Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904598 times)

0 Members and 11 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2880 on: February 13, 2014, 01:06:10 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2882 on: February 15, 2014, 03:51:12 PM »
Scores of fake SSL certificates.
Read: http://news.netcraft.com/archives/2014/02/12/fake-ssl-certificates-deployed-across-the-internet.html
40% of mobile apps do not check for SSL-certificates:
http://blog.ioactive.com/2014/01/personal-banking-apps-leak-info-through.html
(link article autho =r Ariel Sanchez) -see attached image.
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2883 on: February 15, 2014, 05:30:52 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2884 on: February 16, 2014, 01:22:08 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89131
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2886 on: February 21, 2014, 11:04:06 AM »
Microsoft Security Advisory (2934088)
http://technet.microsoft.com/en-us/security/advisory/2934088
Fix It: http://support.microsoft.com/kb/2934088/en-us

Interesting - only effects IE9 and IE10 - No problem with IE8 on XP since MS wouldn't allow XP to update to IE9 or IE10 ;)
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Charyb-0

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2508
« Last Edit: February 21, 2014, 09:39:40 PM by Charyb »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2888 on: February 21, 2014, 11:20:03 PM »
After facebook acquired WhatsApp people in Europe do not trust tnat Messenger app any longer and are leaving the mobile app massively to install Russian developed Telegram-Messenger.
Couldn't  this also be because of this news on reported security and apparent privacy problems? Re: http://www.praetorian.com/blog/whats-up-with-whatsapps-security-facebook-ssl-vulnerabilities
link article author = Paul Jauregui, a Praetorian security researcher.
SSL-problems in WhatsApp-
Quote
This is the kind of stuff the NSA would love
, says Jauregui.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2889 on: February 21, 2014, 11:31:23 PM »
Microsoft Security Advisory (2934088)
http://technet.microsoft.com/en-us/security/advisory/2934088
Fix It: http://support.microsoft.com/kb/2934088/en-us

Interesting - only effects IE9 and IE10 - No problem with IE8 on XP since MS wouldn't allow XP to update to IE9 or IE10 ;)
This also is telling:  The fact that only some versions are affected seems to mean that not all versions are updated and made secure in the same way at the same time.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2890 on: February 21, 2014, 11:53:29 PM »
A secure alternative for the Whatsapp community could or might be this Swiss Threema, a mobile messaging app that puts security first
See:  https://threema.ch/en/  Their claim:
Quote
you can rest assured that only you and the intended recipient can read your messages.
.
All security in these days however is only relative security and that is globally so. How far this is true also here I saw when I analyzed the SSL security headers on their very SSL-site, where I saw problems with x-content-type-options, x-xss-protection, x-frame options, content-security-policy with secure headers not being returned. Also not best practices performed on strict-transport-security. So for instance content sniffing stays overall possible also for this service, despite of what the claims, Found these insecurities from their https site analyzed with Recx Security Analyzer.
Authentication however seems for the larger part OK: https://www.ssllabs.com/ssltest/analyze.html?d=threema.ch

What I think. Stay calm, part of this is fear mongering. It is is all "a hype of the day", at least m.p.o.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

AdrianH

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2891 on: February 22, 2014, 10:49:20 AM »
Linksys Worm "TheMoon" Summary: What we know so far
https://isc.sans.edu/diary/Linksys+Worm+%22TheMoon%22+Summary%3A+What+we+know+so+far/17633

Not just Linksys and Asus , but many other top selling brands are open to attack ....

http://www.bbc.co.uk/news/technology-26287517

Quote
  A separate study by security firm Tripwire has found that 80% of the 25 best-selling routers available on Amazon are vulnerable to compromise.

Security researcher Craig Young from Tripwire said exploits had been publicly discussed and published for more than one-third of these devices.

The past 12 months have seen a flurry of interest in routers by security researchers keen to find bugs and loopholes. One project detailing their findings now lists hundreds of exploits for routers from 36 separate manufacturers.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2892 on: February 23, 2014, 01:28:37 AM »
Hi AdrianH,

That is why to have secure procedures you should use cable.
Despite what everybody claims wifi is not fully secure and it never will be.

What is "hanging in the air" can be trapped, tracked and even compromised.
Dlink Amplifiers can be used to abuse.
Not everybody is behind a proxy fire-walled and neatly configured home network,
that puts the browser screen topsy-turvy for eventual  intruders and then denies them.

So watch out. Security of open wifi is even worse.

We had a lot of problems here in Europe with Fritzbox routers lately
and despite many ISP warnings still a whole army of users did not upgrade
and are still vulnerable to remote hacks.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Charyb-0

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2508
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2894 on: February 25, 2014, 04:20:24 PM »