Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904757 times)

0 Members and 3 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1996 on: July 20, 2012, 04:02:15 PM »
New 'Madi' cyber-espionage campaign targets Iran AND Israel

Attackers 'fluent in Persian', say security sinkholers
http://www.theregister.co.uk/2012/07/17/madi_cyber_espionage_campaign/
more Madi

Iran: If the Madi cyber-strike was us it would've been another Stuxnet
http://www.theregister.co.uk/2012/07/20/madi_cyberspy_analysis/


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

CharleyO

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #1999 on: July 24, 2012, 07:13:00 PM »
***

8 Million Email Addresses And Passwords Spilled From Gaming Site Gamigo Months After Hacker Breach

Quote
Call it a slow leak. Four months after the gaming site Gamigo warned users about a hacker intrusion that accessed some portions of its users’ credentials, more than 8 million usernames, emails and and encrypted passwords from the site have been published on the Web, according to the data breach alert service PwnedList. The half-gigabyte collection of stolen user data was posted to the password-cracking forum Inside Pro earlier this month, where it remained online until late last week.


Read more at :
http://www.forbes.com/sites/andygreenberg/2012/07/23/eight-million-passwords-spilled-from-gaming-site-gamigo-months-after-breach/


***

CharleyO

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2000 on: July 24, 2012, 07:21:47 PM »
***

Hacker Will Expose Potential Security Flaw In Four Million Hotel Room Keycard Locks

Quote
The next time you stay in a hotel room, run your fingers under the keycard lock outside your door. If you find a DC power port there, take note: With a few hacker tricks and a handful of cheap hardware, that tiny round hole might offer access to your room just as completely as your keycard.

At the Black Hat security conference Tuesday evening, a Mozilla software developer and 24-year old security researcher named Cody Brocious plans to present a pair of vulnerabilities he’s discovered in hotel room locks from the manufacturer Onity, whose devices are installed on the doors of between four and five million hotel rooms around the world according to the company’s figures. Using an open-source hardware gadget Brocious built for less than $50, he can insert a plug into that DC port and sometimes, albeit unreliably, open the lock in a matter of seconds. “I plug it in, power it up, and the lock opens,” he says simply.


Read more at :
http://www.forbes.com/sites/andygreenberg/2012/07/23/hacker-will-expose-potential-security-flaw-in-more-than-four-million-hotel-room-keycard-locks/


***

CharleyO

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2001 on: July 24, 2012, 07:30:21 PM »
***

ATM Skimmers Get Wafer Thin

Quote
It’s getting harder to detect some of the newer ATM skimmers, fraud devices attached to or inserted into cash machines and designed to steal card and PIN data. Among the latest and most difficult-to-spot skimmer innovations is a wafer-thin card reading device that can be inserted directly into the ATM’s card acceptance slot.


See and read more at :
http://krebsonsecurity.com/2012/07/atm-skimmers-get-wafer-thin/


***

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2002 on: July 24, 2012, 07:37:28 PM »
Hack Reveals Security Flaw with In-App Purchases

http://www.ign.com/articles/2012/07/14/hack-reveals-security-flaw-with-in-app-purchases

A Hack has been found to enable free in app purchases from the App Store for iOS Devices
"People who are really serious about software should make their own hardware." - Alan Kay

CharleyO

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2003 on: July 24, 2012, 07:56:11 PM »
***

Warning: Battery-saver app on Android is malware

Quote
A new piece of malware is trying to take advantage of poor battery life on Android smartphones. Cybercriminals have created an app that is supposed to reduce battery use, but in reality steals the user's contacts data stored on the device.

Android.Ackposts is a Trojan horse for Android devices that steals the Contacts information from the compromised device and sends it to a predetermined location. The Trojan may arrive as a package with the following name: BatteryLong.apk.


See and read more at :
http://www.zdnet.com/warning-battery-saver-app-on-android-is-malware-7000001483/


***

CharleyO

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2004 on: July 24, 2012, 08:09:49 PM »
***

Mom arrested for hacking school computers, tweaking her kids' grades

Quote
A US mother is facing six felony counts for allegedly hacking into her children's school computer, changing their grades, and accessing the school's human resources system to open thousands of personnel files that contained contracts, employee reports and other information.

Venusto is accused of changing her daughter's grade from an F to an M for "medical," of allegedly boosting her son's grade of 98 percent to 99 percent, and of using the superintendent's information to log onto the district email system and to access Northwestern Lehigh's human resources system.


Read more at :
http://nakedsecurity.sophos.com/2012/07/23/mom-hacking-school-grades/?utm_campaign=Feed%3A+nakedsecurity+%28Naked+Security+-+Sophos%29&utm_medium=feed&utm_source=feedburner


***

Offline MikeBCda

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2247
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2005 on: July 24, 2012, 09:12:41 PM »
***

Hacker Will Expose Potential Security Flaw In Four Million Hotel Room Keycard Locks

Quote
The next time you stay in a hotel room, run your fingers under the keycard lock outside your door. If you find a DC power port there, take note: With a few hacker tricks and a handful of cheap hardware, that tiny round hole might offer access to your room just as completely as your keycard.

At the Black Hat security conference Tuesday evening, a Mozilla software developer and 24-year old security researcher named Cody Brocious plans to present a pair of vulnerabilities he’s discovered in hotel room locks from the manufacturer Onity, whose devices are installed on the doors of between four and five million hotel rooms around the world according to the company’s figures. Using an open-source hardware gadget Brocious built for less than $50, he can insert a plug into that DC port and sometimes, albeit unreliably, open the lock in a matter of seconds. “I plug it in, power it up, and the lock opens,” he says simply.

Sometimes you don't even have to go high-tech.  A few years ago when they were doing major roofing work on our apartment building (we're on the top floor), the management moved us to a nearby hotel for the weekend.  At one point I'd gone downstairs there (breakfast, maybe?), and because for some reason the room numbers didn't correspond with the floor they were on, coming back up I got off the elevator on the wrong floor.

My card opened "our" room just fine, and it was only when I didn't see any of our belongings that I realized my error.  Fortunately the room was unoccupied -- I'm guessing the hotel left unbooked rooms unlocked for the convenience of cleaning and other staff.
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-11, Firefox 51.0
(default). 320 gig HD, 15Mb DSL, Win firewall, Avast 12.3.2280 free, SpywareBlaster, MBAM Prem., Crypto-Prevent

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2006 on: July 25, 2012, 10:52:49 PM »
Hi friends,

Be aware that this could become a real threat: http://community.websense.com/blogs/securitylabs/archive/2012/07/20/a-malware-very-social-and-ready-for-the-olympic-games.aspx  (link post author = Gianluca Giuliani). Don't say we did not warn you to watch your clicks,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2007 on: July 26, 2012, 01:01:12 PM »
Keep your java up to date, go here to check: http://www.java.com/en/download/installed.jsp

Gigantic increase in java based malware recently.
See: http://blogs.technet.com/b/mmpc/archive/2012/07/25/how-to-protect-yourself-from-java-based-malware.aspx
(link article author = MS's Jeong Wook, Microsoft Malware Protection Center,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2008 on: July 26, 2012, 01:05:29 PM »
Keep your java up to date, go here to check: http://www.java.com/en/download/installed.jsp

Gigantic increase in java based malware recently.
See: http://blogs.technet.com/b/mmpc/archive/2012/07/25/how-to-protect-yourself-from-java-based-malware.aspx
(link article author = MS's Jeong Wook, Microsoft Malware Protection Center,

polonus

No Java here for a long time...!!
Funny thing is that most users don't even know that most of them don't need it at all... ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2009 on: July 26, 2012, 01:45:47 PM »
Hi Asyn,

What would help would be the extra click to allow it to run in a browser. I hope that will be brought in. Some browsers will keep it up to date for you, and the cases where you need the java functionality (specific scanners and applications) are becoming rare,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!