Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2895770 times)

0 Members and 4 Guests are viewing this topic.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5190 on: March 29, 2017, 04:47:36 AM »
PyCL Ransomware Delivered via RIG EK in Distribution Test By Lawrence Abrams
https://www.bleepingcomputer.com/news/security/pycl-ransomware-delivered-via-rig-ek-in-distribution-test/
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5191 on: March 29, 2017, 01:13:41 PM »
Zero-day hole in Microsoft IIS 6.0 (no longer being supported) actively attacked:
http://blog.trendmicro.com/trendlabs-security-intelligence/iis-6-0-vulnerability-leads-code-execution
Re: hole is found in Webdav: https://nl.wikipedia.org/wiki/Webdav
Newer versions of the server software are not vulnerable.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5192 on: March 29, 2017, 04:34:30 PM »
Broadband rules axed by Congress, headed to Trump

http://www.usatoday.com/story/tech/news/2017/03/28/broadband-rules-axed-congress-headed-trump/99744078/

Please, no political statements.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5193 on: March 29, 2017, 06:05:51 PM »
Please, no political statements.
D'oh!   :-X    that is a tuff one    ;D



Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89064
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5194 on: March 29, 2017, 06:37:40 PM »
Please, no political statements.

D'oh!   :-X    that is a tuff one    ;D

Very tough when the article is political ;)
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48568
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5195 on: March 29, 2017, 10:20:41 PM »
Please, no political statements.

D'oh!   :-X    that is a tuff one    ;D

Very tough when the article is political ;)
Especially when the bill is still a holdover from Obama. :)

Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48568
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5196 on: March 29, 2017, 10:25:31 PM »
From now on, we'll all be using a VPN. for now, that'll work.
I rely on the one from Avast. If that's not an option,
Get Opera and activate the VPN service in settings > Security & Privacy. :)

Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5197 on: March 29, 2017, 10:46:45 PM »
Hi bob3160,

And what will that mean for the Privacy Shield agreement with the EU,
or will the "old continent" comply to this with not much further ado,
and agree to the new situation, so that all of your data online may be sold to the highest bidder.

As there ever was an end to privacy, then now that moment has arrived.
What you said all along, bob3160, that: "Privacy does not exist any longer"
seems to have been prophetic words here".

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48568
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5198 on: March 29, 2017, 10:51:21 PM »
Hi bob3160,

And what will that mean for the Privacy Shield agreement with the EU,
or will the "old continent" comply to this with not much further ado,
and agree to the new situation, so that all of your data online may be sold to the highest bidder.

As there ever was an end to privacy, then now that moment has arrived.
What you said all along, bob3160, that: "Privacy does not exist any longer"
seems to have been prophetic words here".

Damian
Something elseto read:
http://lifehacker.com/why-is-everyone-talking-about-vpns-1793768312?utm_source=lifehacker_newsletter&utm_medium=email&utm_campaign=2017-03-29
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5199 on: March 30, 2017, 12:05:33 AM »
Dear bob3160,

Just watch this: https://www.youtube.com/watch?v=qAT_ina93NY
Very actual now....

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48568
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5200 on: March 30, 2017, 02:40:48 PM »
Dear bob3160,

Just watch this: https://www.youtube.com/watch?v=qAT_ina93NY
Very actual now....

Damian
Now if you realize that this video is 3 years old, imagine just how much more
of your privacy has been lost for ever.
I've preached for years that there is no such thing as personal privacy. Maybe this video and,
the current proposed legislation, makes that statement hit home.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5203 on: March 31, 2017, 06:28:27 PM »
Less secure bootstrap in the CloudFlare/GoDaddy clouds!

Issues with bootstrap
Found with SRI-hash issues in Stylesheets: https://sritest.io/#report/144f10cc-d705-4ef7-b513-46edbfa469d1
CloudFlare GoDaddy abuse - The getbootstrap.com server is vulnerable to:
Heartbleed also has problems with TLS:
Common name:
 -sni49733.cloudflaressl.com Comodo certificate chain ECC Domain Validated Secure Server  & -sni49733.cloudflaressl certificate
SAN:
 -sni49733.cloudflaressl.com, *.-amazinghunters.com, *.-avhipo.com, *.-bloggbyran.cf, *.-brakeingasout.com, *.-caketopia.eu, *.-egedenbutiklezzetler.com, *.-erwinolie.nl, *.-femclick.com, *.f-rankl.computer, *.-fren.us, *.-getbootstrap.com, *.-ghbtns.com, *.-hncuyelik.com, *.-hockeyed.com, *.-mobile4bizz.net, *.-nokiacamera.com, *.-secstories.com, *.-therecruit.zone, *.-thewareaglereader.com, *.-tickat636.ga, *.-zoekeenfietsenmaker.nl, -amazinghunters.com, -avhipo.com, -bloggbyran.cf, -brakeingasout.com, -caketopia.eu, -egedenbutiklezzetler.com, -erwinolie.nl, -femclick.com, -frankl.computer, -fren.us, - getbootstrap.com, -ghbtns.com, -hncuyelik.com,-hockeyed.com, -mobile4bizz.net, -nokiacamera.com, -secstories.com, -therecruit.zone, -thewareaglereader.com, -tickat636.ga, -zoekeenfietsenmaker.nl

Re: http://toolbar.netcraft.com/site_report?url=http%3A%2F%2Fgetbootstrap.com
See: https://urlscan.io/result/bb7dec19-4186-4864-b722-ac2989f663fb#summary

F-F-X status: https://observatory.mozilla.org/analyze.html?host=getbootstrap.com
MISSING MANDATORY CIPHERS for TLS: https://www.htbridge.com/ssl/?id=11fdf72a57bff6ed97fd176c0f1c23985b6a10e99247c7b70b52025f396e05ca
and other misconfigurations and weaknesses (mixed content and https redirect)

Seems from this report that the American infrastructure does not have that secure e2e encryption we are being led to believe,
this is endangering the average users that make use of such services.

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5204 on: April 01, 2017, 12:53:00 PM »
Marble a very dangerous CIA Malware Obfuscation/Deobfuscation tool.
Through Marble CIA could insert obfuscated txt and deobfuscate txt later to mask the origins of malware.
The tool could be used for instance to blame the Russians for something and then later take off the evidence and then in return blame the Chinese, or whatever the 'spooks had in store for us all.

This dangerous malware tool made everyone''s infrastructure  less secure to protect the interests of  less than 1% of the global population.

Being a linguist myself I wonder whether analytical analysis of the inserted txts could show up inconsistencies in the language inserted, so it can be shown where the malware manipulation was being performed (Langley Virginia, Frankfurt Germany Europe).
Comparative linguistics looking for missspellings, wrong use of grammar rules. In Poland we say prverbially: "Lies have short legs".

Are we as online users being protected against such "cloak and dagger" schemes or does AV have to refrain from analysing further
under existing "gag orders", we will never come to know.

Read comments: https://news.ycombinator.com/item?id=14006059
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!