Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2888575 times)

Simion and 4 Guests are viewing this topic.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #345 on: April 12, 2010, 08:33:17 AM »
sorry Logos, spammer was here but mod must have deleted them- next time I leave it to the mods  :)
« Last Edit: April 12, 2010, 12:03:07 PM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #346 on: April 12, 2010, 11:47:38 AM »
hmm...is yr biznus desperate or someting...surely better place to advertise than here?

???

Offline polonus

  • Avast Ăśberevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #347 on: April 12, 2010, 11:58:18 AM »
Hi malware fighters,

WordPress bloggers being hacked with shared hosting from Network Solutions: http://wordpress.org/support/topic/385477/page/2#post-1470935
Here it is called a plug-in prob: http://krebsonsecurity.com/2010/04/hundreds-of-wordpress-blogs-hit-by-networkads-net-hack/

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #348 on: April 12, 2010, 12:39:51 PM »
I have an account at netsol so I will go in tonight and see if I can find anything amiss. I have the Wordpress options active (I think), but have never used them from what I can recall - why would, when I can have Wordpress as a standalone with sufficient options to link back to netsol, that is links that keep source at arm's length from destination. There have been a lot of problems with Wordpress recently. Cannot say people haven't had sufficient warnings. And Wordpress bundled into netsol...hmm...tonight I stop any active connect for good.

Netsol are unashamedly hard sell, even though they do provide me services at a tenth of the price what they would cost here in New Zealand (I'm not kidding - $NZ14 per annum spent at netsol for what I'm paying approx $NZ170 per annum here just to own a .co.nz domain, and that's not to use the domain, that's just to own it). But point is netsol are unashamedly hard sell, they exude business, and you have to watch yr *ss for yrself, cos they not going to do it for you. That said, their network shield is good, very solid so far, and I feel terribly let down that I haven't received an email notification about this issue. They do crank out emails very regular, hard sell emails that is, and there really is no excuse for the delay. A warning about the threats at least, should be mandatory. As a netsol customer I am terribly let down, and feel the negligence reflects on myself as well as one of their clients. (And just checked - still no email).

Edit - screenshot show Wordpress / mysql database - now removed

maybe I yapped my mouth a bit early ??? but I just know - I knew back then - at least the forum finally got something to talk about, usual its just a vehicle to advertise, better go add my piece of nonsense to the rabble   ;D

Edit - I was wrong there was an alert - alerted that I've got a bill needs to be paid within 30 days   ???
« Last Edit: April 12, 2010, 01:18:28 PM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #349 on: April 12, 2010, 12:47:39 PM »
sorry Logos, spammer was here but mod must have deleted them- next time I leave it to the mods  :)

oh OK ;)


Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #351 on: April 12, 2010, 01:46:58 PM »
thanks Scott, I feel vindicated. I've always felt that Wordpress / mysql option was a risk. but must be tempting for some people.

I'm trying to get into the forum discussion at the moment through my standalone Wordpress.

oh its wordpress.org and my standalone is wordpress.com - they operate separately - has saved me wasting my time.

here's an update on this issue

http://blog.networksolutions.com/2010/update-word-press-issue-fixed/  - fixed (for now)

http://terrywhite.com/techblog/archives/5097  - is tough at the top, Terry (some good tips and tricks on this domain)

Thanks for post Polonus, I've decided to RSS Brian Krebs as a safe measure - no onsite alert from netsol as yet  ???
« Last Edit: April 13, 2010, 12:34:39 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user

Offline Chris Thomas

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1936
  • Christian Geek - aka 'born again' Geek
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #353 on: April 13, 2010, 10:01:36 AM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #354 on: April 13, 2010, 01:32:47 PM »
Malware Extorts Cash From BitTorrent Users

A new type of malware is riding the wave of file-sharing pre-settlement letters by infecting BitTorrent users’ machines and then demanding payments in order to make imaginary lawsuits go away. ICPP Foundation try to give the impression they are RIAA and MPAA affiliated but the whole thing is a scam to extort cash and obtain credit card details.

http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/

Alan Baxter

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #355 on: April 17, 2010, 06:48:39 PM »
Mozilla has blocklisted all older versions of the Java Deployment Toolkit plugin.  I just noticed that the current version in my Java 6U20 installation is Java Deployment Toolkit 6.0.200.2, a version which is newer than those blocklisted, versions 6.0.200.0 and older.

Add-ons Blocklist | Mozilla
Quote
This page lists blocklisted add-ons that should no longer be used with Mozilla products.
...
    * Java Deployment Toolkit, versions 6.0.200.0 and older. Reason: security vulnerabilities (see bug 558584).

This note seems to say a problem is caused by the Java update process, rather than the 1.6.0_20 version of the plugin.  I don't see any evidence that the 1.6.0_20 version is problematic.
US-CERT Vulnerability Note VU#886582
Quote
Note: The installer for Java 1.6.0_20 may not correctly update all instances of the Java Deployment Toolkit plugin. In some cases, the plugin that resides in the \bin\new_plugin directory may not be updated to the fixed 6.0.200.2 version of npdeployJava1.dll. If the new_plugin directory contains npdeploytk.dll version 6.0.190.4 or earlier, then browsers that use plug-ins, such as Mozilla Firefox or Google Chrome, may still be vulnerable. To correct this situation, delete the vulnerable npdeploytk.dll from the new_plugin directory and replace it with the npdeployJava1.dll version from the bin directory.

Please note that the Java Development Toolkit can be installed in multiple browsers, therefore workarounds need to be applied to all browsers with the Java Development Toolkit.

Edit: Updated with US-CERT info.
Mozilla's Add-ons Blocklist page seems to have some incorrect info.
Current version is not blocklisted.
« Last Edit: April 17, 2010, 08:03:01 PM by Alan Baxter »

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #356 on: April 17, 2010, 09:28:40 PM »
There may have been some problems Java update process, perhaps in updating to 1.6.0_20 version.

Chrome Java version

Where I found there was an issue - Vista SP2, Chrome - Secunia found the version to be out of date
- would not update from the Java module in Control Panel
- downloaded 1.6.20 version from Secunia but would not install
- repeat attempt bought up dialog box inform the elevation was necessary to update - special case

Also repeated attempts to change rule from Ask before downloading to Ask before installing was not successful after the rule had been Apply - always went back to initial setting - this is still the case.
- currently Ask before downloading is the only setting that will Apply

The owner of the computer is not computer literate so I did not pursue what was the brief history
- last attempt to update was 4/4/2010 and that was from 1.6.18 version....so? I'm not sure.

What I did was download the latest version and uninstall the existing version
- then I did an install of 1.6.20 and this was successful
- ran a manual update and process was successful returning message that Java already up to date

Still couldn't change update rule to Ask before install - may need to first change some other setting.

Edit - one of my own computers - XP Pro, Firefox - alerts that most recent update of Java console 1.6.18 in browser had not shed previous version, so I deleted previous version and tried manual update of Java in Control Panel - two corrupt downloads before successful install of 1.6.20 and checked browser to find that all was now good - will check all my machines, if any problems will open new post.
« Last Edit: April 18, 2010, 01:30:46 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

spg SCOTT

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #357 on: April 17, 2010, 09:32:06 PM »
Infected XP owners left unpatched

Quote
Some of the latest security updates for Windows XP will not be installed on machines infected with a rootkit virus.
...
The latest updates can spot if a system is compromised by the Alureon rootkit and halt installation.

http://news.bbc.co.uk/1/hi/technology/8624560.stm


Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #358 on: April 18, 2010, 04:55:12 PM »
Network Solutions hacked again

More sites hacked : http://bit.ly/9a8nP2

nmb

Alan Baxter

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #359 on: April 18, 2010, 05:20:01 PM »
More sites hacked : http://bit.ly/9a8nP2

Could you provide the full URL?  In general, I'm not comfortable clicking on shortened ones because they give me no indication of where I'm supposed to wind up.