over warrants for data held outside US

  https://www.rt.com/usa/351052-microsoft-emails-ireland-server/

REDACTED

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4743 on: July 14, 2016, 11:07:00 PM »
Avast Sandbox has a flaw of allowing access to the file system. This could allow ransomware to encrypt files even if it is running in the sandbox, the writeup I found online is here:
http://seclists.org/fulldisclosure/2016/Apr/68

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89102
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4744 on: July 14, 2016, 11:53:53 PM »
Avast Sandbox has a flaw of allowing access to the file system. This could allow ransomware to encrypt files even if it is running in the sandbox, the writeup I found online is here:
http://seclists.org/fulldisclosure/2016/Apr/68

This is pretty old in security terms and related to Avast Free/Pro/IS/Premier versions, 11.x.x and even earlier for the Endpoint Protection versions 8.x.x.

Given that the latest avast that the latest versions of Avast Free/Pro/IS/Premier is at 12.1.x it would have to be confirmed if this is still in effect or resolved in the later versions.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4745 on: July 16, 2016, 04:07:32 AM »
Energy Grid Malware Bypasses Cyber and Physical Security

"Security researchers have discovered new malware designed to bypass traditional physical and cybersecurity which could be used in an attack to shut down an energy grid."

https://sentinelone.com/blogs/sfg-furtims-parent/
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4746 on: July 16, 2016, 06:01:56 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Simion

  • Advanced Poster
  • **
  • Posts: 976

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4748 on: July 18, 2016, 08:49:30 AM »
New version of Petya Released. Fixes bug in Encryption Algorithm

http://www.bleepingcomputer.com/news/security/new-version-of-petya-released-fixes-bug-in-encryption-algorithm/

A new version of the Petya disc-encrypting ransomware has been released that fixes a bug that previously caused some weakness in its encryption algorithm. According to Hasherezade, a security analyst for Malwarebytes, prior versions of the Petya ransomware were not properly implementing the Salsa20 encryption algorithm, which was used by the ransomware to encrypt the drive and for verifying that a correct ransom key was entered.

With this new version, the Petya developer's implementation of the Salsa20 algorithm has been fixed, which removes the previously exploitable weaknesses.

Hope Avast! ready for this ransomware.

PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33910
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4749 on: July 18, 2016, 12:39:08 PM »
Seems a concerted action against Tor ongoing: https://trac.torproject.org/projects/tor/ticket/19690

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33910
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4750 on: July 18, 2016, 10:37:32 PM »
Seeing a lot of examples where CloudFlare enabled websites won't resolve DNS.
Example found lately: https://sritest.io/
I get a
Quote
Error 1001 Ray ID: 2c48982096d52c78 • 2016-07-18 20:14:28 UTC
DNS resolution error 
Do not see a reverse DNS here: http://toolbar.netcraft.com/site_report?url=https://sritest.io
Also see here: http://www.dnsinspect.com/sritest.io/1468872908

Issue with the Comodo Certificate allthough it has been installed properly:sritest.io
This is not a Symantec certificate.
Please contact the Certificate Authority for further verification.
This server cannot be scanned for these vulnerabilities:
Heartbleed. See possible causes.
Poodle (TLS). See possible causes.
Info
BEAST
The BEAST attack is not mitigated on this server.
Certificate information
This server uses a Domain Validated (DV) certificate. No information about the site owner has been validated. Data is protected, but exchanging personal or financial information is not recommended.
Common name:
 sni154156.cloudflaressl.com
SAN:
 sni154156.cloudflaressl.com, *.alexamaster.com, *.denisha.review, *.funnelproducer.com, *.garnettrowand.xyz, *.ouemceeii.cf, *.platypuslovescrypto.party, *.privacyforjournalists.org.au, *.savingnh.com, *.sifoilxi.cf, *.skachat-besplatno-balloon.accountant, *.sritest.io, *.superagency.ru, *.tadra.us, *.thingsandservices.com, *.whitehatmatrix.com, alexamaster.com, denisha.review, funnelproducer.com, garnettrowand.xyz, ouemceeii.cf, platypuslovescrypto.party, privacyforjournalists.org.au, savingnh.com, sifoilxi.cf, skachat-besplatno-balloon.accountant, sritest.io, superagency.ru, tadra.us, thingsandservices.com, whitehatmatrix.com
Valid from:
 2016-Jul-18 00:00:00 GMT
Valid to:
 2017-Jan-22 23:59:59 GMT
Certificate status:
 Valid
Revocation check method:
 OCSP
Organization:
 
Organizational unit:
 PositiveSSL Multi-Domain,Domain Control Validated
City/locality:
 
State/province:
 
Country:
 
Certificate Transparency:
 Not embedded in certificate
Serial number:
 2edd615acf8a11663b75fe0037e2d6d7
Algorithm type:
 SHA256withECDSA
Key size:
 256
Certificate chainShow details
COMODO ECC Certification AuthorityIntermediate certificate
COMODO ECC Domain Validation Secure Server CA 2Intermediate certificate
sni154156.cloudflaressl.comTested certificate
Server configuration
Host name:
 104.24.122.240
Server type:
 cloudflare-nginx
IP address:
 104.24.122.240
Port number:
 443
Protocols enabled:
TLS1.2
TLS1.1
TLS1.0
Protocols not enabled:
SSLv3
SSLv2
Secure Renegotiation:
 Enabled
Downgrade attack prevention:
 Enabled
Next Protocol Negotiation:
 Enabled
Session resumption (caching):
 Enabled
Session resumption (tickets):
 Enabled
Strict Transport Security (HSTS):
 Not Enabled
SSL/TLS compression:
 Not Enabled
Heartbeat (extension):
 Not Enabled
RC4:
 Not Enabled
OCSP stapling:
 Not Enabled

comodo scan gives: E-commerce Safety Information
Transaction Protection
Analysis has failed to complete. Sorry, The connection timed out before all (any?) content was returned! (Note: As a part of their security measures some shared hosting services will block this type of tool from scanning the sites they host. -- some things to try
Scripts resolve normally: https://seomon.com/domain/sritest.io/performance/

Just does not like the oversight at these large cloud blulk hosters, (my remark - pol).
Is this because of recently found cgi vulnerabilities in certain applications, and has this to be mitigated? Anyone?

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33910
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4751 on: July 18, 2016, 10:42:25 PM »
Work-arounds for particular server applications exist: https://httpoxy.org/  - read -> https://www.kb.cert.org/vuls/id/797896

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33910
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4752 on: July 18, 2016, 11:53:03 PM »
Lot of tracking going on in my Google Chrome Browser:
Quote
We found 38 data collectors in Chrome tracking, saving and often selling your browsing.
Here is a list of the trackers we found (data collectors, ad networks, widgets & others):
AdF.ly   Adzerk   Alexa   bitly
Google   Disqus   DoubleClick   Feedjit
Flattr   Foursquare   Imgur   Impact Radius
LinkedIn   Marin Software   Microsoft adCenter   Microsoft
Netmining   Omniture (Adobe)   Pinterest   Po.st
Mail.ru   Reddit   Sanoma   ShareASale
Skimbit Ltd   SoundCloud   TradeDoubler   Twitter
Tynt   UserVoice   Vkontakte   Yandex
Zippyshare   Platform161   MixPanel   Taboola
Wordpress   Olark
  How to keep them at bay?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48580
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48580
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4754 on: July 20, 2016, 03:06:11 PM »
How does this effect Avast ???
http://www.theregister.co.uk/2016/07/20/hooks_cooked_hackers_crack_tonnes_of_security_apps_for_new_cloak_yoke/
I've found my own answer:
EnSilo identified affected products from AVG, Kaspersky Lab, McAfee/Intel Security, Symantec, Trend Micro, Bitdefender, Citrix, Webroot, Avast, Emsisoft and Vera Security.
Now the question is how quickly will this get patched ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet