Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904895 times)

0 Members and 8 Guests are viewing this topic.

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4305 on: December 03, 2015, 04:56:50 AM »
For most people life is to short to read every EULA and that is what most companies hope for.
Speaking of which
« Last Edit: December 03, 2015, 04:59:07 AM by ehmen »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4307 on: December 03, 2015, 06:24:02 PM »
Hundreds of pr0n-sites source of malicious ads: https://blog.malwarebytes.org/malvertising-2/2015/12/large-number-of-adult-sites-distribute-malware-via-adxpansion-malvertising/

polonus
Polonus, do you have any info about this kind of malware that could be converted into a blog article?
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4308 on: December 03, 2015, 06:58:13 PM »
Hi Lisandro,

When it goes into a blog article warn about the nature of the adxpansion threat e.g. explicit adult content.
This is not suitable info for minors!
Besides this has been all over the news at MBAM forum and other places,
so what would be the additional avast blog content value?
But here then is the story in a nutshell and understandable for a greater user base.
It all comes down to cybercriminal fraudulent adxpansion abuse.
Read here: https://www.mywot.com/en/scorecard/adxpansion.com?utm_source=addon&utm_content=popup
This is classified as a 34% high risk site. The malicious manipulation of the ads is not done by the parties that buy ads, but by third parties that manipulate.
We see high risk vulnerabilities here. It is a known Flash ad/exploit attack scheme as this technique simply relies on a disguised Flash advert that downloads its own exploit and payload. The traffic for ads it seeks to malcreate runs in the millions of clicks...  So disabling or uninstall Flash or enable it on demand only could help protect.
Like DirectRev Malvertising this Uses Self Sufficient Flash 0Day.
The ad is booby-trapped such that it silently loads an external URL
and that is not a direct no-no in unethical ad-serving for the adlaunching industry, so can be abused easily.
See observed sub-domains: https://www.virustotal.com/nl/domain/adxpansion.com/information/

This site for instance that was used in the hack was earlier hacked and compromised, so found to be vulnerable
-malenkiyprince dot ru
re: -http://malenkiyprince.otel-v-krimu.ru/aan.txt

The Flash exploit used was described here: http://malware.dontneedcoffee.com/2015/10/cve-2015-7645.html

Here it was not detected and this should be so under normal instances: http://www.stwhisper.com/www.malenkiyprince.ru

More on this malcode  issue here: http://avpclub.alone.tw/discuz/redirect.php?tid=53748&goto=lastpost

So now you see how devious this is and why an adult user should never go on to the Internet without a decent adblocker and an good script blocker,

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: December 03, 2015, 10:44:31 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4310 on: December 05, 2015, 01:22:50 PM »
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4311 on: December 05, 2015, 05:07:01 PM »
Kicking in an open door here: http://www.darkreading.com/vulnerabilities---threats/the-programming-languages-that-spawn-the-most-software-vulnerabilities/d/d-id/1323397?
PHP, ASP Web scripting languages breed more vulnerabilities than Java, .NET programming platforms, Veracode's new state of software security report says.
And it still is very much the truth: Chris Wysopal: "When I see a breach, one of the things that sticks out in my head is 'I'll bet that was a PHP site.'"

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4313 on: December 07, 2015, 11:24:01 AM »
OpenSSL Security Advisory [3 Dec 2015]
http://openssl.org/news/secadv/20151203.txt
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4314 on: December 08, 2015, 03:17:27 PM »
Malvertising returns to DailyMotion again: https://blog.malwarebytes.org/malvertising-2/2015/12/malvertising-hits-dailymotion-serves-up-angler-ek/
The fake traffic schemes that are rotting your Internet: http://www.bloomberg.com/features/2015-click-fraud/

pol
« Last Edit: December 08, 2015, 03:19:25 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4315 on: December 09, 2015, 07:27:35 PM »
Spy-malware researchers life became threatened by malcreant(s): https://citizenlab.org/2015/12/packrat-report/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4316 on: December 09, 2015, 08:47:43 PM »
Found this just wo days old Malwarebytes blogpost about Dailymotion malvertising: https://blog.malwarebytes.org/malvertising-2/2015/12/malvertising-hits-dailymotion-serves-up-angler-ek/

Hope that adblockers are enough to protect casual users from these kind of things. :-\

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4317 on: December 10, 2015, 12:19:14 AM »
Hi Pernaman,

On the other hand the leaking of private data goes on for instance Dutch medical websites and Dutch hospital websites. These sites will leak user health information to commercial third parties. Data-services like AddThis and ShareThis are known to create such user tracking profiles for visitor webhistory, search queries, etc. Trackers were only removed after Dutch TV journalists had asked questions. So a decent adtrack-blocker is a tool we cannot go without for our own good...

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4319 on: December 10, 2015, 07:39:23 AM »
Microsoft Security Bulletin Summary for December 2015
https://technet.microsoft.com/en-us/library/security/ms15-dec.aspx
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0