Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904796 times)

0 Members and 5 Guests are viewing this topic.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4156 on: October 15, 2015, 11:24:11 PM »
Be aware your free download could have come bundled with an unwanted guest, PC Backup.
PCBackup is a misleading program and there has been malware detected inside it.
It can also come installed on your computer by Dell or other computer manufacturers.
Read: http://www.shouldiremoveit.com/MyPC-Backup-19242-program.aspx
Many PC manufacturers have it installed like Dell, Acer, Lenovo.
Go to configuration and uninstall the program. 68% of good people uninstall it!
I just heard from someone that it is a privacy risk, because they have the info you shared with those that installed it,
mail address and who knows what more, so also a privacy injunction there.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4157 on: October 15, 2015, 11:49:18 PM »
Be aware your free download could have come bundled with an unwanted guest, PC Backup.
PCBackup is a misleading program and there has been malware detected inside it.
It can also come installed on your computer by Dell or other computer manufacturers.
Read: http://www.shouldiremoveit.com/MyPC-Backup-19242-program.aspx
Many PC manufacturers have it installed like Dell, Acer, Lenovo.
Go to configuration and uninstall the program. 68% of good people uninstall it!
I just heard from someone that it is a privacy risk, because they have the info you shared with those that installed it,
mail address and who knows what more, so also a privacy injunction there.

polonus
They already have the information the second you register your product or if bought on line, you also supply that information.



Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4158 on: October 16, 2015, 01:09:17 AM »
Hi bob3160,

Thank you for that info bob, but it is new to me that when you give that info to the computer manufacturer it also gets to all the bundler software firms, How should PCBack up know my mail address (or google all account serves it up to them), we bought something online and they automattically filled out the age of my sprouse  :o, you cannot have any secrets on the Interwebs anymore  ;D. They could have been somewhat more discrete?  ;D

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4162 on: October 18, 2015, 04:30:22 PM »
Sinkholed domain returned from the graveyard to serve in ad-fest:
https://forum.avast.com/index.php?topic=177906.0
So not only parked domains deserve this fate, others also will serve up ads from inside the grave.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4163 on: October 19, 2015, 05:32:08 PM »
One million SSL certificates still using “insecure” SHA-1 algorithm
Read Netcraft's report here: http://news.netcraft.com/archives/2015/10/19/one-million-ssl-certificates-still-using-insecure-sha-1-algorithm.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4164 on: October 20, 2015, 04:47:54 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4165 on: October 20, 2015, 05:43:27 PM »
Finfisher the spy software of choice for governments to monitor their citizens.
32 governments now known to use this spy software from Germany.
Read this report by Bill Marczak, John Scott-Railton, Adam Senft, Irene Poetranto, and Sarah McKune: https://citizenlab.org/2015/10/mapping-finfishers-continuing-proliferation/
After all of the Hack Team hack commotion, governments haven't really shown to act with more caution in this field.  :(

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4166 on: October 20, 2015, 05:57:15 PM »
Finfisher the spy software of choice for governments to monitor their citizens.
32 governments now known to use this spy software from Germany.
Read this report by Bill Marczak, John Scott-Railton, Adam Senft, Irene Poetranto, and Sarah McKune: https://citizenlab.org/2015/10/mapping-finfishers-continuing-proliferation/
After all of the Hack Team hack commotion, governments haven't really shown to act with more caution in this field.  :(

polonus
What do you expect when the head of the CIA uses a private email hosted at AOL ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4167 on: October 20, 2015, 06:08:01 PM »
Hi bob3160,

In the example you mention. Isn't it always the lucky that draw the winning card and gets such a job, but there is no guarantee he should also be among the brightest.  ;D

On the detection of Finfisher read here: http://www.netmagellan.com/how-i-removed-a-finfisher-finspy-malware-infection-1814.html where a tool by the name of Detekt was used, and another interesting article: https://citizenlab.org/2013/04/for-their-eyes-only-2/

However it seems there is a lot of cloak -and-dagger stories and desinformation spin involved where such spyware is concerned.  ;)

Seems social engineering is the main route of infection - this spyware has nothing to do with your usage of firefox. it probably comes with a similar filename/logo/description to trick users into allowing it access through firewalls etc (via e-mail).

So for us all here two golden rules:
1.Always update what you have to update (use Avast Update Tool)), patch what you have to patch.
2.Never fall for social engineering.
This is two things that everyone could/should do to feel better protected.

Damian
« Last Edit: October 20, 2015, 06:12:23 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4168 on: October 21, 2015, 12:31:15 AM »
Is this a right step into the right direction? Large browsers now all to support free SSL-service Let's Encrypt.
Re: https://letsencrypt.org/certificates/
Has any of the parties involved also considered this could be a golden opportunity for cybercriminals, when the client-side software comes backdoored? But again cybercrime could afford fraudulous certs already anyway.
On the other hand you do not want the (backdoored) encryption privilage to be exclusively to be with Governments and Big Corps, do you now?
How much of your freedom will you hand over for more privacy as there always will be some sort of tradeoff somewhere?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4169 on: October 21, 2015, 05:31:19 PM »
New security feature coming to firefox in the soon future: http://thenextweb.com/apps/2015/10/21/firefox-is-testing-marking-any-page-that-sends-passwords-over-http-as-insecure/
I have these warnings already a long time from an extension I work in Google Chrome SaferChrome Security report,
alongside runs Browser JSGuard extension (e.g. supported by the Govnmnt of India), warning me about all sort of redirections, as there are: Hidden iFrame(s) Redirections, UnAuthorized Redirections, Encode javascript, External Domain Requests & Trackers.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!