Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904501 times)

0 Members and 11 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4380 on: January 06, 2016, 11:34:50 AM »
Security Notification and Linode Manager Password Reset
http://status.linode.com/incidents/ghdlhfnfngnh
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4382 on: January 07, 2016, 09:40:34 AM »
Microsoft pulling support for Internet Explorer 8, 9, 10

http://money.cnn.com/2016/01/06/technology/microsoft-internet-explorer-support/
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4384 on: January 07, 2016, 03:34:56 PM »
Attackers can take over websites. 25% of websites run the WordPress CMS.
New WordPress hole, users should update asap:
https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
Re commit: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87

With WP all files are inside a public folder,
normally one should only have an index.php, a .htaccess file and CSS/JS/Images files in there.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4385 on: January 07, 2016, 03:47:00 PM »
Attackers can take over websites. 25% of websites run the WordPress CMS.
New WordPress hole, users should update asap:
https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
Re commit: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87

With WP all files are inside a public folder,
normally one should only have an index.php, a .htaccess file and CSS/JS/Images files in there.

polonus
And the WP site alreeady runs 4.5 :)
http://prntscr.com/9n5uva
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4387 on: January 07, 2016, 11:04:46 PM »
Pardon me but...every time I try to find the WP version using wappalyzer I can't find it.
What am I doing wrong?  ??? Color me frustrated.  ??? ::) ???
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4388 on: January 07, 2016, 11:06:30 PM »
Pardon me but...every time I try to find the WP version using wappalyzer I can't find it.
What am I doing wrong?  ??? Color me frustrated.  ??? ::) ???

Wappalyzer sometimes cant get the version and you can also block the version number on Apache and some other softwares :)

Look at Wordpress.org with Wappalyzer, it should you a version number.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4389 on: January 07, 2016, 11:15:48 PM »
Hi Steven Winderlich and Para-Noid,

Easiest way is to go here: http://www.wpthemedetector.com/
Whenever you know there is WP used as CMS, do a scan here: hackertarget.com/wordpress-security-scan/
Here you can do a simple scan for version number, outdated WP plug-ins, whether there is major insecurity like user enumeration or directory listing enabled  :o etc.
Use this bookmarklet: https://codex.wordpress.org/Press_This
The bookmark calls http://example.com/wp-admin/press-this.php?u=&t=&s=&i=

u = the url of the current page
t = the title of the current page
s = the text selection from the current page
i = url of an image file
Edit the bookmark within your browser to change the values passed if necessary.

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: January 07, 2016, 11:21:52 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4390 on: January 07, 2016, 11:20:21 PM »
They need to do some updates. http://prntscr.com/9nbs6q

Look at the NGinx version of Centos.org, or the Apache version on SUSE.com.......Its ridiculous.

@Damian: Check http://gsd-drolshagen.de/site/ on your link and look at the results.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4391 on: January 07, 2016, 11:34:41 PM »
Hi Steven Winderlich, you are right, see it now, some work to be done there by the admins.

WP - WP configuration:Custom. Web application version:
WordPress version: WordPress
Wordpress version from source: 4.0.9
Wordpress Version 4.0 based on: -http://gsd-drolshagen.de/site//wp-admin/js/common.js
WordPress directory: -http://gsd-drolshagen.de/site/wp-content
WordPress theme: -http://gsd-drolshagen.de/site/wp-content/themes/mutootheme/
Author:mutoo GmbH
Description:Template from mutoo
WordPress version outdated: Upgrade required.
Outdated WordPress Found: WordPress Under 4.2

Plug-ins to be checked and updated
The following plugins were detected by reading the HTML source of the WordPress sites front page.

responsive-slider   latest release (0.1.8)
http://alienwp.com/plugins/responsive-slider
nivo-slider   
wp-google-maps   latest release (6.3.04)
http://www.wpgmaps.com
contact-form-7   latest release (4.3.1)
http://contactform7.com/

But also jQuery library issues: -http://gsd-drolshagen.de
Detected libraries:
jquery-migrate - 1.2.1 : -http://gsd-drolshagen.de/site/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
jquery - 1.11.1 : -http://gsd-drolshagen.de/site/wp-includes/js/jquery/jquery.js?ver=1.11.1
1 vulnerable library detected

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4392 on: January 07, 2016, 11:38:15 PM »
@Damian: Remember this site?  http://www.druckerei-hachenburg.de/

Still alot to update, IDIOTIC ADMINS I CAN SAY.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4393 on: January 09, 2016, 09:29:13 AM »
[Security-announce] NEW VMSA-2016-0001 VMware ESXi, Workstation, Player, and Fusion updates address important guest privilege escalation vulnerability
http://lists.vmware.com/pipermail/security-announce/2016/000316.html
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.