Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2888675 times)

0 Members and 3 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
« Last Edit: August 25, 2010, 11:36:35 PM by Asyn »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #676 on: August 25, 2010, 11:32:21 PM »
Apple releases Security Update for Mac OS X
http://support.apple.com/kb/HT4312
asyn
« Last Edit: August 25, 2010, 11:37:42 PM by Asyn »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #677 on: August 25, 2010, 11:55:54 PM »
Apple releases Security Update for Mac OS X
http://support.apple.com/kb/HT4312
asyn

well that's cool ??? ;D

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #678 on: August 26, 2010, 12:50:03 AM »
Logos,

On the site that came after millw0rm there are already exploits presented for Windows Live Email, uTorrent, Foxit Reader, Microsoft Power Point & Wireshark via DLL-hijacking. Standard Vista and Windows 7 programs are vulnerable: https://twitter.com/avivra/statuses/21994799124 Social engineering became just a bit easier: http://twitter.com/avivra/status/22000389011 Metasploit does all this automatically: https://twitter.com/hdmoore/status/22003840688
MS yesterday presented a tool to prevent loading of libraries of shared network folders: : http://support.microsoft.com/kb/2264107 and a patch, here for Vista: http://www.microsoft.com/downloads/en/confirmation.aspx?familyId=86631d97-ebed-4346-be66-d6ba0f500cea&displayLang=en&pf=true
A good thing avast detects DLL-exploit,

polonus
« Last Edit: August 26, 2010, 12:56:41 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #679 on: August 26, 2010, 10:20:15 AM »
@ Polonus: there was an article about that yesterday (dll hijacking), I got to find it again (I think that was an MS advisory), was mentioning that Firefox was vulnerable too. There's no possible fix with Windows, application developers are strongly advised (by MS) to change "something" in the way their app relates to Windows API, only way to get rid of the vulnerability.
 But MS will provide the tools to be used for each OS by third party devs.
http://www.infosecurity-us.com/view/12030/dll-hijacking-bug-hits-microsoft-windows-/
http://www.microsoft.com/technet/security/advisory/2269637.mspx

edit: Avast is or was vulnerable too (I think I read in the forums here that the issue was fixed)
http://vupen.com/english/searchengine.php?keyword=insecure+library+loading

Avast! Antivirus File Opening Insecure Library Loading Vulnerability
http://www.vupen.com/english/advisories/2010/2175

Mozilla Firefox File Opening Insecure Library Loading Vulnerability
http://www.vupen.com/english/advisories/2010/2169

   
Quote
25.08.2010 : Avast! Antivirus File Opening Insecure Library Loading Vulnerability

 25.08.2010 : TeamViewer File Opening Insecure Library Loading Vulnerability

 25.08.2010 : Microsoft Windows Live Mail Insecure Library Loading Vulnerability

 25.08.2010 : VLC Media Player File Opening Insecure Library Loading Vulnerability

 25.08.2010 : Adobe Dreamweaver File Opening Insecure Library Loading Vulnerability

 25.08.2010 : Adobe Photoshop File Opening Insecure Library Loading Vulnerability

 25.08.2010 : Mozilla Firefox File Opening Insecure Library Loading Vulnerability

 25.08.2010 : Microsoft Windows Address Book Insecure Library Loading Vulnerability

 25.08.2010 : Opera Browser File Opening Insecure Library Loading Vulnerability

 25.08.2010 : Microsoft Office PowerPoint Insecure Library Loading Vulnerability

 25.08.2010 : Wireshark File Opening Insecure Library Loading Vulnerability

 25.08.2010 : uTorrent File Opening Insecure Library Loading Vulnerability
« Last Edit: August 26, 2010, 10:31:13 AM by Logos »

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #680 on: August 26, 2010, 06:45:32 PM »

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #681 on: August 26, 2010, 07:38:28 PM »
okay it's important to mention that Avast pre-release version is patched, I knew that a patch was mentioned by Vlk in his post about the pre-release:
http://forum.avast.com/index.php?topic=63151.msg533449#msg533449
... but I wasn't sure it was about the same vulnerability. Just got confirmation from Avast that it was actually just that.



Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #682 on: August 26, 2010, 08:56:45 PM »

gonzo416

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #683 on: August 27, 2010, 05:40:18 PM »
 I was on a IE tab on firefox and a page just showed up that said: 

                  STOCKPHOTO
you just have been hacked By tun hacker
hacked by Number 7. Tn.Spamer
contact; an.7@live.fr greetz: tun hackers~~underground people

I really need help because I don't know what to do. I unplugged the ethernet cable to the desktop. I hope this laptop is not affected.

HELP!!!!HELP!!!!!PLEASE,PLEASE,PLEASE!!!!!!!!!!!

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #684 on: August 27, 2010, 05:43:37 PM »
I was on a IE tab on firefox and a page just showed up that said: 

                  STOCKPHOTO
you just have been hacked By tun hacker
hacked by Number 7. Tn.Spamer
contact; an.7@live.fr greetz: tun hackers~~underground people

I really need help because I don't know what to do. I unplugged the ethernet cable to the desktop. I hope this laptop is not affected.

HELP!!!!HELP!!!!!PLEASE,PLEASE,PLEASE!!!!!!!!!!!

this is not a help thread. Why did you post here ???

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #685 on: August 27, 2010, 06:21:42 PM »
Hi malware fighters,

Autorun DLL Hijacker usb stick: http://www.attackvector.org/autorun-dll-hijacker-usb-stick/
One day attackers will also use malicious pop-ups, just wait and see,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #686 on: August 27, 2010, 07:27:57 PM »

spg SCOTT

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #687 on: August 27, 2010, 09:08:36 PM »
Outbreak: Fake Fedex Tracking Number emails carry malware
http://origin-www.sophos.com/blogs/gc/g/2010/08/26/outbreak-fake-fedex-tracking-number-emails-carry-malware/

Not new at all.

I have had these in various guises for ages now...
(one thing I still don't get is that the email says it is to someone with a completely different email address and yet it still comes to me... ???)
http://forum.avast.com/index.php?topic=59388.msg500590#msg500590

YoKenny

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #688 on: August 28, 2010, 12:16:17 AM »
@ spg SCOTT

See Bcc:
Quote
Blind carbon copy

In the context of correspondence, blind carbon copy (abbreviated Bcc:) refers to the practice of sending a message to multiple recipients in such a way that conceals individual email addresses (mentioned in "to" field of the mail) from the complete list of recipients.
http://en.wikipedia.org/wiki/Blind_carbon_copy

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #689 on: August 28, 2010, 12:53:38 AM »
<snip>
Not new at all.

I have had these in various guises for ages now...
(one thing I still don't get is that the email says it is to someone with a completely different email address and yet it still comes to me... ???)
<snip>

That should be the biggest clue of all that it is a fake as a legit copy would be directly addressed to the customer to whom the invoice/tracking number, etc. consignment is for.

But the spammers aren't going to send out spam to individual addresses but to groups of addresses.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security