“IMWAN for all seasons.”



Post new topic Reply to topic  [ 17 posts ] 
Author Message
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Sep 23, 2014 3:53 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
Sans wrote:

Google Shuts Down Malvertising Attack

(September 22, 2014)
On September 19, Google shut down a malvertising campaign that affected
visitors to several different websites, including Last.fm and The
Jerusalem Post. The questionable ads were being served by the Zedo ad
platform through Google's DoubleClick. The malicious ads were serving
up a downloader known as Zermot.
http://arstechnica.com/security/2014/09 ... -millions/
[Editor's note (Northcutt): Google has worked for years to identify
malware on web sites:
http://static.googleusercontent.com/med ... -2008a.pdf

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Sat Dec 20, 2014 10:34 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
To resurrect an old thread............. (no new threats, just a year end Malware summary from Malwarebytes)

https://blog.malwarebytes.org/malvertis ... -and-zedo/

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Sun Jan 11, 2015 2:30 am 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
It isn't just Google. I recommend Firefox (or Seamonkey) with NO SCRIPT for those on Windoze.

Sans wrote:

--AOL Halts Malware Being Served by its Advertising Platforms
(January 6, 2015)
AOL has stopped its advertising platforms from serving malicious ads
after being alerted to the situation. The malicious ads redirected users
to sites containing exploit kits that attempted to install malware on
their computers. Users could be infected simply by visiting the
malicious sites.
http://www.scmagazine.com/ransomware-is ... le/391235/

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Feb 03, 2015 4:52 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
FYI

Sans wrote:

--Adobe Will Patch Third Flash Vulnerability in Two Weeks
(February 2, 2015)
Adobe has released an advisory about yet another flaw in Flash Player.
This is the third flaw discovered in Flash in less than three weeks.
Adobe plans to have a patch for this most recent vulnerability available
within the next week. This one is being actively exploited through
advertisements.
It affects Flash for Windows systems running Internet
Explorer or Firefox browsers.
http://www.darkreading.com/new-adobe-fl ... id/1318900?
http://www.scmagazine.com/adobe-warns-f ... le/395957/
http://www.theregister.co.uk/2015/02/02 ... other_one/
http://www.v3.co.uk/v3-uk/news/2393223/ ... layer-flaw
http://blog.trendmicro.com/trendlabs-se ... tisements/
[Editor's Note (Murray): Historically broken Flash has now replaced
browsers as the most persistent vulnerability on the desktop. It is no
longer adequate simply to expect consumers to patch it faithfully.
Apple has demonstrated that it is possible, not to mention safer, to
live without it.]

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Feb 03, 2015 8:23 pm 
User avatar
Sonic Death Monkey

Joined: 22 Aug 2004
Posts: 8540
Location: Jet City
Bannings: 6
I wish Flash would just die already...

_________________
My home on the web:
http://www.alger-photography.com


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Feb 03, 2015 11:25 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
ted262 wrote:
I wish Flash would just die already...


I found this comment above interesting, "Apple has demonstrated that it is possible, not to mention safer, to
live without it (Flash)"

Short of uninstalling it, the safest way I know of to deal with it is:

1. Subscribe to a list like SANS for early warning

2. CONSTANTLY patch (there are 3 versions: (1 for I.E. 1 for Firefox, & 1 for all other browsers)

3 Use Firefox ONLY. (I.E. is invisibly called up by many programs though, I don't know how to stop that behavior as the end user doesn't know it's running)

4. Install No Script as a Firefox add on.

5. Set Firefox to always ask before allowing Flash to run (& be aware that some of the You Tube adds are infected).

As far as Flash, that's the extent of my knowledge. Also keep your java current; almost as much of a risk. Both are much bigger risks than XP. If you are using XP, use Fox-it free pdf reader; NOT Adobe.

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 

IMWAN Admin
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Feb 03, 2015 11:35 pm 
User avatar
Helpful Librarian

Joined: Day WAN
Posts: 197040
Location: IMWAN Towers
Bannings: If you're not nice
No YouTube ads are infected. The adspace doesn't hold anything but image and link data. Clicking through a YouTube ad could conceivably lead you to a site that serves malware, but you'd first have to make the decision to click and then deliberately do it.

_________________
Image


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Feb 03, 2015 11:54 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
I'm not saying ICE is unsafe. What the article is saying is GOOGLE is serving adds infected by Malware. Google is not practicing due diligence. And Google Owns You Tube, so controls the add content.

Linda, you might want to post the most recent ABP script you gave me to block the You Tube Adds.

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Wed Feb 04, 2015 12:04 am 
User avatar
Sonic Death Monkey

Joined: 22 Aug 2004
Posts: 8540
Location: Jet City
Bannings: 6
I use ClickToFlash (requires permission to run Flash) and a Youtube extension that forces the page to load HTML5 versions of videos when possible.

_________________
My home on the web:
http://www.alger-photography.com


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Wed Feb 04, 2015 6:41 am 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
Ted, What's the name of the You Tube Extension? What browser is it for?

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 

IMWAN Mod
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Wed Feb 04, 2015 10:40 am 
User avatar
The Modfather; Wizard of WAN

Joined: 05 Oct 2006
Posts: 56213
Location: Under the Iron Bridge
Bannings: freely handed out
Google has recently changed to HTML5 as the default for YouTube. Flash is becoming less and less necessary. That said, this kind of thing is not nearly the cause for concern that Geff's regular postings here might lead you to believe. Just being sensible about what sites you visit and what you click on protects you from 99% of threats out there. Running an adblocker in your browser protects you from 99.999% of the rest, and those handful are not really a cause for concern for the VAST majority of people anyway. Also, I don't see Chrome mentioned up there as being vulnerable, so switching to that might help even more.

I'm not saying that Geff's posts should be discounted entirely; at a minimum, they can raise your awareness and certainly should make one think before clicking on something dodgy. I'm just concerned that some of you might get a little too worried from these posts, and stop visiting the boards. There's nothing to worry about here! :)


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Wed Feb 04, 2015 6:04 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
I really like the new feature in Firefox of disabling Flash until the end user allows it each time. I agree with Jeff that it's rarely necessary. It also really speeds up Amazon pages loading; I don't know what the Flash is doing on both Ebay & Amazon; but my Amazon loading time has been cut in 1/2, & browser freeze ups (my main pc is a quad at 2.4 ghz which is a bit slow these days), have been cut way back also.

Another comment I found interesting from the last Sans post above, "Historically broken Flash has now replaced
browsers as the most persistent vulnerability on the desktop."

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Thu Feb 05, 2015 8:32 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
FYI: Flash patch #3 referred to above is out. It may NOT get delivered automatically for several days. If you wish to get it immediately, go here:

http://www.adobe.com/products/flashplay ... tion3.html

These are the full versions, not the installer stubs that sometimes freeze during download.

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Sep 08, 2015 3:02 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
This specific article does not relate to Google or You Tube, but it is relevant in the bigger picture. There is a real problem with this issue.

SANS wrote:
--Malicious Ads on Yahoo are Pushing Angler Exploit Kit
(September 7, 2015)
Researchers at Malwarebytes say that miscreants are distributing malware
through advertisements on Yahoo. They are tricking automated ad delivery
systems into displaying ads that contain embedded malware. This
particular attack attempts to load the Angler Exploit Kit onto users'
computers. Yahoo has taken steps to stop the malvertising.
http://www.scmagazine.com/hackers-sprea ... le/437075/
[Editor's Note (Northcutt): Wired magazine has a great non-technical
overview of malvertising, including how it can be precisely targeted.
Malwarebytes, who apparently discovered the Yahoo problem, posted an
article on how the attack works and also the scope of the problem.
Regardless, this is clearly Malvertising month, you can add
match.com/POF and MSN to the list. If you work for an organization that
earns revenue by displaying ads supplied by 3rd parties, you may want
to look into safe frame:
http://www.wired.com/insights/2014/11/m ... weet-spot/

https://blog.malwarebytes.org/malvertis ... -on-yahoo/

https://blog.malwarebytes.org/malvertis ... tchdotcom/

https://blog.malwarebytes.org/malvertis ... -campaign/
http://www.iab.net/safeframe ]

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 

ICE Mod
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Sep 08, 2015 3:47 pm 
User avatar
Yes...my real name is Steve..REALLY! ;)

Joined: 20 Sep 2006
Posts: 9669
Location: Boston Area, MA
Bannings: Living on the edge.
I love Malwarebytes and won't have a PC without it. I'm glad they're on this.

_________________
F.A.S.T. Stroke Signs

F = Face drooping - Look for an uneven smile
A = Arm Weakness - Is one arm weak? - Can you lift both arms?
S = Speech Difficulty - Listen for slurred speech - Do people understand your speech?
T = Time is brain! - Call 9-1-1


Brain Rebuilding 05/13/2017


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Sep 08, 2015 3:52 pm 
User avatar
I love Music & hate brickwalled audio

Joined: 27 Sep 2006
Posts: 37646
Location: The Pasture
I use MBAM & MBAE on all my machines.

_________________
Putty Cats are God's gift to the universe.


Top
  Profile  
 
 Post subject: Maybe I Wasn't So Paranoid After All..........
PostPosted: Tue Sep 08, 2015 4:01 pm 
User avatar

Joined: 09 Aug 2004
Posts: 5574
Walter P wrote:
I love Malwarebytes and won't have a PC without it. I'm glad they're on this.


hmmmm...


Top
  Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 17 posts ]   



Who is WANline

Users browsing this forum: Google [Bot] and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  


Powdered by phpBB® Forum Software © phpBB Limited

IMWAN is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide
a means for sites to earn advertising fees by advertising and linking to amazon.com, amazon.ca and amazon.co.uk.