Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2890481 times)

0 Members and 1 Guest are viewing this topic.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5371 on: July 06, 2017, 02:42:55 AM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5372 on: July 06, 2017, 02:44:15 AM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5373 on: July 10, 2017, 07:11:52 PM »
https://security.googleblog.com/2016/10/distrusting-wosign-and-startcom.html

While not sticking to the rules, these certifiers have endangered website visitors and are not trusted any longer by Google.

Background read: https://www.lowendtalk.com/discussion/95618/google-chrome-distrusting-wosign-and-startcom-certificates

Comics can tell more than a thousand words: -http://dilbert.com/search_results?terms=Vast+Power+Of+Certification

pol
« Last Edit: July 10, 2017, 07:36:21 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5374 on: July 11, 2017, 02:48:22 PM »
Most providers and CDNs in cahoots with Big GubbermentRead: https://www.eff.org/who-has-your-back-2017

This not about protecting your personal data through security technology, best practices etc, this just touches transparency,
policy towards end-users, Amazon and Whatsapp has a bad reputation for the total lack of protecting your data against snoopers.

Adobe, Amazon, Apple, Facebook, Google, LinkedIn, Microsoft, T-Mobile, Twitter, WhatsApp, WordPress en Yahoo. Providers Verizon, T-Mobile, Comcast en AT&T just scored one star in protecting your data from Government requests.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5375 on: July 12, 2017, 03:31:39 PM »
Big Campaign in USA for Netneutrality:

https://www.battleforthenet.com/july12/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5376 on: July 12, 2017, 07:19:13 PM »
Big Campaign in USA for Netneutrality:

https://www.battleforthenet.com/july12/

polonus

Knowing the political climate here in the good ol' U.S. of A. this looks like a losing cause.  :'(
We can always hope.  ;)
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5377 on: July 13, 2017, 12:22:18 AM »

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5378 on: July 13, 2017, 12:22:39 AM »
Don't Open SPAM Containing Password Protected Word Docs
(Should be obvious at this point.)

https://www.bleepingcomputer.com/news/security/psa-dont-open-spam-containing-password-protected-word-docs/
« Last Edit: July 13, 2017, 12:24:49 AM by ehmen »

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5379 on: July 13, 2017, 11:21:15 PM »
The WPSetup Attack: New Campaign Targets Fresh WordPress Installs
Read: https://www.wordfence.com/blog/2017/07/wpsetup-attack/

The best method for "wizzard"-like  setups for webapplications is to have the set-up done locally at home, and when the set up is what you like it to be, then you are  to rsync it to the webserver, together with the right permissions, security and unnecessary files being deleted.

Even better stil is using git and make sure through a .gitignore that no vulnerable files land onto your live server.

Whenever you do not need an interactive site really, in that case you should make use of a static site generator! (When you need comments on posts you could do that using Disqus - https://gohugo.io/extras/comments/)

For starters there is Hugo, giving the least problems for beginners; http://gohugo.io/

(Info credits go to Soeperees and Neb Poorten, thanks folks)

polonus (volunteer website secruity analyst and website error hunter)


« Last Edit: July 13, 2017, 11:30:31 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5380 on: July 14, 2017, 03:16:46 AM »

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5382 on: July 17, 2017, 01:25:23 PM »
Retire QuickTime for Windows for good, uninstall!

Read why? Re: https://www.us-cert.gov/ncas/bulletins/SB17-191

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5383 on: July 18, 2017, 12:01:30 PM »
Researchers find up serious holes in Web Ex: https://bugs.chromium.org/p/project-zero/issues/detail?id=1324

11 holes in Radius found in DHCP and RADIUS packet parsers via fuzzing: https://guidovranken.wordpress.com/2017/07/17/11-remote-vulnerabilities-inc-2x-rce-in-freeradius-packet-parsers/

polonus (volunteer website security analyst and website error-hunter)

Advice: always fully patch, upgrade and backup  ;)

D.
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5384 on: July 25, 2017, 06:00:50 PM »
“Perverse” malware infecting hundreds of Macs remained undetected for years
https://arstechnica.com/security/2017/07/perverse-malware-infecting-hundreds-of-macs-remained-undetected-for-years/
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast