Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2895866 times)

0 Members and 4 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #300 on: March 26, 2010, 02:46:50 PM »
Hi malware fighters,

Apparent Detecting and Defeating Government Interception Attacks Against SSL, Certification authorities have provided government with false certifications so they need not break and can easily circumvent encryption: http://files.cloudprivacy.net/ssl-mitm.pdf
Involved is packet-forensics: http://www.wired.com/threatlevel/2010/03/packet-forensics
Now we understand why a lot of browsers trust a lot of certificates:
http://www.eff.org/deeplinks/2010/03/researchers-reveal-likelihood-governments-fake-ssl]

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #301 on: March 26, 2010, 06:08:19 PM »
Hi malware fighters,

Apparent Detecting and Defeating Government Interception Attacks Against SSL, Certification authorities have provided government with false certifications so they need not break and can easily circumvent encryption: http://files.cloudprivacy.net/ssl-mitm.pdf
Involved is packet-forensics: http://www.wired.com/threatlevel/2010/03/packet-forensics
Now we understand why a lot of browsers trust a lot of certificates:
http://www.eff.org/deeplinks/2010/03/researchers-reveal-likelihood-governments-fake-ssl]

polonus


I hope that's not true ??? :o

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #302 on: March 27, 2010, 12:00:30 AM »
@Logos,

More links: http://www.betanews.com/article/Has-SSL-become-pointless-Researchers-suspect-statesponsored-CA-forgery/1269551694
http://betabubble.com/?tag=intermediate-certificates
It was not developed with your security in mind....
It is all about endpoints, and it is all about trust to what is going over the "wire"......
DNSSEC has a similar attack against it,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #303 on: March 27, 2010, 01:17:14 AM »
I trust the sources, that's not the problem, I was just a bit shocked to say the least. I posted that on Comodo forums to get some reactions (could be interesting as they're in ssl business) but no feedback so far...

crofty59

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #304 on: March 27, 2010, 04:34:23 AM »
Trojans masquerading as updates for popular applications such as Adobe, Java or Windows.

I read this on Sunbelt blog
http://sunbeltblog.blogspot.com/2010/03/fake-updates-install-backdoors.html

Also more info on Softpedia
http://news.softpedia.com/news/Trojan-Masquerades-as-Adobe-Reader-Updater-Component-138453.shtml

Edited wrong Link
« Last Edit: March 27, 2010, 04:35:54 AM by crofty59 »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #305 on: March 30, 2010, 01:30:11 PM »
Hi malware fighters,

Security researcher D. Stevens has published a hole in PDF that cannot be patched!
POC: http://blog.didierstevens.com/2010/03/29/escape-from-pdf/
Forewarned is forearmed. Adobe is putting everyone in danger,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #306 on: March 30, 2010, 03:37:03 PM »
I now use Foxit - regardless that is less supported PDF platform
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #307 on: March 30, 2010, 03:44:41 PM »
I use sumatra pdf. recommended by scott, its awesome. Thanks scott. No problems whatsoever.

nmb

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #308 on: March 30, 2010, 06:55:53 PM »
okay I give it a go. no doubt still recommended by Scott.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

spg SCOTT

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #309 on: March 30, 2010, 07:06:37 PM »
I use both foxit and Sumatra as they both come in portable versions (portableapps.com)
 

Simple, small, lightweight, and crucially not targeted as much as adobe ;D

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #310 on: March 30, 2010, 09:27:08 PM »
Thats what I'll do Scott. And the portable on my flash drive as well. Cheers, buddy.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #311 on: March 30, 2010, 09:33:11 PM »
Hi malware fighters Scott and mkis,

Thanks for the additional info, forum friends,  Adobe has been under malware flak too long now and their patch cycle cannot keep up with what is uncoming, as this cannot be patched as Didier Stevens mentions then it is better to shun Adobe's PDF software until they really will clean up their act,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #312 on: March 30, 2010, 10:03:37 PM »
OK this is all interesting, and I (seriously) don't doubt a second about the existence of Adobe Reader or Flash vulnerabilities. This said, I'm still waiting for my first Adobe related infection ;D

Offline MikeBCda

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2247
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #313 on: March 30, 2010, 10:04:23 PM »
My personal third-party choice is Tracker's PDF-XChange Viewer (freeware, at least the version I've got).

If I understand correctly, the vulnerability is in Adobe's reader itself, rather than anything inherent in PDF coding, so 3rd party viewers should be OK.

I suspect Adobe has a general attitude problem about proper security.  Maybe my sense of what happened when is a little fuzzy, but didn't all the problems with Flash start more or less when Adobe took that (and Shockwave generally) over?
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-11, Firefox 51.0
(default). 320 gig HD, 15Mb DSL, Win firewall, Avast 12.3.2280 free, SpywareBlaster, MBAM Prem., Crypto-Prevent

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #314 on: March 30, 2010, 10:08:19 PM »
Hi Logos,

The case is worse than the responders thought, it is not only Adobe PDF that is holed, it is all PDF, in Foxit it is even worse that you get no warning and still the POC works. Use this to test: http://didierstevens.com/files/data/launch-action-cmd.zip   If cmd.exe is started well  :'(
It is broken, folks, it is broken, they are going for broke!!! This is the POC for Foxit Reader: http://twitter.com/riotz/status/11281340909
But PDF-XChange Viewer still standing, nothing being executed only thing you get is an error after the warning....

polonus

« Last Edit: March 30, 2010, 10:19:59 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!