Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904866 times)

0 Members and 6 Guests are viewing this topic.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3076 on: August 06, 2014, 07:02:24 PM »
Isn't it time to change your password whenever you visited one of these 420.000  :o sites, hacked via SQL injection flaws?
Read: http://www.holdsecurity.com/news/cybervor-breach/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3077 on: August 06, 2014, 07:06:28 PM »
Don't just trust any link on your smartphone: http://securelist.com/blog/virus-watch/65459/android-worm-on-chinese-valentines-day/
link article author = Securelist's Vigi Zhang.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline merckxist

  • Jr. Member
  • **
  • Posts: 76
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3078 on: August 06, 2014, 08:38:53 PM »
Isn't it time to change your password whenever you visited one of these 420.000  :o sites, hacked via SQL injection flaws?
Read: http://www.holdsecurity.com/news/cybervor-breach/

polonus

Since Hold Security isn't identifying the exploited sites so we know where its now safe to change a password (non-disclosure is such a convenient CYA mechanism), might we rely on AOS to check for "SQL injection flaws" before it puts that green check mark next to a site name?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89132
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3079 on: August 06, 2014, 08:54:26 PM »
Isn't it time to change your password whenever you visited one of these 420.000  :o sites, hacked via SQL injection flaws?
Read: http://www.holdsecurity.com/news/cybervor-breach/

polonus

Since Hold Security isn't identifying the exploited sites so we know where its now safe to change a password (non-disclosure is such a convenient CYA mechanism), might we rely on AOS to check for "SQL injection flaws" before it puts that green check mark next to a site name?

Since SQL injection is outside of what AOS is actually monitoring, it isn't checking page content (script injection, etc.) as such, then No it won't. Adding 420,000 + sites to a list (like the known malicious sites) for checking it likely to impact on browsing.

The web shield is more likely to detect SQL injection as that is looking at source code, etc. Presumably this SQL injection would probably take you to (or run code on) another site. This is the sort of thing that the web shield is looking at.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3080 on: August 06, 2014, 09:03:14 PM »
Hi merckxist,

Apart from the SQL threat, considering the overall website security situation of sites on the Interwebs to-day -
it is a good policy to change passwords once in a while over time.
Once bitten  twice shy, ( where I point at what happened to these support forums recently)
Your reaction shows that you are fully aware of the present password security situation.

polonus

P.S.
DavidR and I are using script blocking on sites (e.g. No Script) as a good form of protection against third party threats.
« Last Edit: August 06, 2014, 09:05:35 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3081 on: August 07, 2014, 12:43:06 PM »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3082 on: August 07, 2014, 12:55:19 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3083 on: August 07, 2014, 08:55:48 PM »
Google will give a better ranking to https sites over http sites.
This as a security priority. Or is this security through obscurity measure?
So it will be high time av scanners could scan within SSL sites now.
Read on the Google Blog: http://googleonlinesecurity.blogspot.ca/2014/08/https-as-ranking-signal_6.html

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3085 on: August 07, 2014, 10:38:34 PM »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3086 on: August 08, 2014, 12:34:46 AM »
Cybercrime only costs a fraction of the damage it does.


polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3087 on: August 09, 2014, 10:40:37 AM »
Microsoft Security Bulletin Advance Notification for August 2014
https://technet.microsoft.com/library/security/ms14-aug
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3088 on: August 09, 2014, 08:11:35 PM »
Is your neighbor's cat gone a-wardriving, is this a normal flea band or one going to break into your WiFi router?
Read: https://defcon.org/html/defcon-22/dc-22-speakers.html#Bransfield  Gene Bransfieldlink article author =
What is out there on the hot tin roof?

pol

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3089 on: August 09, 2014, 09:01:37 PM »
Does Avast fix or remove Powelik?