Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904463 times)

0 Members and 4 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4545 on: March 09, 2016, 10:58:59 AM »
Microsoft Security Bulletin Summary for March 2016
https://technet.microsoft.com/en-us/library/security/ms16-mar.aspx
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4546 on: March 10, 2016, 12:20:39 PM »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4547 on: March 11, 2016, 03:48:24 PM »
Seagate employees’ W-2 forms exposed in another payroll phish

http://arstechnica.com/security/2016/03/seagate-employees-w-2-forms-exposed-in-another-payroll-phish/

It’s 2016, so why is the world still falling for Office macro malware?

http://arstechnica.com/security/2016/03/its-2016-so-why-is-the-world-still-falling-for-office-macro-malware/

How Minecraft undermined my digital defences

http://www.bbc.com/news/technology-34474883

Want Safer Passwords? Don’t Change Them So Often

http://www.wired.com/2016/03/want-safer-passwords-dont-change-often/
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4548 on: March 13, 2016, 01:32:47 AM »
Firm sells tablet/computers for children with vulnerable Flash Player  :o
Read: http://www.mikecarthy.com/offensive-security/childrens-tablet-computer-vulnerable-flash-exploit/
So Polonus would like to know and scanned the firms server address for DROWn attcak vulnerability and DANG.
So our poor kids are additionally also threatened from the DROWn attack  :o
see here: https://test.drownattack.com/?site=LeapFrog.com

polonus (volunteer website security analyst and website error.hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4549 on: March 13, 2016, 01:38:47 AM »
Firm sells tablet/computers for children with vulnerable Flash Player  :o
Read: http://www.mikecarthy.com/offensive-security/childrens-tablet-computer-vulnerable-flash-exploit/
So Polonus would like to know and scanned the firms server address for DROWn attcak vulnerability and DANG.
So our poor kids are additionally also threatened from the DROWn attack  :o
see here: https://test.drownattack.com/?site=LeapFrog.com

polonus (volunteer website security analyst and website error.hunter)
http://www.ibtimes.co.uk/leapfrog-weak-security-kid-friendly-tablet-could-leave-children-exposed-online-snooping-1548905
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4551 on: March 13, 2016, 10:49:14 PM »
Cloud service providers are failing when it comes to protecting their clients against the recently disclosed DROWN attack, with only 33 providers having patched their servers from a total of 653 surveyed services. : http://news.softpedia.com/news/one-week-later-drown-vulnerability-still-affects-620-of-653-cloud-services-501599.shtml
link article author -  Catalin Cimpanu.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4552 on: March 13, 2016, 10:57:28 PM »
Cloud service providers are failing when it comes to protecting their clients against the recently disclosed DROWN attack, with only 33 providers having patched their servers from a total of 653 surveyed services. : http://news.softpedia.com/news/one-week-later-drown-vulnerability-still-affects-620-of-653-cloud-services-501599.shtml
link article author -  Catalin Cimpanu.

polonus
Not much help when they don't list the effected and patched services.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4553 on: March 13, 2016, 11:24:51 PM »
Hi bob3160,

This is one outside that 5.1% patched against DROWn with CloudFlare, Inc. as Netblock owner.
https://test.drownattack.com/?site=ns1.hostmonster.com
You could test here for your cloud service of choice: https://test.drownattack.com/?site=
But DROWn should be patched on all underlying servers and services that share that same certificate and are vulnerable,
that it is why that exploit is that lively dangerous. Forgotten to mitigate or patch somewhere or forgotten to disable SSLv2/3  and DANG PRESTO! :o

polonus

P.S. And do not forget to scan your cloud apps: example : https://test.drownattack.com/?site=just.cloud  & https://test.drownattack.com/?site=express.vpn  and a long row of other vulnerable app services.

Oh, and we have to see this exploit in a clear light as not everybody will spend 400 bucks on resources to be able to compromise to decrypt the key  ;) But some parties might take an interest there.... (info credits: Eric Wingfield)

Damian
« Last Edit: March 13, 2016, 11:41:25 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4554 on: March 14, 2016, 02:09:44 PM »
3 year old java bug, still there

Broken security fix in Oracle Java SE 7/8/9
http://seclists.org/fulldisclosure/2016/Mar/31


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4555 on: March 14, 2016, 02:28:08 PM »
How can you quarrel about mouseclick-surveillance, when we all already got it?
The only discussion is on making that mouse-click surveillance even simpler and more straight-forward,
to do away with all encryption obstacles that might hinder Big Brother´s dragnet.
The rest is just made-up for discussion´s sake.
Re: https://www.eff.org/deeplinks/2016/03/next-front-new-crypto-wars-whatsapp
First it is the iPhone, now it is WhatsApp.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

REDACTED

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4557 on: March 15, 2016, 08:20:16 PM »
I use firefox with all of the blockers in place, turn off history, run a cookie cleaner and always use startpage as my search engine.  I never had an issue.  Never had an issue. 

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4559 on: March 16, 2016, 03:40:08 PM »
Security of AV code is meshy, insecure, and not of this time,
it is like hacking like in 1999. That means we´re in peril when the next big threat comes knocking at the door!

Read: http://blog.cmpxchg8b.com/2016/03/security-software-certification.html )link article author = Tavis Ormandy.
Mondern security is not what AV has to offer us.
Anyone.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!