Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2905194 times)

0 Members and 10 Guests are viewing this topic.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3660 on: May 06, 2015, 05:58:32 AM »
Computer Science > Cryptography and Security
A New Covert Channel over Cellular Voice Channel in Smartphones

http://arxiv.org/abs/1504.05647
PDF:  http://arxiv.org/ftp/arxiv/papers/1504/1504.05647.pdf
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3661 on: May 06, 2015, 08:08:08 AM »
Rombertik, dangerous password stealing malware that ruins the MBR: http://blogs.cisco.com/security/talos/rombertik
link article was authored by Ben Baker and Alex Chiu.

polonus
More on this....................

Rombertik malware wipes hard drives to prevent detection
http://www.zdnet.com/article/rombertik-malware-wipes-hard-drives-to-prevent-detection/

Threat Spotlight: Rombertik – Gazing Past the Smoke, Mirrors, and Trapdoors

http://blogs.cisco.com/security/talos/rombertik


Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3663 on: May 06, 2015, 10:07:28 PM »
Adware a big, big problem: http://www.theverge.com/2015/5/6/8557843/google-adware-survey-ad-injectors-security-malware
link article author = By Russell Brandom 

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3664 on: May 06, 2015, 11:21:05 PM »
Always the same small circle of malvertising ad-injecting abusers.
Quote from Google:
Quote
A small number of software developers support the vast majority of these injectors who in turn syndicate from the larger ad ecosystem. We have contacted the Chrome Web Store and the advertisers targeted by ad injectors to alert each of the deceptive practices involved.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3665 on: May 07, 2015, 02:41:37 PM »
Another critical update for WordPress: https://wordpress.org/news/2015/04/wordpress-4-2-1/

What are the most prevalent WP security risks as I know them from my third party cold reconnaissance scanning.
Quote
WordPress Plugins check against the latest versions. Plugins are a source of many security vulnerabilities within WordPress installations, always keep them updated to the latest version available and check the developers plugin page for information about security related updates and fixes.

WordPress Theme
The theme has been found by examining the path /wp-content/themes/ *theme name* /

For instance: twentyeleven
While plugins get a lot of attention when it comes to security vulnerabilities, themes are another source of security vulnerabilities within WordPress installations, always keep them updated to the latest version available and check the developers theme page for information about security related updates and fixes.

Warning User Enumeration is possible
The first two user ID's were tested to determine if user enumeration is possible.
For instance on this website:
User ID 1 : speedrider
User ID 2 : None
It is recommended to rename the admin user account to reduce the chance of brute force attacks occurring. As this will reduce the chance of automated password attackers gaining access. However it is important to understand that if the author archives are enabled it is usually possible to enumerate all users within a WordPress installation.

Only the first two user ID's were tested

Directory Indexing
Directory indexing was tested on the /wp-content/uploads/ and /wp-content/plugins/ directores. It does not seem to be possible to list the directory contents using this method. Note that other directories may have this web server feature enabled, so ensure you check other folders in your installation. It is good practice to ensure directory indexing is disabled for your full WordPress installation either through the web server configuration or .htaccess.

Compare to linked sites and linked Javascripts Scan -  Quote Info Credits go to WordPress Security Scan.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3668 on: May 08, 2015, 09:02:48 AM »
Cisco UCS Central Software Arbitrary Command Execution Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150506-ucsc
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3669 on: May 08, 2015, 03:46:36 PM »
Passwords from hacked Word Press websites stolen in malware campaign:
http://research.zscaler.com/2015/05/compromised-wordpress-sites-leaking.html
Link site Analysis by - Sameer Patil & Deepen Desai

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3671 on: May 08, 2015, 06:24:12 PM »
Hi Para-Noid,

WOT has two reds for this: cs.adxpansion dot com: https://www.mywot.com/en/scorecard/cs.adxpansion.com
several negative WOT user reports as well.
Webutation also flags: https://www.virustotal.com/nl/url/40801dedf9be8615fc82d1429aa2f1a688938f40457cef028d3e472ccdea824b/analysis/
See: http://cookiepedia.co.uk/host/cs.adxpansion.com
See the IP and server mitigation here: http://toolbar.netcraft.com/site_report?url=cs.adxpansion.com
Service = tcpwrapped - TCP Wrapper is a client side software solution for Linux/BSD machines which provides firewall features. It monitors all incoming packets to the machine and if an external node attempts to connect, the software checks to see if the node is authorized based on various criteria you can specify (80/tcp connection)
Hosted: http://www.dnsinspect.com/gammanetworking.com/1431102021

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline MikeBCda

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2247
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3673 on: May 09, 2015, 12:04:13 AM »
Just looking for suckers!

https://blog.malwarebytes.org/fraud-scam/2015/05/your-account-paypal-has-been-limited-phishing-scam/?utm_source=gplus&utm_medium=social
That IP has a history and it's not good https://www.virustotal.com/en/ip-address/72.55.165.59/information/
That sample screen posted in the link does have one obvious indication that it's a scam ... PayPal has made the point over and over again that it will never, ever, address you as "Dear valued customer" or other generic greeting, but will instead always address you by your full registered name of record, whether individual or enterprise.

Since surely there are ways for a scammer to get this info, they're either too dumb or too lazy to be bothered.  Or maybe they're just gambling that no one ever reads PayPal's (or anyone else's) security warnings.
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-11, Firefox 51.0
(default). 320 gig HD, 15Mb DSL, Win firewall, Avast 12.3.2280 free, SpywareBlaster, MBAM Prem., Crypto-Prevent

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3674 on: May 09, 2015, 12:12:02 AM »
Misspellings and grammatical mistakes also always is a good give-away, things aren't what they should be - so scam.
These folks weren't very attentive at school, while they were contemplating other schemes.

polonus
« Last Edit: May 09, 2015, 12:19:18 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!