Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2890751 times)

0 Members and 7 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5460 on: September 20, 2017, 01:59:49 PM »
Closer to home, EFF warned because of the recent 'supply chain" CCleaner attack:

Read:
https://air.mozilla.org/why-and-how-of-reproducible-builds-distrusting-our-own-infrastructure-for-safer-software-releases/
also
https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf

Why it becomes harder and harder to have trust in Trust!

polonus



Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48567
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5461 on: September 20, 2017, 03:06:28 PM »
Closer to home, EFF warned because of the recent 'supply chain" CCleaner attack:

Read:
https://air.mozilla.org/why-and-how-of-reproducible-builds-distrusting-our-own-infrastructure-for-safer-software-releases/
also
https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf

Why it becomes harder and harder to have trust in Trust!

polonus
A simple analogy. A Restaurant with one excellent cook is pretty trustworthy.
When expansion happens and we now have 10 cooks, that trustworthiness now decreases because it's harder to trust 10 people.
It also becomes harder to track the responsible person when something goes wrong. It also becomes harder to quickly correct the problem.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5462 on: September 20, 2017, 03:10:44 PM »
Poor Internal Security Measures/Practices Take a Toll:
More data lost or stolen in first half of this year  than in all of 2016

http://breachlevelindex.com/assets/Breach-Level-Index-Report-H1-2017-Gemalto.pdf
-> https://www.theregister.co.uk/2017/09/20/gemalto_breach_index/

Wise up, folks, now learn and educate, don't be sloppy or let yourselves be dumbed down
by legit and illegal data grabbers  :o

pol
« Last Edit: September 20, 2017, 03:23:58 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5463 on: September 21, 2017, 11:05:25 AM »
More concerns about the CCleaner Control and Command Server,
additional malware has been installed to a small number of victims,
approx. 20 servers with 8 organizations, that have infested around 2.2 million users.
Thanks to api-hacker group: "Chinese time zone PRC, APT17/Group 72".

Read: http://blog.talosintelligence.com/2017/09/ccleaner-c2-concern.html

Some more background on this sophisticated hacker group:
https://blogs.cisco.com/security/talos/opening-zxshell  &  https://attack.mitre.org/wiki/Group/G0001

Information the info stealer gathers:
local hostname
organization
owner
operating system details
CPU speed
total physical memory

polonus
« Last Edit: September 21, 2017, 12:28:24 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5464 on: September 21, 2017, 12:10:51 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5465 on: September 21, 2017, 12:49:38 PM »
Word Press plug-in developers partnered with spammers and spammed you for 4 to 5 years:
https://www.wordfence.com/blog/2017/09/coordinated-plugin-spam/

It's all about the money... ;D

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48567
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5466 on: September 21, 2017, 02:54:36 PM »
Continuing update on the Ccleaner investigation:
https://blog.avast.com/progress-on-ccleaner-investigation
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5467 on: September 22, 2017, 10:49:17 AM »
In the light of the recent CCleaner data breach with many victims in my country, the Netherlands I pondered on this info,
that has been available for us all for quite some time. But what can the common end-user do, when no one protects us
against the spooks that instigate this on the infrastructure.... :o

Where government agents put us at risk, command-and-control-server with weaknesses and RATs:
Read:
http://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware
&
https://campustechnology.com/articles/2017/05/02/industry-tool-detects-thousands-of-c2-server-rats.aspx
&
https://www.fireeye.com/blog/threat-research/2010/09/chasing-cnc-servers-part-2.html
&
https://tweakers.net/nieuws/123911/interpol-en-beveiligingsbedrijven-identificeren-8800-c2-servers-in-zuidoost-azie.html
(use Google translate to do a quick and dirty translation into English)

If there is no hardenened server security or low end insecure C2 servers are being used, those entities (groups/firms) these actions are directed against are "food for the birds"  soon. Helped by weak implementations, hiding data traffic via non-public clouds with all sorts of holes, like we had cloudbleed, etc. Unsigned versions  :o -> https://www.theregister.co.uk/2017/09/21/slack_linux/

It is a mess, dear forum folks, and it is going from bad to worse. What they wanna cover?

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5468 on: September 22, 2017, 12:25:43 PM »
This went wrong with the CCleaner compromittal : Wrong low-end server administering.

- One did not have any insight in (non-standard) network traffic;
- No following up/alert for the server being low on diskspace;
- No following up/alert that logging was being removed / Did they have permission (RCE/EoP?);
- No  log backup but an external system;
- No follow up/alert that the database was corrupted;
- No follow up/alert that a re-installation of the database had been taken place.

Hopefully avast servers are better being protected...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5469 on: September 23, 2017, 02:57:24 PM »
« Last Edit: September 23, 2017, 02:59:53 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
« Last Edit: September 23, 2017, 04:25:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5471 on: September 24, 2017, 01:10:49 PM »
Hundreds of firms vulnerable to be hacked easily via support ticket:

https://medium.freecodecamp.org/how-i-hacked-hundreds-of-companies-through-their-helpdesk-b7680ddc2d4c

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
« Last Edit: September 26, 2017, 06:20:38 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5473 on: September 26, 2017, 05:52:44 PM »
Additional information regarding the recent CCleaner APT security incident
https://blog.avast.com/additional-information-regarding-the-recent-ccleaner-apt-security-incident


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5474 on: September 26, 2017, 06:27:50 PM »
Interesting, Pondus, very in teresting, all around LA's ServerCrate C2 server,
and the links to Rumania, shortly a peak into the sordid little world of state actor infostealers.

Not a place to dwell in...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!