Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2880181 times)

0 Members and 8 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #690 on: August 28, 2010, 05:16:28 PM »
Attackers exploit DLL vulnerability in Office and other applications
http://isc.sans.edu/diary.html?storyid=9445
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #691 on: August 28, 2010, 05:45:09 PM »
Hi malware fighters,

How tracking cookies are being preserved inside IE, while the user want to delete them at close down of the browser:
http://ha.ckers.org/blog/20100827/ie-cookies/
IE does not handle cookies always with the browser user in mind,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #692 on: August 28, 2010, 06:15:44 PM »
IE does not handle cookies always with the browser user in mind,
polonus

Yes D., true..!
That's just one of the reasons why I never would use it...
Btw., Ccleaner does a good job here. ;)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

YoKenny

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #693 on: August 28, 2010, 06:26:11 PM »
IE does not handle cookies always with the browser user in mind,
polonus

Yes D., true..!
That's just one of the reasons why I never would use it...
Btw., Ccleaner does a good job here. ;)
asyn
Also for Firefox.  ;)

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #695 on: August 30, 2010, 09:37:39 PM »
Hi mkis,

Yes Pushbot was infiltrated, but it seems that the C&C servers are being specifically protected by Chinese and American hosting firms, so the perpetrators will keep a low profile for a while and then to continue their activities: http://blog.fireeye.com/research/2010/08/infiltrating-pushdo-part-2.html
So this time they were saved by their own back-up C&C-servers. Hard to understand why the various governments (USA, Europe, Russia, China) did not close down the hosting firms of aforementioned back-up C&C servers or they must have a serious interest not to take action?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Gargamel360

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #696 on: August 30, 2010, 09:57:15 PM »
Hard to understand why the various governments (USA, Europe, Russia, China) did not close down the hosting firms of aforementioned back-up C&C servers or they must have a serious interest not to take action?

polonus
Big Gov's intelligence sectors love dipping fingers into black market.  They maybe (I say MAYBE ;))have vested interest/money in keeping them going. 

But it might just be good old bureaucratic "red tape" also.   Don't know about abroad, but in the states you could tell the Fed. Govt. their pants are on fire, they would have to fill out 20 different requisition forms to request first a fire extinguisher, then more forms for what type, weight, etc.   All the while with pants still burning.


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #697 on: August 30, 2010, 10:04:44 PM »
Hi malware fighters,

Just in a new DLL-Hijacking exploit, this time for Fx: http://www.exploit-db.com/exploits/14730/
They keep them coming,
Detect vulnerable Windows apps within 25 to 30 minutes with this free tool: https://www.metasploit.com/redmine/projects/framework/repository/raw/external/source/DLLHijackAuditKit.zip

polonus
« Last Edit: August 30, 2010, 11:00:57 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

YoKenny

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #698 on: August 31, 2010, 12:13:47 AM »
Detect vulnerable Windows apps within 25 to 30 minutes with this free tool: https://www.metasploit.com/redmine/projects/framework/repository/raw/external/source/DLLHijackAuditKit.zip

polonus
What I see
Quote
Internet Explorer cannot display the webpage

I guess Fx is being exploited now.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89015
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #699 on: August 31, 2010, 12:31:59 AM »
It isn't a web page, but a zip file to be downloaded, so I rather doubt you could display it in any browser.

Most browsers would recognise it isn't a web page and download the file (depending on your settings) or pop-up a download window.

Mine recognised it as a zip file and downloaded it as per my settings.

So firefox isn't being exploited, rather IE can't seem to deal with a download link.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48542
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #700 on: August 31, 2010, 01:21:40 AM »
Detect vulnerable Windows apps within 25 to 30 minutes with this free tool: https://www.metasploit.com/redmine/projects/framework/repository/raw/external/source/DLLHijackAuditKit.zip

polonus
What I see
Quote
Internet Explorer cannot display the webpage

I guess Fx is being exploited now.
The link actually crashed IE 8 so I guess it's IE8 that has a problem.
Copying the link opened Gigaget (download manager) which had no problems downloading the .zip file
Chrome also had no problems handling the link posted. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

timcan

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #701 on: August 31, 2010, 02:23:31 AM »
Detect vulnerable Windows apps within 25 to 30 minutes with this free tool: https://www.metasploit.com/redmine/projects/framework/repository/raw/external/source/DLLHijackAuditKit.zip

polonus
What I see
Quote
Internet Explorer cannot display the webpage

I guess Fx is being exploited now.
The link actually crashed IE 8 so I guess it's IE8 that has a problem.
Copying the link opened Gigaget (download manager) which had no problems downloading the .zip file
Chrome also had no problems handling the link posted. :)

 ???

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #702 on: August 31, 2010, 11:18:48 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #703 on: August 31, 2010, 10:18:08 PM »
Apple QuickTime backdoor creates code-execution peril / Getting punked by 9-year-old parameter
http://www.theregister.co.uk/2010/08/30/apple_quicktime_critical_vuln/

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #704 on: September 01, 2010, 09:37:23 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0