Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2890113 times)

0 Members and 2 Guests are viewing this topic.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3615 on: April 27, 2015, 09:38:15 PM »
If and when AV-C is ready they will reveal the guilty party.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3617 on: April 28, 2015, 01:31:30 AM »
Thank you, Para-Noid, for the heads-up on this.
And folks remember when you have plug-ins activate as an on demand basiis,
so only when you trust it to run inside the browser.
And remember now you rarely need java, so when not needed uninstall.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3618 on: April 28, 2015, 02:29:21 PM »
Again critical hole in WP CMS: http://klikki.fi/adv/wordpress2.html (disclosed by Jouko Pynnonen )
Sucuri's analysis: http://klikki.fi/adv/wordpress2.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3619 on: April 28, 2015, 04:03:23 PM »
Yet another reason to have a good ad blocker and MalwareBytes Anti-Exploit

https://blog.malwarebytes.org/privacy-2/2015/04/ads-on-colouring-pages-website-lead-to-installs-explicit-content/?utm_source=Gplus&utm_medium=social

This is getting old in a hurry. The only thing a user can do is to use common sense and be alert and stay up to date with all of the
malicious on-goings on the web. Look before you leap. In other words do some research before you click. It may save you some anguish later.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3620 on: April 29, 2015, 07:27:46 AM »
Malware authors go a step further to access bank accounts

https://blog.avast.com/2015/04/27/malware-authors-go-a-step-further-to-access-bank-accounts/

Updated: Kaspersky leaves users open to FREAK attack

On this article you will see this statement: "All the anti-virus applications checked - Avast, Kaspersky and ESET - lower the security of TLS connections in one way or another says Hanno Bock."

http://www.scmagazineuk.com/updated-kaspersky-leaves-users-open-to-freak-attack/article/411470/

Hope Avast read this. Someone please attract my post to the moderators so we can get an answer/clarification about a fix or a solution. Thanks.
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3621 on: April 29, 2015, 07:33:03 AM »
Hope Avast read this. Someone please attract my post to the moderators so we can get an answer/clarification about a fix or a solution. Thanks.
See: https://forum.avast.com/index.php?topic=170164.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3622 on: April 29, 2015, 03:43:13 PM »
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3623 on: April 30, 2015, 09:29:04 AM »
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3624 on: April 30, 2015, 04:08:07 PM »
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3626 on: May 01, 2015, 05:00:51 PM »
Mozilla is phasing out HTTP in favor of HTTPS:
http://news.softpedia.com/news/Mozilla-Is-Phasing-Out-HTTP-Support-a-Legacy-Mode-Will-Be-Available-479895.shtml
and
https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-http/
and
https://letsencrypt.org/
Quote
Websites will be have "new features" disabled to pressure them into using TLS.

This all became possible because IE will soon join "Clippy" in the M$' Afterlife,
well at least that is what they plan for the future.

Also Google Chrome is planning to support the transition of HTTP through HTTPS.
Also to better thward off ad-blocking, conflicting with their main income scheme.

My personal question is why change unsecurity through another form of unsecurity driven by obscurity and encryption.

Malvertising detection will get harder. Loads and loads of website owners will continue to provide mixed and unsecure content and continue their unsecure misconfiguration of server and CMS (and plug-ins and themes) and endanger users further through outdated software and vulnerabilities.

First see to it that the protocol is configured securely, educate those that are responsible for a website's security and then think of a transition from http to https.

I have scanned many a so-called HTTPS Everywhere adopted website and what I found there did not make me particularly happy.
Scan for yourselves here: http://cyh.herokuapp.com/cyh  (online https and http security header scanner)

Also see loads and loads of sites where the log-in info go in plain txt over the wires.  :o

Browser developers in the first place should work on the client side,
not decide what should be on the server side, allthough they have a right to alert,
when and where something is going wrong.

Here a little background info and where the quote was taken from:
http://cryto.net/~joepie91/blog/2015/05/01/on-mozillas-forced-ssl/
link article  author = Joepie91.
And here a word from some-one that promotes the transition: http://moz.com/blog/seo-tips-https-ssl
link article author =  Cyrus Shepard

polonus

« Last Edit: May 01, 2015, 05:32:40 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3627 on: May 01, 2015, 07:02:50 PM »
“We Need Your Support” Nepal Earthquake 419 Spam

https://blog.malwarebytes.org/fraud-scam/2015/05/we-need-your-support-nepal-earthquake-419-spam/?utm_source=Gplus&utm_medium=social

There is always some idiot trying to prey on those with big hearts.
I have an idea on what to do with them...but it's illegal in the USA.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3628 on: May 01, 2015, 07:33:09 PM »
Google Password Alert for the second time bypassed: http://arstechnica.com/security/2015/04/30/behold-the-drop-dead-simply-exploit-that-nukes-googles-password-alert/
Advice: Do not use any Password Managers.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3629 on: May 01, 2015, 07:36:44 PM »
Definitely time to leave Chrome for something more secure