Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2886570 times)

0 Members and 4 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1096 on: February 15, 2011, 07:15:48 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

malcontent

  • Guest
Hacked BBC streaming websites serve up malware
« Reply #1097 on: February 15, 2011, 09:38:01 PM »
http://www.theregister.co.uk/2011/02/15/bbc_driveby_download/
Quote
Streaming sites operated by the BBC were hacked on Tuesday so they silently served visitors with malware, researchers from security firm Websense said.

An iframe tag on the BBC's 6 Music and 1Xtra websites injected an exploit that was housed on a website with an address ending in cc, a top level domain for the Cocos Islands. The malicious binary was generated by the Phoenix exploit kit, which dates back to 2007 and streamlines malware infections by collecting detailed statistics.

“If an unprotected user browsed to the site they would be faced with drive-by downloads, meaning that simply browsing to the page is enough to get infected with a malicious executable,” Websense researchers wrote in a blog post.

A VirusTotal scan showed that only nine of the top 43 antivirus products detected the threat.

http://www.virustotal.com/file-scan/report.html?id=4a0ab371e6c6dd54deeab41ab1b77fa373d2face149523dfd183d669b31da6bc-1297784293

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1099 on: February 16, 2011, 01:30:56 PM »
Winamp Forums Security Notification

http://forums.winamp.com/showthread.php?t=327366
Quote
We have confirmed that your email address was exposed as a result of this attack. We have not confirmed but must assume that other Winamp Forums user account detail, including your forums username, date of birth, time zone preference and encrypted password (not your clear text or unencrypted password) was exposed. The Winamp Forums are now secure, but because we value your privacy we would like to notify you of the incident and encourage you to immediately change your password as a precautionary measure. If you have used your Winamp forums password across other web sites, please change the password on those web sites as well.
Twitter: OmidFarhangEn - OS: Manjaro KDE

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
« Last Edit: February 17, 2011, 09:59:28 AM by Asyn »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

YoKenny

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1102 on: February 17, 2011, 02:30:48 PM »

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1103 on: February 17, 2011, 04:21:34 PM »
http://www.theregister.co.uk/2011/02/15/bbc_driveby_download/
Quote
Streaming sites operated by the BBC were hacked on Tuesday so they silently served visitors with malware, researchers from security firm Websense said.

An iframe tag on the BBC's 6 Music and 1Xtra websites injected an exploit that was housed on a website with an address ending in cc, a top level domain for the Cocos Islands. The malicious binary was generated by the Phoenix exploit kit, which dates back to 2007 and streamlines malware infections by collecting detailed statistics.

“If an unprotected user browsed to the site they would be faced with drive-by downloads, meaning that simply browsing to the page is enough to get infected with a malicious executable,” Websense researchers wrote in a blog post.

A VirusTotal scan showed that only nine of the top 43 antivirus products detected the threat.

http://www.virustotal.com/file-scan/report.html?id=4a0ab371e6c6dd54deeab41ab1b77fa373d2face149523dfd183d669b31da6bc-1297784293

interesting yesterdays refresh claims that Avast! still fails to identify this threat
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

spg SCOTT

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1104 on: February 17, 2011, 07:37:21 PM »
Just took that script and put it in a text file, and scanned it with avast. The iframe was detected.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1105 on: February 21, 2011, 02:03:05 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0



Alan Baxter

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1108 on: February 21, 2011, 10:40:39 PM »
Thank you, YoKenny.  I get the same results in IE8 even after flushing the Windows XP DNS cache.  Google DNS (8.8.8.8) returns an IP of 174.122.92.18 for www.socialnetworksecurity.org.  When I enter the IP in IE8 I still get the 404.  Could you enter nslookup www.socialnetworksecurity.org in a command window and tell me your result?  I'd like to know the IP of your server and the IP it returns for the problematic website.

Edit: The Level 3 name server at 4.2.2.1 is returning 174.122.92.41, which at least takes me to the socialnetworksecurity.org German language page.
« Last Edit: February 21, 2011, 11:01:18 PM by Alan Baxter »

YoKenny

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1109 on: February 22, 2011, 12:37:29 AM »
Could you enter nslookup www.socialnetworksecurity.org in a command window and tell me your result?  I'd like to know the IP of your server and the IP it returns for the problematic website.

Response from nslookup
Code: [Select]
C:\>nslookup www.socialnetworksecurity.org
Server:  resolver1-fs.opendns.com
Address:  208.67.222.123

Non-authoritative answer:
Name:    www.socialnetworksecurity.org.2wire.net
Address:  67.215.65.132