Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2902391 times)

0 Members and 3 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4065 on: September 12, 2015, 10:36:27 AM »
Hi DavidR,

Still hope Avast will sign AOS add-on (as they said they would with fx version 41) as signing software is always generally speaking a good practice. DrWeb's also signed their extension for that matter.

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4066 on: September 12, 2015, 11:02:46 AM »
Too many things goeing wrong at FireEye's lately  ::): http://www.theregister.co.uk/2015/09/08/fireeye_0day/
Re: https://www.insinuator.net/2015/09/sending-mixed-signals-what-can-happen-in-the-course-of-vulnerability-disclosure/
FireEye reacted that propriety software secrets were revealed by these German info security researchers.

Question of money or a lack of knowledgable expertise, e.g. surplus of generically educated IT staff,
but a lack of technical IT specialists, and that is obvious through recent major security  incidents
(data breaches, compromittal, insecure practices, general incompetence)?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4068 on: September 13, 2015, 02:18:25 PM »
You certainly want a datingsite to be encrypted, but often it is not: https://www.eff.org/deeplinks/2012/02/six-heartbreaking-truths-about-online-dating-privacy

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4070 on: September 15, 2015, 01:38:57 PM »
Mal-ad campaign goes on almost unnoticed for weeksand weeks with Angler exploit redirects, 139 million monthly British eBay visitors were at risk  :o.
Read: https://blog.malwarebytes.org/malvertising-2/2015/09/large-malvertising-campaign-goes-almost-undetected/
So, my dear Avast friends, polonus will I keep his adblocker with special subscription lists up and running.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89118
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4072 on: September 15, 2015, 04:43:51 PM »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4073 on: September 15, 2015, 11:18:25 PM »
Corrupted Firmware on hacked Cisco-Routers detected: https://www.fireeye.com/blog/threat-research/2015/09/synful_knock_-_acis.html
The routers were backdoored to be able compromise several modules.
Link article authors: FireEye Threat Research's By Bill Hau and  Tony Lee.

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48586
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4075 on: September 17, 2015, 10:11:31 PM »
Phishing Attempt - Caution!

If you look at the detailed senders address carefully, you should see this didn't really come from Wells Fargo.


The spelling and grammar has gotten much better and more convincing.
However, if you hover your mouse over the included "signon" link you'll notice it doesn't go to Wells Fargo:

This is a sure sign of a Phishing attempt. Don't be the fool that falls for it. Stay vigilant and be suspicious any time
you receive something like this from your bank or other type of financial institution.
Never click on included link. If you aren't sure, take the initiative and, contact your financial institution on your own.

Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4076 on: September 18, 2015, 11:36:05 PM »
Thousands and thousands of hacked WordPress sites are spreading malware, read here: https://blog.sucuri.net/2015/09/wordpress-malware-active-visitortracker-campaign.html  article author is Sucuri's Daniel Cid.
Attackers seems to use leaks in WP plug-ins. WP websites often haven't updated to the latests CMS software versions,
plug-ins can be outdated and themes can have vulnerable code. To check your security with a quick and dirty cold reconnaissance scan go here: https://hackertarget.com/wordpress-security-scan/
I strongly advise WP website owners, website admins, pro-active hosters and other IT staff to do so.

One thing that will make you vulnerable is outdated, unpatched or even worse: left code. Do not leave your visitors at risk, update, patch and secure. Also we find a lot of server misconfiguration and security headers missing. It is not only website code, it is also hosters that do not take security of the domains they service at heart. Excessive server header proliferation (to the world and attackers) is wide-spread. Outdated and vulnerable server code is found. Do not be an ignorant and have yourself informed by doing the necessary scans.

polonus (volunteer website security analyst and website eror-hunter)

P.S. Just an example where we find the code Daniel Cid is refering to: -http://www.brainvalue.com/en/newsroom-en/feed/rss/newsroom/newsroom-2?format=feed
Consider: -http://www.domxssscanner.com/scan?url=http%3A%2F%2Fbrainvalue.com%2Fcomponents%2Fcom_contact%2Fcommon_configs%2Fvisitor.php%3Fmob%3D1
& read: http://wordpress.stackexchange.com/questions/188763/cookiechoices-js-keeps-reappearing-without-caching-plugin

Damian
« Last Edit: September 19, 2015, 12:12:27 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48586
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4077 on: September 19, 2015, 12:10:41 AM »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4078 on: September 19, 2015, 12:30:19 AM »
Hi bob3160,

???? because there is a brand new WP update out - 4.3.1

Even a better scan here: https://sitecheck.sucuri.net/results/bob3160.wordpress.com
Analysing on https://s2.wp.com/wp-content I found this plug-in questionable: ie-sitemode
You may not have it, but I see no update address for that code, has it been left?
This has some sources and sinks, but I see no immediate threat: -http://www.domxssscanner.com/scan?url=http%3A%2F%2F0.gravatar.com%2Fjs%2Fgprofiles.js%3Fver%3D201538y
Nothing here: -http://www.domxssscanner.com/scan?url=https%3A%2F%2Fs2.wp.com%2Fwp-content%2Fmu-plugins%2Fgravatar-hovercards%2Fwpgroho.js%3Fm%3D1380573781g
Some sources and sinks:- -http://www.domxssscanner.com/scan?url=-https%3A%2F%2Fplatform.twitter.com%2Fwidgets.js%3Fver%3D20111117
and all touching on:  -http://d.rmgserving.com/rmgdsc/newcafv2.js?1.1
as goes for this: -http://www.domxssscanner.com/scan?url=https%3A%2F%2Fs.skimresources.com%2Fjs%2F725X1342.skimlinks.js
and finally this-http://www.domxssscanner.com/scan?url=http%3A%2F%2Fstats.wp.com%2Fw.js%3F48
which most adblockers block for us: uMatrix has prevented the following page from loading:
-http://stats.wp.com/w.js?48

You can be assured that website is secure as far as I could establish. And Sucuri agrees with me.

See the website risk status that Netcraft gives: http://toolbar.netcraft.com/site_report?url=https://bob3160.wordpress.com
but that could have to do with the fact Netcraft sees this site for the first time, that is why the 7 red out of 10 risk score.

All's well, bob3160, ;)

Damian
« Last Edit: September 19, 2015, 12:34:42 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48586
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4079 on: September 19, 2015, 12:31:50 AM »
ie-sitemode is there because I use Windows Live Writer?
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet