Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904700 times)

0 Members and 10 Guests are viewing this topic.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2715 on: September 21, 2013, 10:31:37 AM »
Update on IE use-after-free vulnerability

Tech blog Microsoft Security Response Center announces new Fix-it and out-of-band release Windows Update patch for all versions of IE:  http://blogs.technet.com/b/msrc/archive/2012/09/19/internet-explorer-fix-it-available-now-security-update-scheduled-for-friday.aspx
« Last Edit: September 21, 2013, 10:36:42 AM by mchain »
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48595
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2718 on: September 25, 2013, 01:43:56 AM »
More information about IE, all versions, exploits, attacks:

http://www.pcadvisor.co.uk/news/security/3470426/internet-explorer-zero-day-attackers-linked-to-bit9-hackers/

Some published reports state that this attack team uses a weaponized version and so far has been used to attack only enterprise/commercial users using IE 8 and IE 9.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2719 on: September 25, 2013, 02:57:16 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2720 on: September 25, 2013, 09:15:50 PM »
Starting next year: https://cabforum.org/pipermail/public/2013-September/002233.html
Google Weaker SSL-Certificate alerts
This also seen to these developments: http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security
Also Bruce Schneier warned about these issues leaving everyone less secure.
In the meantime I check with Calomel SSL Validation in firefox: https://addons.mozilla.org/En-us/firefox/addon/calomel-ssl-validation/

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2721 on: September 25, 2013, 09:18:47 PM »
So Google is going to implement their own certificate verification system like in Firefox. ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2722 on: September 25, 2013, 09:57:00 PM »
Hi Steven Winderlich,

Seems so,

Well I like a check like this example from DigiCert® SSL Installation Diagnostics Tool:
DNS resolves 'www.security.nl' to 213.156.0.246
HTTP Server Header: Apache

SSL certificate
Common Name = www.security.nl

Subject Alternative Names = www.security.nl

Issuer = Thawte DV SSL CA

Or Why no padlock?
Domain Name: www.security.nl
URL Tested: https://www.security.nl
Number of items downloaded on page: 24
   Valid Certificate found.
   Certificate valid through: Dec 13 23:59:59 2013 GMT
Certificate Issuer: Thawte, Inc.
   All 24 items called securely!

Serial Number = 67ED771B1120A17564A4685737F1D84A

SHA1 Thumbprint = 3C6925620CBFBE09098886F4306F32DE0A363E29

Key Length = 2048 bit

Signature algorithm = SHA1 + RSA (good)

Secure Renegotiation: Supported

SSL ciphers supported by the server
TLS_RSA_WITH_RC4_128_MD5

TLS_RSA_WITH_RC4_128_SHA

TLS_RSA_WITH_3DES_EDE_CBC_SHA

TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA

TLS_RSA_WITH_AES_128_CBC_SHA

TLS_DHE_RSA_WITH_AES_128_CBC_SHA

TLS_RSA_WITH_AES_256_CBC_SHA

TLS_DHE_RSA_WITH_AES_256_CBC_SHA

TLS_RSA_WITH_AES_128_CBC_SHA256

TLS_RSA_WITH_AES_256_CBC_SHA256

TLS_RSA_WITH_CAMELLIA_128_CBC_SHA

TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA

TLS_DHE_RSA_WITH_AES_128_CBC_SHA256

TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

TLS_RSA_WITH_CAMELLIA_256_CBC_SHA

TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA

TLS_RSA_WITH_SEED_CBC_SHA

TLS_DHE_RSA_WITH_SEED_CBC_SHA

TLS_RSA_WITH_AES_128_GCM_SHA256

TLS_RSA_WITH_AES_256_GCM_SHA384

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

This certificate does not use a vulnerable Debian key (this is good)
SSL Certificate expiration
The certificate expires December 13, 2013 (78 days from today)

Certificate Name matches www.security.nl
 
Subject www.security.nl
Valid from 13/Dec/2012 to 13/Dec/2013 
Issuer Thawte DV SSL CA
   
 
Subject Thawte DV SSL CA
Valid from 18/Feb/2010 to 17/Feb/2020 
Issuer thawte Primary Root CA
   
 
Subject thawte Primary Root CA
Valid from 17/Nov/2006 to 30/Dec/2020 
Issuer Thawte Premium Server CA

SSL Certificate is correctly installed

or this examplke  from Why No Padlock?
Domain Name: www.security.nl
URL Tested: https://www.security.nl
Number of items downloaded on page: 24
   Valid Certificate found.
   Certificate valid through: Dec 13 23:59:59 2013 GMT
Certificate Issuer: Thawte, Inc.
   All 24 items called securely!

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2724 on: October 02, 2013, 12:11:01 AM »
Unpatched IE-hole abused in cyber-espionage: http://www.fireeye.com/blog/technical/cyber-exploits/2013/09/hand-me-downs-exploit-and-infrastructure-reuse-among-apt-campaigns.html      link article authors  Ned Moran and Nart Villeneuve
A MS-Fix-it is available, but no patch has been issues yet,

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2725 on: October 04, 2013, 09:51:49 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2726 on: October 04, 2013, 12:24:12 PM »
Hi Asyn,

And this as a reaction on this data breach: http://krebsonsecurity.com/2013/10/adobe-to-announce-source-code-customer-data-breach/
What gonna be the implications?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2728 on: October 04, 2013, 01:23:57 PM »
Microsoft Security Bulletin Advance Notification for October 2013
http://technet.microsoft.com/en-us/security/bulletin/ms13-oct
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2729 on: October 04, 2013, 06:36:54 PM »
Hi Asyn,

Thanks for that article link.
Others here could google translate that articlke txt  into UK English or American English.

Couldn't we or shouldn't we further advise users to at least use another reader,
 like for instance FoxIt for the time being until the security position of Adobe's been clarified.
Users should also explicitly allow the use of these readers in the browser
as is the rule with a lot of browsers now.
They should rfeally pre-scan document links or re-check these particular software executables and update uri's for malcode.
Through these latest hacks Adobe has manoevered itself into the ranks of Java and likewise security-problematic codes.

polonus
« Last Edit: October 04, 2013, 06:39:02 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!