Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2889701 times)

0 Members and 6 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3585 on: April 21, 2015, 09:06:59 AM »
Do not continue using Java 7: http://www.infoworld.com/article/2909685/application-development/oracle-cutting-publicly-available-security-fixes-for-java-7-this-month.html  link article author = Paul Krill.
Do not use Java when you do not need java, else update manually to Java 8.
Also consider the Ask toolbar that Java bundles, you might not like to have it on your OS!

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3586 on: April 21, 2015, 02:47:05 PM »
"Also consider the Ask toolbar that Java bundles, you might not like to have it on your OS!"
If you've got Unchecky installed, it will automatically uncheck the installation of the Ask Toolbar,
even if you happen to miss that nasty addition.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3587 on: April 21, 2015, 03:41:09 PM »
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline abruptum

  • Massive Poster
  • ****
  • Posts: 2460
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3588 on: April 21, 2015, 05:37:11 PM »

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3589 on: April 22, 2015, 08:29:55 AM »
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3590 on: April 22, 2015, 10:17:40 AM »
Security Advisory: XSS Vulnerability Affecting Multiple WordPress Plugins
https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3591 on: April 22, 2015, 08:58:18 PM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3592 on: April 22, 2015, 09:07:41 PM »
Failed Apple Rootpipe Fix Leaves Backdoor On All Macs, Researchers Claim
http://www.forbes.com/sites/thomasbrewster/2015/04/19/apple-fails-to-patch-rootpipe/

1,500 iOS apps have HTTPS-crippling bug. Is one of them on your device?

http://arstechnica.com/security/2015/04/1500-ios-apps-have-https-crippling-bug-is-one-of-them-on-your-device/


and i thought Mac`s was fault free    ;D


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3593 on: April 22, 2015, 10:32:48 PM »
Implimenting HTTPS Everywhere will make malvertisers harder to detect.
Also read: https://threatpost.com/ad-networks-ripe-for-abuse-via-malvertising/111840

polonus

« Last Edit: April 22, 2015, 10:36:19 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3594 on: April 22, 2015, 11:41:11 PM »
Implimenting HTTPS Everywhere will make malvertisers harder to detect.
Also read: https://threatpost.com/ad-networks-ripe-for-abuse-via-malvertising/111840

polonus
I remember when HTTPS Everywhere was all the rage. (It wasn't that long ago either.....)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3595 on: April 22, 2015, 11:51:34 PM »
Implimenting HTTPS Everywhere will make malvertisers harder to detect.
Also read: https://threatpost.com/ad-networks-ripe-for-abuse-via-malvertising/111840

polonus
I remember when HTTPS Everywhere was all the rage. (It wasn't that long ago either.....)

And I remember I was raging against its use ;D

For a very short time I considered changing my position as avast now scans https content (but not on all OSes), but I'm still of the same position on forcing https. There are some areas where it can help combat 'man in the middle attacks,' but now see there are other compromising issues.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3596 on: April 22, 2015, 11:57:50 PM »
Hi bob3160 and DavidR,

Encryption is fine, but when there is malicious code and it comes in in an encrypted way and you can not scan or check this in advance. What then? And what you say, bob3160, what about https sites with plain txt log-ins. I see a lot of these still. A lot of implementation of https everywhere adopted sites is also weak - not to say rather insecure- , and so here we go again. What looks right at a first glance, should not always be so in practice.
Well, do you see the problem there? Moreover these malvertising campaigns, lately through an obscure Bulgarian domain, only lasts a couple of hours, but could make an awful lot of victim. A decent adblocker is a must nowadays.

polonus
« Last Edit: April 22, 2015, 11:59:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3597 on: April 23, 2015, 12:16:53 AM »
Hi bob3160 and DavidR,

Encryption is fine, but when there is malicious code and it comes in in an encrypted way and you can not scan or check this in advance. What then? And what you say, bob3160, what about https sites with plain txt log-ins. I see a lot of these still. A lot of implementation of https everywhere adopted sites is also weak - not to say rather insecure- , and so here we go again. What looks right at a first glance, should not always be so in practice.
Well, do you see the problem there? Moreover these malvertising campaigns, lately through an obscure Bulgarian domain, only lasts a couple of hours, but could make an awful lot of victim. A decent adblocker is a must nowadays.

polonus
I like David, always warned against using HTTPS Everywhere. I haven't changed my mind. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3598 on: April 23, 2015, 12:20:46 AM »
Hi bob3160,

US users come under special malvertisement threat during U.S. federal holidays and three-day weekends,
Malvertisers from other part of the world have calenders up to just pick these days.
Google removes hundreds of million bad ads, but of course always some will slip through.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3599 on: April 23, 2015, 12:41:12 AM »
Please enlighten me, what's wrong with HTTPS Everywhere?  ???
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.