Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2885708 times)

0 Members and 6 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4890 on: October 27, 2016, 06:57:29 PM »
Trying to halt Mirai through a security hole: https://www.invincealabs.com/blog/2016/10/killing-mirai/
link author = Scott Tenaglia.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4891 on: October 28, 2016, 12:32:41 AM »
Effective regular expression to be used against new spam botnet:
Quote
/[a-z]+\.php\?[a-z]\=146\&[\w]+\=[\w]+\&J9p\=[\w]{3}\&/

Spambot linked to SEO Spam and social media abuse, zie https://www.mywot.com/en/scorecard/urlrate.net?utm_source=addon&utm_content=popup
The important Joomla update seems almost too late for mentioned website, re: code error: undefined function window.addEvent -> htxp://tivaen.com/templates/ZAjax_Temp/js/roksortable.js

info credits security.nl anonymous posts 25-10-2016, 01:05 &  Yesterday, 21:28

Remarkable is that people who have ISP mail accounts with good and decent working spam filters might not see it
or may get it only as junk mail ready to be deleted. I for instance have not seen these mails with obfuscated shortened url link spam.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4893 on: October 29, 2016, 06:19:43 AM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4894 on: October 29, 2016, 08:25:53 AM »
AtomBombing: A Code Injection that Bypasses Current Security Solutions
http://blog.ensilo.com/atombombing-a-code-injection-that-bypasses-current-security-solutions
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4895 on: October 30, 2016, 12:15:32 AM »
Grand scale attacks on outdated Joomla almost a certainty. according to Sucuri's:
https://blog.sucuri.net/2016/10/joomla-mass-exploits-privilege-vulnerability.html

This is so for those who haven't found this Joomla update icon yet:
https://docs.joomla.org/Where_is_the_auto_update_for_Joomla%3F

polonus

P.S. How to block malicious account creation for vuln. Joomla: https://github.com/fcoulter/accountblocker
« Last Edit: November 03, 2016, 06:15:29 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4896 on: October 30, 2016, 01:23:53 PM »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4897 on: October 30, 2016, 04:23:27 PM »
The Internet of Things Ecosystem is Broken. How Do We Fix It?
http://blog.trendmicro.com/trendlabs-security-intelligence/internet-things-ecosystem-broken-fix/

I think that when the IoT (idea) came into being there was little or no thought given to security.

There is no way I would give internet access to a bloody fridge, etc. I have a so called Smart TV (and that is over 7 years old) and there is absolutely no way I would hook it up to the internet.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4898 on: October 30, 2016, 04:34:21 PM »
The Internet of Things Ecosystem is Broken. How Do We Fix It?
http://blog.trendmicro.com/trendlabs-security-intelligence/internet-things-ecosystem-broken-fix/

I think that when the IoT (idea) came into being there was little or no thought given to security.

There is no way I would give internet access to a bloody fridge, etc. I have a so called Smart TV (and that is over 7 years old) and there is absolutely no way I would hook it up to the internet.
I have a chrome device hooked into one TV and enjoy some of the smart things available on the new "smart TV".
Different strokes for different folks. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4899 on: October 30, 2016, 04:54:10 PM »
I have  mye TV,  Blueray player online so i get software updates +Apple TV and cableTV box to recive all features like Netflix and movie rent

Offline abruptum

  • Massive Poster
  • ****
  • Posts: 2460

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4901 on: October 31, 2016, 10:26:28 PM »
Some things you can do securing your iOT devices at Home.

First and formeost use Avast solutions to protect your Wifi.
I do and I haven't regret that decision since.
Would not use my Android without it.

1. Do not take iOT devices to your workplace, for instance your Bluetooth music watch.

2.    Create a separate guest network for iOT devices on your wifi home network.
2. a Check using Wireless Network Watcher for instance to see what's on there.

3. Only plug those devices into the network that you cannot do without.

4. Update, upgrade and patch the firmware of all iOT devices.

5.   Disable UPnP, so your devices are not exposed on the Interwebs.
5.a Check for this using Shodan search engine for instance, or dork searches.

6. Alter the default passwords. Pick good secure passwords and hand a different one to all and every device.

7. Always be wary of cloud services and establish the security thereof. Use secure connections.
 
8. Keep your "landline"open in any case of a major emergency. Never trust anything outside your network.

9. Disable wifi and bluetooth services whenever there is no need for it.
    Then these services should be off.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4902 on: November 01, 2016, 10:35:13 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4903 on: November 01, 2016, 12:33:48 PM »
Microsoft not happy with Google disclosing major Windows bug - Web giant says no fix or advisory has been issued even though it reported the flaw 10 days ago.

https://www.cnet.com/news/microsoft-unhappy-with-google-disclosing-major-windows-bug-security/?ftag=COS-05-10aaa0h&utm_campaign=trueAnthem:+Trending+Content&utm_content=58180fbe89b9830007afc76a&utm_medium=trueAnthem&utm_source=facebook
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4904 on: November 01, 2016, 12:59:57 PM »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet