Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2905031 times)

0 Members and 6 Guests are viewing this topic.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4246 on: November 15, 2015, 12:22:35 AM »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48597
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4247 on: November 15, 2015, 02:33:48 PM »
Windows 3.1 crash puts French airport out of commission
www.digitaltrends.com/computing/windows-3-1-crash-puts-french-airport-out-of-commission/
You certainly can't blame Windows 3.1 for this.
France and the world have more serious problems right now.  :'(
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4248 on: November 15, 2015, 05:18:46 PM »
WordPress sites have been attacked 3 1/2 times more often recently.
WP websites became attacked 7 times more often via (SEO)-spam and RFI attacks (remote file inclusion)
then their non-CMS-application counterparts.

WordPress has a problem according to the Imperva report, that shows all sorts of plug-ins and extensions are being developed for it for where security does not play any role whatsoever and is a last-resort-issue.
So new vulnerabilities and exploits are being detected over and over again. Moreover WordPress is based on PHP, which often comes not securely implemented by developers. Read the report here: http://www.imperva.com/docs/HII_Web_Application_Attack_Report_Ed6.pdf

More often then not these sites are being flagged and alerted for insecure websites but only after the fact, as such websites already have become compromised, attacked, defaced, malware ridden, spam-brewing and spewing, PHISHING and part of all sorts of mal-abuse under the sun. Part of such insecure websites are being taken down, in case of continuing abuse sites' accounts are suspended and/or ad-parked or terminated.

But I and some other here in the forums would like these sites set out as dangerous and open to all forms of abuse from one moment unto the other. Just like a truck should be taken off the road by a highway patrol when it has unsafe technology (slick tyres etc.) these websites with such obvious insecurity because of incompetence and negligenge, should not be allowed any longer to be part of the Interwebs. Users of the Internet would be rather thankful.

polonus (volunteer website security analyst and website error hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4249 on: November 15, 2015, 05:48:51 PM »
If it was me,

check used WP version, server software version and such.
And if a version is used a month after a patch/update has been released, block the site/IP and do not allow it until the patch/update is applied.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89139
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4250 on: November 15, 2015, 06:02:54 PM »
If it was me,

check used WP version, server software version and such.
And if a version is used a month after a patch/update has been released, block the site/IP and do not allow it until the patch/update is applied.


Good job it isn't you, a month is a mere blink of an eye for many. Some wait longer than that just to see if there is any adverse impact of an update/patch.

###
Cast you mind back to the forums software - avast too waited a long time before updating ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4251 on: November 15, 2015, 06:13:47 PM »
I did not mean that, DavidR. I meant to say there is no excuse for someone to put a WordPress site up, that leaves user enumeration enabled and his log-in info can be retrieved like plain txt as"for instance "user user" or "user admin"or whatever. Such nitwits/fools should better be taken off of the Interwebs because they come endangering themselves and everybody else. When a hoster does not informt them, the hoster is also responsible for every infection this might bring about. Still I see truckloads of websites which are such epic fails. Why we only detect them after the fact and when they have caused incidents and why aren't they set out before the fact for being lively dangerous? But it is just like with certain parents, some should never have children, still they have them.  ;D

polonus

For those that are now curious about a website's WP, read here: http://andrewrezk.com/how-to-spy-on-wordpress-sites-detect-their-wp-themes-plugins/  (link author = andrew rezk)  Do a scan here: http://scanwp.net/

Damian
« Last Edit: November 15, 2015, 06:19:55 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89139
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4252 on: November 15, 2015, 07:26:52 PM »
@ polonus
My post was directly to Eddy, whose post I quoted.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4254 on: November 16, 2015, 11:21:19 PM »
Google Chrome now also warning on fake websites: https://googleonlinesecurity.blogspot.jp/2015/11/safe-browsing-protection-from-even-more.html
These Google safe-browsing guys are giving me a good feeling. Next step warning for/against the technical epic fail websites?
I would welcome that  ;)

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3739
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4255 on: November 16, 2015, 11:32:58 PM »
Very scary ...

Beware of ads that use inaudible sound to link your phone, TV, tablet, and PC

http://arstechnica.com/tech-policy/2015/11/beware-of-ads-that-use-inaudible-sound-to-link-your-phone-tv-tablet-and-pc/

Greetz, Red.
OS: Win 10 / iOS 17 / Debian 12 / Tails 5
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4256 on: November 16, 2015, 11:52:46 PM »
Hi eric,

The Interwebs are turning into an ever more scary place. Png-file buffer overflow zero-day waiting for abuse to start:
http://www.openwall.com/lists/oss-security/2015/11/12/2
Hope we can upload png-files until this is being patched. Patch here:  libpng.sourceforge.net.
Vulnerable are all webbrowsers, Android, imageviewers, media-players and almost all Office=programmes.
« Last Edit: November 16, 2015, 11:56:14 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89139
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4257 on: November 17, 2015, 12:32:40 AM »
Very scary ...

Beware of ads that use inaudible sound to link your phone, TV, tablet, and PC

http://arstechnica.com/tech-policy/2015/11/beware-of-ads-that-use-inaudible-sound-to-link-your-phone-tv-tablet-and-pc/

Greetz, Red.

Ha, Smart TV, dumb user, I think not. From a little over 5 years ago I bought a Samsung LED TV and that was meant to be a Smart TV, there is absolutely no way I would ever hook up its network connection to give it internet access. I never trusted this so called smart title just because it connects to the internet, all this with no smart TV antivirus.

I don't have a microphone connected unless I'm specifically going to use it. The same is true of my netbook and its camera (blanked off).
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4258 on: November 17, 2015, 04:44:21 PM »
Individual targets will get pinpointed thanks to web analytics:
https://www2.fireeye.com/threat-intel-report-WITCHCOVEN.html
Some 100 websites have been purposefully being hacked and manipulated to redirect the visitors whithout them noticing to another website where WITCHCOVEN script is running to gather information and hand out a super cookie identification.
The attack then later makes use of pinpointed attacks against the target computer.

Wonder whether this is real info or just a American entertainment horror-story report coming from  behind a paywall subscription. Has this info been verified  :-[  Seems now Russian based....
Read from another source: https://www2.fireeye.com/threat-intel-report-WITCHCOVEN.html

polonus
« Last Edit: November 17, 2015, 05:17:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4259 on: November 17, 2015, 07:50:37 PM »
Conficer worm, still out there

Hidden Virus Discovered in Martel Police Body Camera
http://www.goipower.com/?pageId=40

Analysis date:   2015-11-12 11:06:25 UTC ( 5 days, 7 hours ago )
https://www.virustotal.com/en/file/dfc1f69b3efc968310ed8901eda055ea40fa488059a6a3763c356539820ccc3e/analysis/



« Last Edit: November 17, 2015, 07:52:39 PM by Pondus »