Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2889346 times)

0 Members and 1 Guest are viewing this topic.

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #705 on: September 01, 2010, 10:33:17 AM »
Apple QuickTime backdoor creates code-execution peril / Getting punked by 9-year-old parameter
http://www.theregister.co.uk/2010/08/30/apple_quicktime_critical_vuln/

Detailed Info here:
http://reversemode.com/index.php?option=com_content&task=view&id=69&Itemid=1
asyn

my quicktime install just got an automatic update, so may be it fixed that...

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #706 on: September 01, 2010, 11:27:55 PM »
Hi malware fighters,

0-days will be found here during all of this month: http://www.exploit-db.com/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #708 on: September 03, 2010, 11:51:02 PM »
Hackers blind quantum cryptographers
http://www.nature.com/news/2010/100829/full/news.2010.436.html

Hacking commercial quantum cryptography systems by tailored bright illumination
http://www.nature.com/nphoton/journal/vaop/ncurrent/full/nphoton.2010.214.html



Number of vulnerabilities on the rise
http://www.norman.com/security_center/security_center_archive/2010/91886/en

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #709 on: September 04, 2010, 09:15:18 PM »
Thanks Pondus,

Google Code removed 50 malware after being alerted they were on their servers: http://threatpost.com/en_us/blogs/google-code-discovered-serving-malware-090110

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #710 on: September 04, 2010, 09:40:26 PM »
It would be nice if they took a pro-active response to this type of thing, rather than a reactive response waiting for someone to tell them.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #711 on: September 04, 2010, 09:47:09 PM »
Hi DavidR,

A bit like a sort of Pontius Pilate comment by Google's, also seen from their official policy
Quote
"Google actively works to protect our users from malware. Using Google Code, or any of our products, for distribution or coordination of malware is a violation of our product policies, and we will remove any projects discovered to be used for these purposes," a Google spokesman responded in an e-mail message to Threatpost.com."

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #712 on: September 07, 2010, 11:46:11 AM »
MS probes mystery IE bug
http://www.theregister.co.uk/2010/09/06/mystery_ie_bug/

Quote
Microsoft is investigating reports of a new bug in Internet Explorer.

Redmond's Security Response Team (MSRT) said on Friday that it was aware of a "publicly disclosed issue involving Internet Explorer", and promised an investigation, without going into details.

Circumstantial evidence suggests Microsoft is referring to a post by security researcher Chris Evans, of Google, to a Full Disclosure mailing list on Friday, hours before MSRT's tweet.

"A nasty vulnerability exists in the latest Internet Explorer 8," Evans wrote. "I have been unsuccessful in persuading the vendor to issue a fix."

"The bug permits — for example — an arbitrary web site to force the victim to make tweets," he added.

http://twitter.com/msftsecresponse/status/22934606564

(see the article from the register to get the link to the full description, as I'd rather not post this link here)
« Last Edit: September 07, 2010, 11:49:40 AM by Logos »



Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #715 on: September 10, 2010, 09:49:39 AM »
Beware of Link: E-Mail Virus Plays Havoc With Internet

An e-mail virus swept through the Internet Thursday, snarling traffic and taking down servers at ABC, NASA, Comcast, and Google -- and possibly even affecting the Department of Homeland Security.


http://www.foxnews.com/scitech/2010/09/09/beware-link-e-mail-virus-plays-havoc-internet/?test=latestnews
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #716 on: September 14, 2010, 09:57:12 PM »
Hi folks,

Hackers target and exploit Pirate bay's Adserver. Also big sites using OpenX were apparently being hacked: http://torrentfreak.com/hackers-target-and-exploit-pirate-bay-ad-server-100913/

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #717 on: September 16, 2010, 11:20:46 AM »
Old vulnerability in Apple's QuickTime Player allows remote code execution for Windows systems (UPDATED)
http://www.norman.com/security_center/security_center_archive/2010/91862/en

About the security content of QuickTime 7.6.8
http://support.apple.com/kb/HT4339

YoKenny

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #718 on: September 16, 2010, 03:17:30 PM »
Old vulnerability in Apple's QuickTime Player allows remote code execution for Windows systems (UPDATED)
http://www.norman.com/security_center/security_center_archive/2010/91862/en

About the security content of QuickTime 7.6.8
http://support.apple.com/kb/HT4339

Key statement
Quote
Update 16 September 2010
Apple has published QuickTime version 7.6.8. This update fixes the vulnerability mentioned above as well as another vulnerability in previous QuickTime versions.
I have version 7.68.75.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #719 on: September 17, 2010, 09:40:58 AM »
Update to Mozilla Firefox solves several critical vulnerabilities (UPDATED)
http://www.norman.com/security_center/security_center_archive/2010/91922/en