Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904709 times)

0 Members and 6 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2460 on: March 25, 2013, 05:57:11 PM »
Hi SpeedyPC,

You know my position - avast! is a "darned" good product and it is getting better every day...
and well bob3160 seems to have converted quite a contingent of fine users in the States to make that final switch to the avast! av solution..

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2461 on: March 25, 2013, 06:02:46 PM »
Are zero days taken seriously? Re: http://www.zerodayinitiative.com/advisories/upcoming/  (reported by DVLabs)
The end of upcoming Java zero days is not in sight...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2462 on: March 25, 2013, 06:22:38 PM »
Are zero days taken seriously? Re: http://www.zerodayinitiative.com/advisories/upcoming/  (reported by DVLabs)
The end of upcoming Java zero days is not in sight...

polonus
Zero Day is another reason why in my opinion, the new feature in avast! to keep your program up-to date
is a good idea. If used properly, new updates which patched a recent exploit will get updated on the users
computer. Even in the free  version of avast!
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2463 on: March 25, 2013, 08:36:26 PM »
Are zero days taken seriously? Re: http://www.zerodayinitiative.com/advisories/upcoming/  (reported by DVLabs)
The end of upcoming Java zero days is not in sight...

polonus
Sandbox will be an answer, wouldn't it?
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2464 on: March 25, 2013, 09:51:31 PM »
Hi Tech,

Good suggestion i.m.h.o.,

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2465 on: March 25, 2013, 10:09:54 PM »
Are zero days taken seriously? Re: http://www.zerodayinitiative.com/advisories/upcoming/  (reported by DVLabs)
The end of upcoming Java zero days is not in sight...

polonus
Sandbox will be an answer, wouldn't it?
Absolutely correct.  Any malware downloaded to your system will remain inside the sandbox where it can do no harm.  Once the sandbox is deleted, all contents within vanish, and the threat(s) is/are removed.  Some malware will not run within a sandbox if it detects it is inside one, so one will get additional protection from that as well. 

Tracking cookies vanish too when the sandbox is deleted.

If java jre is not needed, best to uninstall it from your system.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2466 on: March 25, 2013, 10:11:02 PM »
If java jre is not needed, best to uninstall it from your system.
We need it for online banking in my country :'(
The best things in life are free.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2467 on: March 25, 2013, 10:26:40 PM »
If java jre is not needed, best to uninstall it from your system.
We need it for online banking in my country :'(
**Sigh**

Problem is, most users of computer systems are not advanced/expert users and thus not really aware of the dangers of using such sites.  Until Oracle fixes all zero-days, or introduces a new cross-platform jre variant specifically for banker use, then the task of maintaining one's own IT support can be daunting at best, and victimize innocent users at worst.  Convenience does not outweigh security in this case.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2468 on: March 25, 2013, 11:32:26 PM »
@Tech,

At least you could always update to the latest java version. Pre-scan links where you wanna go to avoid java based exploits (kits) landing sites.
Use NoScript and RequestPolicy extensions in the firefox browser to prevent malscripts from running and third party requests being met.
Have the avast shields up and running. Only enable java in the browser when you need it, else do not allow it...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2469 on: March 26, 2013, 04:25:39 AM »
If java jre is not needed, best to uninstall it from your system.
We need it for online banking in my country :'(

Me too Tech :'( :'( you're not alone buddy and you still have to keep an eye out what you're doing with online banking so you don't get robbed :o
« Last Edit: March 26, 2013, 06:49:13 AM by SpeedyPC »
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2471 on: March 28, 2013, 10:31:34 AM »
Very hot phishing attack on Facebook users originally posted by Carol @ c|net Spyware, viruses, & security forum: NEWS - March 26, 2013.

Direct link to article report:  http://www.scambook.com/blog/2013/03/facebook-security-alert-www-wasvideo-com-hacks-your-account-spams-your-friends/

Urlquery report:  http://urlquery.net/report.php?id=1653452  Note the source origination point and screenshot of website.  Screenshot of website is identical to the https Facebook version.
Urlvoid report:  http://www.urlvoid.com/scan/fizikubook.com/
Sucuri report:  http://sitecheck.sucuri.net/results/www.fizikubook.com/indexv2.php
VirusTotal url scan report:  https://www.virustotal.com/en/url/cb2a916e6d5f226ce65a22e56266248d8fe03592c104d11c83caefe784cbc49b/analysis/1364462131/
zulu zscaler report:  Not available as this site is currently number 45 in queue.

Firefox does block this site as a reported web forgery.

Under no circumstance visit this hxxp://www.fizubook.com directly.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2472 on: March 29, 2013, 03:16:54 PM »
Let us hope malcreants do not find out about this spamming technique abuse of Google services in combination with an URL/shortener....
: https://www.barracuda.com//blogs/labsblog?bid=3130 )article author ° Dave Michmerhuizen'
Do not use them, check links to click (for security reasons) Give in shortened links at a url-expander like
http://longurl.org/ or http://www.clybs.com/urlexpander

polonus
« Last Edit: March 29, 2013, 03:20:54 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2473 on: March 29, 2013, 04:00:01 PM »
Let us hope malcreants do not find out about this spamming technique abuse of Google services in combination with an URL/shortener....
: https://www.barracuda.com//blogs/labsblog?bid=3130 )article author ° Dave Michmerhuizen'
Do not use them, check links to click (for security reasons) Give in shortened links at a url-expander like
http://longurl.org/ or http://www.clybs.com/urlexpander

polonus
This doesn't have anything to do with URL shortening but links embedded in translated websites. :)
I use https://goo.gl  a lot of times.
Here is just one of them:
http://goo.gl/VLXde
Certainly not dangerous. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89131
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2474 on: March 29, 2013, 04:34:37 PM »
@ Bob
What is dangerous is the fact that the user has no way of identifying where the link leads to without clicking on the link. So there is an element of blind trust when using URL shortening methods.

I already use Long URL Mobile Expander add-on in FF, but it doesn't cover all or goo.gl being one such instance.

@ polonus
The 2nd link urlexpander, isn't as convenient as the Long URL Mobile Expander add-on as it appears to be on-line only - there is also a problem on the site any shortened url entered results in an application error. So not very good.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security