Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2881058 times)

0 Members and 2 Guests are viewing this topic.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5505 on: October 20, 2017, 06:01:27 PM »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5506 on: October 24, 2017, 01:02:40 PM »
Another zero-day in extension used to attack websites with WordPress detected by Wordfence.

https://wordpress.org/plugins/ultimate-form-builder-lite/#developers

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5507 on: October 24, 2017, 05:08:48 PM »
New authentication method on lenovo - FIDO:
They claim to be the first: http://www.businesswire.com/news/home/20171024005571/en/Lenovo%E2%84%A2-Intel%C2%AE-Deliver-Simpler-Safer-Online-Authentication

Is it safe and cannot it be circumvented?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89021
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5508 on: October 24, 2017, 05:32:01 PM »
New authentication method on lenovo - FIDO:
They claim to be the first: http://www.businesswire.com/news/home/20171024005571/en/Lenovo%E2%84%A2-Intel%C2%AE-Deliver-Simpler-Safer-Online-Authentication

Is it safe and cannot it be circumvented?

polonus

Personally since the various security issues relating to Lenovo, I would be wary of any security related promotion connected to Lenovo. 

Previous to my purchase of this win10 acer notebook, lenovo products were attractive given the Performance Vs Price. Security issues however, took lenovo right off my list and they haven't regained my trust (very hard in my case).

Also fingerprints as a security measure are loosing ground as far as security goes, they can be tricked by a lifted fingerprint. Something that has also been talked about is that fingerprints actually change as we get older; have a look at your fingerprints, the young are relatively clear and well defined those older computer users will see (excuse the pun) that their fingerprints aren't so clearly defined.  They look more worn and faded, possibly more so in those who were in a manual job.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48550
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5509 on: October 24, 2017, 06:00:33 PM »
New authentication method on lenovo - FIDO:
They claim to be the first: http://www.businesswire.com/news/home/20171024005571/en/Lenovo%E2%84%A2-Intel%C2%AE-Deliver-Simpler-Safer-Online-Authentication

Is it safe and cannot it be circumvented?

polonus

Personally since the various security issues relating to Lenovo, I would be wary of any security related promotion connected to Lenovo. 

Previous to my purchase of this win10 acer notebook, lenovo products were attractive given the Performance Vs Price. Security issues however, took lenovo right off my list and they haven't regained my trust (very hard in my case).

Also fingerprints as a security measure are loosing ground as far as security goes, they can be tricked by a lifted fingerprint. Something that has also been talked about is that fingerprints actually change as we get older; have a look at your fingerprints, the young are relatively clear and well defined those older computer users will see (excuse the pun) that their fingerprints aren't so clearly defined.  They look more worn and faded, possibly more so in those who were in a manual job.
As long as we're just talking about fingerprints, I'll agree with you. :) :) :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89021
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5510 on: October 24, 2017, 06:58:58 PM »
New authentication method on lenovo - FIDO:
They claim to be the first: http://www.businesswire.com/news/home/20171024005571/en/Lenovo%E2%84%A2-Intel%C2%AE-Deliver-Simpler-Safer-Online-Authentication

Is it safe and cannot it be circumvented?

polonus
<snip>
Also fingerprints as a security measure are loosing ground as far as security goes, they can be tricked by a lifted fingerprint. Something that has also been talked about is that fingerprints actually change as we get older; have a look at your fingerprints, the young are relatively clear and well defined those older computer users will see (excuse the pun) that their fingerprints aren't so clearly defined.  They look more worn and faded, possibly more so in those who were in a manual job.
As long as we're just talking about fingerprints, I'll agree with you. :) :) :)

Yes that is the 'main' train of my thoughts fingerprints really aren't that great as far as security is concerned.  There have been articles about biometrics.

"The measurement of physical characteristics, such as fingerprints, DNA, or retinal patterns, for use in verifying the identity of individuals" from http://www.tfd.com/biometrics .

Retinal use for id purposes has also had some negative reports/issues if used for authentication.  Whilst the use of DNA is probably the most secure it has a long way to go before it can be used for id/authentication at such a low level.  I don't think that we will see 'lick/touch screens/pads' to analyse your saliva any time soon.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5511 on: October 25, 2017, 03:51:25 AM »
Bad Rabbit: Not-Petya is back with improved ransomware

https://www.welivesecurity.com/2017/10/24/bad-rabbit-not-petya-back/
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5512 on: October 25, 2017, 03:24:34 PM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5513 on: November 02, 2017, 04:01:50 PM »
Dwindling privacy and less security resulting in ever so many data-breaches, now again in the land of down under:

https://medium.com/@woj_ciech/short-story-about-s3-bucket-python-script-thousands-of-data-and-australian-government-435e4d2b213e

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5514 on: November 05, 2017, 11:39:14 AM »
A typical case of lack of input validation for e-mail fraud- damage for customers could be over a million in dollars...
http://theartnewspaper.com/news/galleries-lose-large-sums-to-cybercrime

2FA, in a lot of cases, it cannot come in too soon,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5515 on: November 06, 2017, 10:20:36 PM »
Tor browser IP leaks for linux- and Mac-users:

Tor project came with an important update: https://blog.torproject.org/tor-browser-709-released

This bug was detected as a design flaw: https://trac.torproject.org/projects/tor/ticket/24052

For some the leakage was hard to reproduce.
Probably the design error was found, because of the transition to unix domain sockets.

Read about this by Robert Ransom at this link: https://packetstormsecurity.com/files/112439/torproxy-bypass.txt

How to reproduce an example was given here: https://trac.torproject.org/projects/tor/ticket/5741
Quote

Download and verify "tor-browser-gnu-linux-i686-2.2.35-10-dev-en-US.tar.gz"
Start up Wireshark to monitor your network, optionally filtering for "dns"
Unpack Tor and start it by running the "start-tor-browser" script
Once TorBrowser is open, go to "?http://bitcoincharts.com/"
See DNS request for "bitcoincharts.com" being logged in Wireshark
System information:
Tor Browser Bundle for 32-bit Linux, version 2.2.35-10
Running on Fedora 16

To reproduce the exact syntax used and configuration are important,
obfuscation already can be an erroneous factor,
those into reproducing could come up with their own "scrum-report" of sorts.

(info credits security dot nl).

polonus

P.S. The right order and right use of vpn and tor on whonix could be critical for security reasons.

Important notice:
Remember to use these anonimity tools only for legitimate use. Abuse of such services is an legal offence,
and abusers will often suffer the consequences, when found out. No hacker is really out of harm's way.  :D


In some countries the use of such tools may be forbidden (certain VPN services in the Russian Federation,
when keys are withheld from the authorities).

Damian
« Last Edit: November 06, 2017, 10:36:42 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5517 on: November 10, 2017, 01:13:37 PM »
PHISHING back as one of the major Internet threats, why so few phishing websites are actually detected and blocked by AV?

See the report: https://security.googleblog.com/2017/11/new-research-understanding-root-cause.html

Best phising detection performance from IDS alerting "fortinet's" see urlquery.net results.
Also check on: http://www.urlvoid.com/scan/freckleface.com.au/

Bitdefender TrafficLight extension and Webutation Rating also do a fine job.
The average AV solution often miserably fails in detecting or
are detecting long after the fact, when the actual phishing campaign is long over.

Third party content blocking via NoScript and uMatrix and browser hygiene is your best option.

Just an example where average AV fails: http://www.urlvoid.com/scan/freckleface.com.au/  -> https://urlquery.net/report/7e257590-c233-482d-871b-db7baadbb167
where only OpenPhish and fortinet detect and alert this.

Also has to do with what we consider accepted legal phishing by a big techno corporation, like Google's for instance,
and what is considered as 'bad phishing', two standards going and a lot of confusion for the modern end-user  ::)

polonus (volunteer website security analyst and website error-hunter0
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48550
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5518 on: November 11, 2017, 03:52:03 PM »
This needs to be done ASAP - Disable SMB1

Server Message Block (SMB) is a local network file sharing protocol designed for sharing data, printers, etc.
between computers. SMBv1 is the formative iteration of the protocol which has since been replaced by SMBv2 and SMBv3.
SMB1 is still enabled by default in Windows simply to cater for specific older software which hasn’t been updated to support SMB2 or SMB3.
Microsoft will be disabling SMB1 by default starting with the Windows 10 Fall Creators Update.
It was still turned on on my systems and they are all running Windows 10 Fall Creators Update
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89021
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5519 on: November 11, 2017, 04:57:27 PM »
@bob3160

Very interesting, but I do find the response by many companies "Vendor does not publicly document their requirement for SMB1."  That is pretty poor and almost an admission that they do use it, this certainly doesn't help the user protect their system. 

I would be seriously looking to get rid of any program that doesn't comment on their use of SMBv1, if they do, then their users systems could be at risk. If they don't use it (or use a later version of SMBv?) then their users aren't at risk, but should still disable SMBv1.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security