Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2880004 times)

0 Members and 1 Guest are viewing this topic.

llariel

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #420 on: May 19, 2010, 01:48:20 AM »
Oracle Java SE and Java for Business are prone to a remote heap-based buffer-overflow vulnerability affecting the Java Runtime Environment (JRE).

Attackers can exploit this issue to execute arbitrary code within the context of the user invoking the JRE.

Versions prior to Java 5.0 Update 24 and Java 6.0 Update 19 are vulnerable.

http://url4.eu/3Xqok

Offline Chris Thomas

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1936
  • Christian Geek - aka 'born again' Geek
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #421 on: May 19, 2010, 05:48:39 PM »
Microsoft Confirms x64 Windows 7 Aero Vulnerability

Vulnerability in Canonical Display Driver Could Allow Remote Code Executio

http://www.microsoft.com/technet/security/advisory/2028859.mspx

 :-X

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #422 on: May 20, 2010, 10:42:28 PM »
Hi malware fighters,

Latetst threats: http://security.technosoftcorp.com/ss/ss_index.htm

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #423 on: May 21, 2010, 11:52:07 PM »
Hi malware fighters,

Already 44 PHP leaks found up: http://www.php-security.org/

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #424 on: May 23, 2010, 12:35:31 AM »
Hi malware fighters,

Notorious torrent site with malware: 3471018cfbd0f17899258e2b62a1dd61   2010-05-11   Eleonore Exploits pack   IE6   24/41 (58.54%)    TR/PSW.Zbot.185344.R    Blocked   UK   hxxp://91.216.3.108/ca1/index.php
See: http://support.clean-mx.de/clean-mx/viruses.php?domain=91.216.3.108&submit=query
Still malicious avast reports: hxtp://wepawet.cs.ucsb.edu/view.php?type=js&hash=3ebe99eb909fd7458dd245ccbc8c4615&t=1273536734 (do not click link, it is flagged for sign of JS:Pdfka-BT [Expl] has been found
Norton Safe Web gives it green, but that is false: This is a dangerous site,it is blocked on Blade,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #425 on: May 24, 2010, 10:37:23 AM »
not really a warning but worth noting:
Google turns on SSL encryption for search

http://www.theregister.co.uk/2010/05/21/google_search_ssl_encryption/



http://googleblog.blogspot.com/2010/05/search-more-securely-with-encrypted.html

Quote
A few notes to remember: Google will still maintain search data to improve your search quality and to provide better service. Searching over SSL doesn’t reduce the data sent to Google — it only hides that data from third parties who seek it.
« Last Edit: May 24, 2010, 10:39:20 AM by Logos »

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #426 on: May 24, 2010, 10:54:02 AM »
Fake joke worm wriggles through Facebook
http://www.theregister.co.uk/2010/05/21/fake_joke_worm_facebook/

Quote
The malware, for now at least, does nothing more malicious than posting a message on an infected user's Facebook wall that point to a site called fbhole.com. Nonetheless, the speed of its spread on the social networking site has net security experts worried.

The message that the worm posts takes the form
:
Code: [Select]
try not to laugh xD http://www.fbhole. com/omg/allow.php?s=a&r=[random number]
Facebook gives users' names to advertisers
Violates own privacy policy
http://www.theregister.co.uk/2010/05/21/facebook_ads/
http://online.wsj.com/article/SB10001424052748704513104575256701215465596.html

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #427 on: May 24, 2010, 12:33:07 PM »
Hi friends,

The fbhole.com attack ended in 15 seconds. Check out fsecure's weblog : http://www.f-secure.com/weblog/archives/00001955.html

nmb

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #428 on: May 24, 2010, 01:20:32 PM »
Hi friends,

The fbhole.com attack ended in 15 seconds. Check out fsecure's weblog : http://www.f-secure.com/weblog/archives/00001955.html

nmb

LOL  ;D

Quote
Updated to add: Domain fbhole.com shared an IP address with ironbrain.net [82.208.32.99]. Ironbrain.net hosted a website with references to Facebook but no obvious illegal content. While fbhole.com was registered with privacy protection, ironbrain.net had contact information in the WHOIS database, complete with a Czech phone number.

So I called the number.

The call went roughly like this:

– Hello?
– Hi. This is Mikko Hypponen from F-Secure Labs.
– What is this about?
– I'm looking for a person related to ironbrain.net.
???
– We're investigating a Facebook worm on fbhole.com. That domain shares an IP address with ironbrain.net which is registered under your name.
– And you are?
– I'm from an antivirus company. Are you related to ironbrain.net?
– I'll have to check… maybe my company is…
– Please do.
– Bye…
[Click]

About 15 seconds later, both fbhole.com and ironbrain.net went offline. The attack is over
.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #429 on: May 24, 2010, 03:59:52 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37526
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #430 on: May 26, 2010, 12:52:48 AM »
IBM hands out malware-stuffed USB at security conference
http://www.theregister.co.uk/2010/05/21/ibm_usb_malware_snafu/

Offline Chris Thomas

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1936
  • Christian Geek - aka 'born again' Geek
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #431 on: May 26, 2010, 05:11:08 PM »
First human 'infected with computer virus'


A British scientist says he is the first man in the world to become infected with a computer virus

Is he a humanoid?

Not as terrible as I though

http://news.bbc.co.uk/2/hi/technology/10158517.stm
« Last Edit: May 26, 2010, 05:14:08 PM by Chris Thomas »

llariel

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #432 on: May 26, 2010, 07:14:40 PM »
Facebook Apps hacked or exploited and is hosting HTML:Iframe-inf

Edit: I found this today and still active. Trying to connect twitter with Facebook via Facebook Apps. Google Chrome is giving alert, but the malware can be execute automatically by the server. avast is detecting & blocking it.
« Last Edit: May 26, 2010, 07:20:46 PM by Llanziel »

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #433 on: May 26, 2010, 07:15:58 PM »
Facebook Apps hacked or exploited and is hosting HTML:Iframe-inf

more details may be? ;D

llariel

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #434 on: May 26, 2010, 07:22:54 PM »
Facebook Apps hacked or exploited and is hosting HTML:Iframe-inf

more details may be? ;D

No info is available in the web so far, but I be notified by Google Chrome & avast