Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2886034 times)

0 Members and 5 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #660 on: August 18, 2010, 12:01:34 PM »
Government Uses Social Networking Sites for More than Investigations
http://www.eff.org/deeplinks/2010/08/government-monitors-much-more-social-networks
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #661 on: August 18, 2010, 01:25:17 PM »
Government Uses Social Networking Sites for More than Investigations
http://www.eff.org/deeplinks/2010/08/government-monitors-much-more-social-networks
asyn


yeah so what...there's nothing surprising, when people agree to disclose aspects of their private life on the net, without restricting access anyway, it is also expected that the cops etc...might get interested ;D

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #662 on: August 18, 2010, 03:48:29 PM »
Skeletons Hidden in the Linux Closet: r00ting your Linux
http://theinvisiblethings.blogspot.com/2010/08/skeletons-hidden-in-linux-closet.html
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0


Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #664 on: August 19, 2010, 01:43:41 PM »
Due to fake digital signatures (stolen), other antivirus/suites are removing this option from their products.
For instance Comodo (for registered users: https://forums.comodo.com/beta-corner-cis/no-option-for-not-trusting-digitally-signed-applications-t60658.0.html;msg425806#msg425806).
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #665 on: August 19, 2010, 04:19:28 PM »
Hi malware fighters,

A likewise big hole similar to the LNK-hole or even bigger has been found up for 40 Windows apps together with
the Windows shell and various dll's should be patched for this exploit vector, http://twitter.com/hdmoore/status/21510351207
The cat is out of the b*g, whether this is read like bug or bag!
For the time being one should block TCP ports 139 and 445 and en disable the WebDAV client.
To close the ports use WWDC = Windows Worms Doors Cleaner 1.4 from here:
http://www.dobreprogramy.pl/Windows-Worms-Doors-Cleaner,Program,Windows,11744.html
Windows-Worms-Doors-Cleaner is a very good small program to do this,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #666 on: August 19, 2010, 05:14:08 PM »
Skeletons Hidden in the Linux Closet: r00ting your Linux
http://theinvisiblethings.blogspot.com/2010/08/skeletons-hidden-in-linux-closet.html
asyn

Update #1 - In an email, Joanna Rutowska clarifies that Spengler's exploit targets "some unrelated vulnerability" and her reference to it was in relation to guesses made by Spengler noted in the source code comments.

Update #2 - As Marcus Meissner from the SUSE security team explained to heise Security, SUSE maintainer Andrea Arcangeli provided a fix for the problem in September 2004, but for unknown reasons this fix was not included in the Linux kernel. SUSE itself has the fix and SUSE Linux Enterprise 9, 10 and 11 as well as openSUSE 11.1 through 11.3 do not exhibit this vulnerability.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #667 on: August 19, 2010, 05:27:09 PM »
Hi malware fighters,
A likewise big hole similar to the LNK-hole or even bigger has been found up for 40 Windows apps together with
the Windows shell and various dll's should be patched for this exploit vector, http://twitter.com/hdmoore/status/21510351207

Hi polonus,
more info here...
http://www.h-online.com/security/news/item/New-Windows-vulnerability-Applications-download-malicious-code-from-the-net-1062153.html
related info...
http://www.acrossecurity.com/aspr/ASPR-2010-08-18-1-PUB.txt
asyn
« Last Edit: August 19, 2010, 05:28:57 PM by Asyn »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #668 on: August 19, 2010, 07:52:07 PM »
Hi Asyn,

The Metasploit exploit is ready made and waiting on desk, but has not been issued yet, because the exploit has not been revealed so far.
There are many more skeletons around in the MS cupboard. Mind you what vulnerabilities we will see because of the memory adjustments that were applied long way back as the NT 4.0 days,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #669 on: August 19, 2010, 08:02:25 PM »
Hi Asyn,
The Metasploit exploit is ready made and waiting on desk, but has not been issued yet, because the exploit has not been revealed so far.

I'll post any news on that when available, asap.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

YoKenny

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #670 on: August 19, 2010, 08:18:28 PM »
Hi malware fighters,

A likewise big hole similar to the LNK-hole or even bigger has been found up for 40 Windows apps together with
the Windows shell and various dll's should be patched for this exploit vector, http://twitter.com/hdmoore/status/21510351207
The cat is out of the b*g, whether this is read like bug or bag!
For the time being one should block TCP ports 139 and 445 and en disable the WebDAV client.
To close the ports use WWDC = Windows Worms Doors Cleaner 1.4 from here:
http://www.dobreprogramy.pl/Windows-Worms-Doors-Cleaner,Program,Windows,11744.html
Windows-Worms-Doors-Cleaner is a very good small program to do this,

polonus

Does not work on Windows 7!

iRonzel

  • Guest

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #672 on: August 20, 2010, 09:47:40 PM »
Hi forum friends,

The newly detected remote binary planting hole in Windows is much more severe than first thought, nearly all applications (220 were tested) are affected: http://news.idg.no/cw/art.cfm?id=8C1F74F0-1A64-67EA-E49A617FAC05584F
Moreover the hole can be exploited quite easily. Most Windows applications use the exploitable functionality so an MS patch will not be a very easy task, moreover patching or changing how the functionality works could break quite some applications. The exploit could have been around for 10 years, and was re-detected: http://www.securityfocus.com/bid/1699/discuss
At the time it was called: Microsoft Windows DLL Search Path Weakness.
http://msdn2.microsoft.com/en-us/library/ms972822.aspx.
The scope of the hole and abusing the exploit: https://deepsec.net/docs/speaker.html#PSLOT33

http://www.juniper.net/security/auto/vulnerabilities/vuln1699.html

A firewall blocking outbound WebDAV traffic (in addition to blocking all
Windows Networking protocols) could stop an Internet-based attack.

How many of these holes are still around in the dark corners of Microsoft's code?,

polonus
« Last Edit: August 21, 2010, 07:03:17 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #673 on: August 22, 2010, 02:07:23 PM »
Scareware tries to trick marks into dropping defences
http://www.theregister.co.uk/2010/08/20/social_engineering_scareware/

and this is the bug

Rogue Turning Retrovirus
http://www.symantec.com/connect/blogs/rogue-turning-retrovirus

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0