Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904771 times)

0 Members and 12 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3720 on: May 23, 2015, 10:48:11 PM »
Interesting resume on logjam's impact on IP and DNS: https://nohats.ca/wordpress/blog/2015/05/20/weakdh-and-ike-ipsec/
(article author = Paul Wouters).
And read this: http://cryptologie.net/article/270/the-logjam-attack/  (we need end to end security).

Somehow Google Chrome developers went for speed over security: TLS also provides an option for EDH: ephemeral Diffie-Hellman in a multiplicative group. We chose ECDHE because of the speed advantages: EDH in a 2048-bit group is plenty secure, but much slower.

polonus
« Last Edit: May 23, 2015, 10:53:38 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3721 on: May 25, 2015, 02:03:24 PM »
UAC Phishing Attack: http://blog.cylance.com/trick-me-once-shameonuac
Link article author = Derek Soeder

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3722 on: May 27, 2015, 12:03:48 AM »
Adware PUPs are getting nastier and more and more irritating - LSP hijackers with rootkit-elements start to resemble real malware - the distinctions grey out: https://blog.malwarebytes.org/security-threat/2015/05/fake-adblocker-bylekh-is-an-lsp-hijacker/  (link article author PIETER ARNTZ).

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3723 on: May 27, 2015, 12:43:15 AM »
New POS malware - new Alina variant and others: https://www.fireeye.com/blog/threat-research/2015/05/nitlovepos_another.html  link article authors: Nart Villeneuve, Daniel Regalado.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3724 on: May 27, 2015, 01:26:02 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3726 on: May 27, 2015, 07:29:19 PM »
Security researchers hindered by 0-day exploit strict export restrictions for dual use technology.
0-days can only to be acquired by government.
New rules to restrict export of surveillance-, hack en intrusion-software.
Robert Graham on this: http://blog.erratasec.com/2015/05/this-is-how-we-get-ants.html

"When you outlaw tools, outlaws are gonna use them" ;D

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3727 on: May 27, 2015, 08:36:18 PM »
iPhone Crash: What You Need To Know

https://blog.malwarebytes.org/mobile-2/2015/05/iphone-crash-what-you-need-to-know/?utm_source=Gplus&utm_medium=social

Be careful with what you do with any smartphone any time.
I use one free weather website and lo and behold there is a banner at the top "telling" me my phone is infected.
It even includes a "scan now" button. I figured it was a phishing ad and didn't tap scan. It isn't just malicious text(s)/email
one need to worry about. Before you click/tap ask yourself "if it's worth the risk?" Do your research before you wish you had.
I do online scans on various websites and a lot of people would be shocked at the risks they are taking. A website may seem innocent,
but then again "is it?" Always scan before you click. "Look before you leap" attitude is a must anymore.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3728 on: May 27, 2015, 10:38:10 PM »
iPhone Crash: What You Need To Know

https://blog.malwarebytes.org/mobile-2/2015/05/iphone-crash-what-you-need-to-know/?utm_source=Gplus&utm_medium=social

Be careful with what you do with any smartphone any time.
I use one free weather website and lo and behold there is a banner at the top "telling" me my phone is infected.
It even includes a "scan now" button. I figured it was a phishing ad and didn't tap scan. It isn't just malicious text(s)/email
one need to worry about. Before you click/tap ask yourself "if it's worth the risk?" Do your research before you wish you had.
I do online scans on various websites and a lot of people would be shocked at the risks they are taking. A website may seem innocent,
but then again "is it?" Always scan before you click. "Look before you leap" attitude is a must anymore.
In your case, I'd question why a weather app wants to scan for malware and what's a weather app contain that allowed it to scan
my device to find a virus in the first place.
If an app requires more permission than it needs to perform it's function. Don't install it.
As an example, If your Flashlight app requires permission to access anything other than your camera, I wouldn't install it.
The flashlight function needs access to the flash function of your camera and therefore shouldn't need access to anything beyond that.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3729 on: May 27, 2015, 10:48:50 PM »
Hi bob3160,

I agree with what Para-Noid says as we have seen mal-apps posing as genuine benevolent ones.
If you take certain things at face-value you take a gigantic risk.
That is why I think it was bad that Google banned ad-blockers on androids in their function of mal-ad blockers.
The "secret" Google team hunts for fraudulent adclicks, malvertisers et all, etc, but they cannot catch up with all.
Moreover the grey lines between adware/crapware and real persistent malware is becoming thinner and thinner,
We should be protected and at least. Well, do as Para_Noid says: "Look hard before you leap".
Scan: http://mypermissions.org/

polonus
« Last Edit: May 27, 2015, 10:52:17 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3730 on: May 28, 2015, 09:14:29 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline abruptum

  • Massive Poster
  • ****
  • Posts: 2460
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3732 on: May 28, 2015, 12:39:09 PM »
Beware: Hola VPN turns your PC into an exit node and sells your traffic


  http://www.ghacks.net/2015/05/28/beware-hola-vpn-turns-your-pc-into-an-exit-node-and-sells-your-traffic/

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3734 on: May 28, 2015, 08:17:56 PM »
« Last Edit: May 29, 2015, 12:21:43 AM by Para-Noid »
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.