Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2888319 times)

0 Members and 3 Guests are viewing this topic.

CharleyO

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #525 on: June 28, 2010, 11:05:33 AM »

CharleyO

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #526 on: June 30, 2010, 09:57:28 AM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #527 on: June 30, 2010, 12:11:48 PM »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #528 on: June 30, 2010, 01:08:44 PM »
Hi malware fighters,

In Amsterdam a couple of important HTTP-protocol flaws will be revealed: the vulnerabilities are for all programs and services that make use of the HTTP-protocol, e.g. Internet Explorer, Firefox, Microsoft Office, buts also Twitter, Hotmail, Facebook and iPhone Apps. MS and Facebook could mend these flaws in their code, but closing the holes for the HTML-protocol itself won't be that easy and swift a task...
So that is why I use HTTPS-everywhere extension inside the Mozilla browser for now, NoScript will protect the user as well, so all my search queries go via encrypted.google.com, my good friends,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48558
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #529 on: June 30, 2010, 04:41:09 PM »
Using HTTPS stops avast from being able to scan your web activity.
At this point, I'd rather depend on avast! to protect me. :)  (This is my opinion)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #530 on: June 30, 2010, 05:08:46 PM »
Using HTTPS stops avast from being able to scan your web activity.
At this point, I'd rather depend on avast! to protect me. :)  (This is my opinion)

Couldn't agree more, why use the web shield if you are going to cripple it by using an add-on to use https.

Not to mention a point polonus makes that NoScript also protects you to a degree in firefox, by switching to https you are actually reducing that effectiveness as the rules in NS by default are different for https (active content in https connection, see image). So not only are you blocking avast you are also reducing the effectiveness of noscript, a poor swap in my opinion.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #531 on: June 30, 2010, 05:53:56 PM »
DavidR,

The avast shields keeps working I guessed, the https everywhere is only for a couple of sites that give this additional service (alas google via encrypted.google, because of the school filter circumvention issue), it would be a sad thing indeed that we weren't protected on/via https connections. Is that so? I have the extension now disabled for the mo, but like to hear a bit more on the issue why https is not protected by avast via their port 12080 shield connection,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #532 on: June 30, 2010, 06:28:02 PM »
It isn't only for a couple of sites and they are looking at adding other sites, not to mention some of the sites they do include notably facebook (I believe, or some such social networking site/s), which are large targets for malware.

It is a simple fact https is encrypted and the web shield can't monitor/scan encrypted traffic so it doesn't even try. So you loose that level of protection on https pages, it may well be picked up by the file system shield, but that isn't assured and certainly not any hacked site, redirect, exploit issues.

You only need monitor the web shield whilst browsing an https site and you will see zero scanning of https pages/content. Why do you think I have been banging on about it every time you mention this add-on.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #533 on: June 30, 2010, 09:20:25 PM »


The avast shields keeps working I guessed...

polonus

I'm surprised to hear that from you Pol...how do you want to scan encrypted traffic :) remains that the file shield will interact at disk level...but hey that's not the same level of protection anymore ;) This said there's no risk surfing on https on a few sites (allowing it), I do that myself, on twitter for instance, where there's nothing hosted >>> if malware is linked there it's out of twitter, so the webshield will interact again. I'd be more careful with Facebook (that I hate anyway), because stuff is hosted there, so yes there are definitely some sites where ssl is not advised at all.
 The main point of using ssl is to get the privacy that you can't get on http in the case that bad guys would be eavesdropping the network...but the downside is that "malwarewise", you're almost on your own there.

ps: but again, I think switching to ssl is fine on a very restricted number of sites, like Google docs (on your account) and as a rule on nothing shared from another account.

iRonzel

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #534 on: June 30, 2010, 11:46:48 PM »
Hi guys!

One question,

Is Google search exploited, or is a FP from avast!?

my avast! found in many occasions a JS-ScripIP-inf trojan trying to download to my computer when I make searches through Google.   



iRanzel

attach: report file from Web Shield

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #535 on: June 30, 2010, 11:55:45 PM »
Hi iRanzel,

It is w\Xw.google.com.pr that has been hacked: t's the Peace Crew, formerly known as Terrorist Crew, a group of politically motivated hackers supporting the Palestinian cause, who recently defaced the Microsoft New Zealand sites. Earlier this year, they attacked a number of Nato and US military websites.

The principal Peace Crew character is a hacker known as Agd_Scorp, allegedly of Turkish origin. Others prominent members are rx5 and Cr@zy_King.

I don't know just how exactly did they go about this hack, but it seems to have something to do with modifying the DNS records of the hacked domains, which in effect re-directs prospect visitors to a site designed by the hackers. This particular exploit is known as "SQL Injection vulnerability".
source(s):
Microsoft NZ Hack:
http://w0rm.us/tag/peace-crew
http://www.nzherald.co.nz/technology/news/article.cfm?c_id=5&objectid=1...

NATO Hack:
http://news.softpedia.com/news/Palestinian-Supporters-Hack-NATO-and-U-S-Arm...

DNS Record Types:
http://en.wikipedia.org/wiki/List_of_DNS_record_types

SQL Injection:
http://en.wikipedia.org/wiki/SQL_injection

Use for searches the encrypted.google.com serviced, that is https and not that easy to hack or do your searches at
Ixquick, they also do not retain your search queries, http://ixquick.com/do/metasearch.pl

But looking for keygens is the royal route into your computer for malcode, because it often comes bundled with it..


polonus
« Last Edit: July 01, 2010, 12:12:46 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #536 on: July 01, 2010, 12:50:58 AM »
Hi malware fighters,

A FOOBAR by GoogleChrome as some take it - Flash Player installed a la default with their latest update of the browser, a security nightmare, Google says:  you, the user, do not have to install anything and maintain anything, we'll do that for you. The option to fall back on a player you installed yourself is still there in the browser, but for that you have to opt out, but even as Flash Player comes sandboxed in GoogleChrome, isn't it better to go on with HTML5 and let Flash die a silent death, it is and was a security nightmare, folks?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

iRonzel

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #537 on: July 01, 2010, 03:51:33 AM »
Quote
But looking for keygens is the royal route into your computer for malcode, because it often comes bundled with it..


polonus

Exactly, is the best way to find new malwares and send to avast! labs. I hate piracy.... is one of the causes of the recessions and crisis. Including lost jobs.  

Edit: Thanks for your info polonus.  
« Last Edit: July 01, 2010, 03:53:16 AM by iRanzel »

Avastfan1

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #538 on: July 01, 2010, 02:49:12 PM »
Not sure if the Beeb was a little late reporting this... http://news.bbc.co.uk/2/hi/technology/10473495.stm

Has anybody used the workaround? http://support.microsoft.com/kb/2219475

YoKenny

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #539 on: July 01, 2010, 02:57:10 PM »

Has anybody used the workaround? http://support.microsoft.com/kb/2219475
Installed ages ago on my XP Pro system when it was released June 14, 2010