Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2880051 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4875 on: October 18, 2016, 11:30:52 AM »
@Asyn,

New link where the list resides: https://github.com/gwillem/ecommerce-malware-collection/tree/master/js
Check these with a Magento security scanner like: https://www.magereport.com/scan/?s=
and other scans in your toolchest.

enjoy, my good friends,

pol

P.S.
Nota Bene.
Mind you. This is a commercial list to sort of "lure" infested or (potentially) insecure webshop owners
to Byte.BV's security support services.
This as the creator, Willem de Groot, of the forementioned list, is also owner of this firm/hosting service,
Byte B.V. in the Netherlands. So his intentions with the list and all may differ from our intentions with it.

Just wanted to remind you of this situation, as it only seems fair to do so.
Notice polonus is a 100% purely unbiased & independant avast support forum volunteer website security specialist.
and I have no interest in this list as only for research purposes. 
Seems only 176 webshops are really malicious as such.

Damian
« Last Edit: October 18, 2016, 11:33:10 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4877 on: October 18, 2016, 12:02:15 PM »
Thanks for that one, Asyn. Bookmarked. We're even now.  ;)

Would be great to go over that list with some  specific scans: http://www.domxssscanner.com/  &
san at: https://observatory.mozilla.org/
and then put the suspicious code through an unpacker for errors (bugs and insecurity).

Fact is that loads and loads of websites, especially the smaller ones, but not necessarily so,
have sloppy IT managment (update/patch management etc.),
and are therefore insecure and open to abuse/infection.

A lot of those on the Willem de G. list also comes blocked with firehol: https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_webserver.netset

Have a nice day, ye all,

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: October 18, 2016, 12:26:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4878 on: October 18, 2016, 02:36:51 PM »
WordPress sites hacked via new Marketplace plug-in zero-day:
http://labs.sucuri.net/?note=2016-10-17
Obfuscated backdoor code detected....

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4880 on: October 19, 2016, 11:50:42 PM »
Cybercriminal skimmers find creative solution: creditcard data hidden inside image:
https://blog.sucuri.net/2016/10/magento-credit-card-swiper-exports-image.html

Scan your webshop that has Magento here to be alerted to insecurity: magereport.com/scan/?s=

We see that the so-called Willem de G. list made some researchers look a bit sharper for e-commerce site's insecurity.
All reported to Google Safe Browsing that cooperates firmly with Sucuri's.

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4881 on: October 22, 2016, 07:58:27 AM »
Tens of millions of websites at risk in latest mega breach
https://www.leakedsource.com/blog/weebly/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4882 on: October 22, 2016, 12:41:26 PM »
Tens of millions of websites at risk in latest mega breach
https://www.leakedsource.com/blog/weebly/

WTF  >:(!!! For one of my uni papers at my institute uses weebly as a source for giving us (students) lecture notes, notices, timetable, and etc etc. I will pass this info to my uni IT support and let them know. Thanks Asyn for posting this
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4883 on: October 22, 2016, 03:51:40 PM »
Tens of millions of websites at risk in latest mega breach
https://www.leakedsource.com/blog/weebly/

Interesting when WOT doesn't trust/like leakedsource.com.

One thing for sure when I come across sites like this there is absolutely no way I would check user name and passwords. As soon as you do that you have pretty much compromised your information and can't/shouldn't use that data again.

Who would trust that the data wouldn't be harvested, certainly not me and I'm a trusting sort NOT.

I won't even use sites to check the strength of my passwords, for the very same reasons.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4884 on: October 22, 2016, 05:27:19 PM »
Hi DavidR,

Striking again that a Russian source seems to come with a bad web reputation,
lots of that demonizing going on lately.

The leakedsource dot com organization is into data harvesting, so it sits on big pile of cloud data.

At the moment for whatever reason there is a concerted action going on to make Russia look like the evil empire of cyberwarfare?

In this case:  JSC DBA RU-CENTER, privacy protection service.
Comodo Certification - PositiveSSL Multi-Domain,Domain Control Validate seems OK.

What is CloudFlare's role in all this.
The bad side of it all is that CloudFlare seems indifferent to what they have in that cloud traffic they are facilitating.
The good, the bad and the ugly as long as it brings them big profits.
Big data cloud security is bad.
For the majority of big enterprise do not have protection as it should be implemented.

This will not be the last of such big data-breaches, where and when we may find them.


polonus
« Last Edit: October 22, 2016, 05:40:32 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4885 on: October 22, 2016, 06:04:58 PM »
Tens of millions of websites at risk in latest mega breach
https://www.leakedsource.com/blog/weebly/
WTF  >:(!!! For one of my uni papers at my institute uses weebly as a source for giving us (students) lecture notes, notices, timetable, and etc etc. I will pass this info to my uni IT support and let them know. Thanks Asyn for posting this
You're welcome. :)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37526
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4886 on: October 24, 2016, 06:56:53 AM »
Unprotected IoT devices killed the US Internet for hours
http://www.bitdefender.com/box/mirai-IOT-security-alert.html


Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4887 on: October 25, 2016, 07:33:30 AM »
Locky Adds Support for a New "S**T" Extension
Security researcher MalwareHunterTeam tells Softpedia that the infamous Locky ransomware has returned today with a new spam campaign that's spreading a new version of the ransomware.
http://news.softpedia.com/news/locky-adds-support-for-a-new-s-t-extension-509588.shtml
« Last Edit: October 25, 2016, 07:36:04 AM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4888 on: October 25, 2016, 11:54:23 PM »
There are being warnings given out about a new spam botnet.
Important is the advice that shortened urls in an e-mail should always be frowned upon as suspicious.
Do not click such links.

Here is the information link given on a Dutch news forum, use Google translate to be able to read on this new spam botnet:
https://www.security.nl/posting/490176/Nieuw+spam+botnet%3F

Be aware of the obfuscated  146&........ look out for patters  like e.g. 146&AGTfVq or 146&cc4by etc. in the URL address link.
This could create a handle for blocking this smut-spam
with domain names found to be like:
-hookupclub4[.]com
-flirthookup5[.]com
-flirthookup6[.]com
-flirthookup4[.]com
-claimyourprize2[.]com
-claimyourprize1[.]com

-Info credits here go to : SecGuru_OTX & NSG

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4889 on: October 26, 2016, 12:04:04 PM »
Tens of millions of websites at risk in latest mega breach
https://www.leakedsource.com/blog/weebly/
WTF  >:(!!! For one of my uni papers at my institute uses weebly as a source for giving us (students) lecture notes, notices, timetable, and etc etc. I will pass this info to my uni IT support and let them know. Thanks Asyn for posting this
You're welcome. :)

@Asyn: It's all good. The IT department at my uni, they knew about this problem and had already taken precautions. Thanks again  :)
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2