Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904761 times)

0 Members and 4 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2326 on: January 14, 2013, 02:12:17 PM »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2327 on: January 14, 2013, 03:33:48 PM »
The patch is to change the security setting from medium to high... So now the user has to confirm that he wants the script to run..  Now how foolproof is that

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2328 on: January 14, 2013, 03:44:45 PM »
The patch is to change the security setting from medium to high... So now the user has to confirm that he wants the script to run..  Now how foolproof is that
Now you can put the blame on the user for the infection and hold Oracle blameless.  :'(
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2329 on: January 14, 2013, 05:54:36 PM »
The attack code abusing the vulnerability, has been added to exploit-kits like Blackhole, Nuclear Pack en Cool Exploit Kit and also to Gong Da / Gondad Exploit Pack, read: http://eromang.zataz.com/2013/01/13/gong-da-gondad-exploit-pack-add-java-cve-2013-0422-support/ (link article author eric romang)

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2330 on: January 14, 2013, 09:57:28 PM »
The patch is to change the security setting from medium to high... So now the user has to confirm that he wants the script to run..  Now how foolproof is that
The patch is to change the security setting from medium to high... So now the user has to confirm that he wants the script to run..  Now how foolproof is that
Now you can put the blame on the user for the infection and hold Oracle blameless.  :'(
We can do better than that.  All we have to do is remove java completely and avoid this issue entirely.  Shame on Oracle for resorting to "fixing" a known exploit that is now being actively exploited in the wild in this way.

This is a "fix" I could have done by myself, no help needed from Oracle.  Problem is, do noobies know what to do with the alerts?  Probably not.   >:(   More work for IT staff anyways.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2331 on: January 15, 2013, 04:25:44 PM »
The patch is to change the security setting from medium to high... So now the user has to confirm that he wants the script to run..  Now how foolproof is that
The patch is to change the security setting from medium to high... So now the user has to confirm that he wants the script to run..  Now how foolproof is that
Now you can put the blame on the user for the infection and hold Oracle blameless.  :'(
We can do better than that.  All we have to do is remove java completely and avoid this issue entirely.  Shame on Oracle for resorting to "fixing" a known exploit that is now being actively exploited in the wild in this way.

This is a "fix" I could have done by myself, no help needed from Oracle.  Problem is, do noobies know what to do with the alerts?  Probably not.   >:(   More work for IT staff anyways.

Confirmed: Java only fixed one of the two bugs
http://immunityproducts.blogspot.ca/2013/01/confirmed-java-only-fixed-one-of-two.html
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2333 on: January 16, 2013, 10:39:16 PM »

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2334 on: January 17, 2013, 05:08:24 AM »
Malware Infecting US Power Plant SCADA Systems

http://www.hotforsecurity.com/blog/malware-infecting-us-power-plant-scada-systems-5050.html

It's already happening here.

BTW,  FF has a setting in Tools>Options>Content where one can disable JavaScript within the browser.  See essexboy's post above. 

Anyone realize that the icons for url and others in the text reply box are java-script based, and will not work or be present when JavaScript is turned off in the browser?
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2335 on: January 17, 2013, 08:31:56 AM »
BTW,  FF has a setting in Tools>Options>Content where one can disable JavaScript within the browser.  See essexboy's post above. 

Java and JavaScript are two different things..!!
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2336 on: January 17, 2013, 02:27:53 PM »
BTW,  FF has a setting in Tools>Options>Content where one can disable JavaScript within the browser.  See essexboy's post above. 

Java and JavaScript are two different things..!!
You can also check the following thread for full removal details:
http://forum.avast.com/index.php?topic=19387.msg884597#msg884597
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2337 on: January 17, 2013, 06:55:59 PM »
BTW,  FF has a setting in Tools>Options>Content where one can disable JavaScript within the browser.  See essexboy's post above. 

Java and JavaScript are two different things..!!
You can also check the following thread for full removal details:
http://forum.avast.com/index.php?topic=19387.msg884597#msg884597
Sorry, guys.

Some things I have yet to learn.  Reason I noted javascript in the browser is because without it running, then things such as accessing webmail is not possible unless one uses an older version of it that does not require it, c|net member logon not doable without it, even mediafire will not work without it, Avast text reply box is missing the common icons for text and link enhancement, and so on.  Since it is the java plugin from Oracle that is 99% of the problem, have been testing running the browser without javascript and finding it seems to be used in everything everywhere I go.

Do not have java anything installed atm, just so you know.  It is apparent that FF, at least, provides their own version of java in the form of a FF javascript and one still needs that to view normal web content within the browser.  Just experimenting.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2338 on: January 17, 2013, 09:53:22 PM »
BTW,  FF has a setting in Tools>Options>Content where one can disable JavaScript within the browser.  See essexboy's post above. 

Java and JavaScript are two different things..!!
You can also check the following thread for full removal details:
http://forum.avast.com/index.php?topic=19387.msg884597#msg884597
Sorry, guys.

Some things I have yet to learn.  Reason I noted javascript in the browser is because without it running, then things such as accessing webmail is not possible unless one uses an older version of it that does not require it, c|net member logon not doable without it, even mediafire will not work without it, Avast text reply box is missing the common icons for text and link enhancement, and so on.  Since it is the java plugin from Oracle that is 99% of the problem, have been testing running the browser without javascript and finding it seems to be used in everything everywhere I go.

Do not have java anything installed atm, just so you know.  It is apparent that FF, at least, provides their own version of java in the form of a FF javascript and one still needs that to view normal web content within the browser.  Just experimenting.
You want to get rid of Java not java script. They aren't the same. If you get rid of java script, then you'll find that many things will not work.
In Firefox, use NoScript in Chrome, use FlashControl. both of these browser add-ons give you the option to either allow or not allow the scrip for a page that needs it.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user