Technology Get the latest on technology, electronics and software…

The Official Internet/Computer Security News Discussion Thread

Thread Tools
 
Old 10-19-2010, 01:03 PM
  #1  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
The Official Internet/Computer Security News Discussion Thread

I've been meaning to make this thread for a while. I'd like this to be where we can discuss the latest trends in malware, phishing attacks, social engineering attacks, etc. Also things to look out for, how to configure your computer to enhance security and where people can come and get help if they need it.
Old 10-19-2010, 01:15 PM
  #2  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
First up, MS found that Java exploits are greatly on the rise!



<div> <table style="display: inline; border-collapse: collapse; font-size: 1em" border="1" cellspacing="2" cellpadding="2" width="532"><tbody> <tr> <td style="vertical-align: top" class="ms-rtetablecells" width="64"> <div><strong>CVE</strong></div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="54"> <div align="right"><strong>Attacks</strong></div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="67"> <div align="right"><strong>Computers</strong></div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="335"> <div><strong>Description</strong></div> </td> </tr> <tr> <td style="vertical-align: top" class="ms-rtetablecells" width="64"> <div>CVE-2008-5353</div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="58"> <div align="right">3,560,669</div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="71"> <div align="right">1,196,480</div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="328"> <div>A deserialization issue in vulnerable versions of JRE (Java Runtime Environment) allows remote code execution through Java-enabled browsers on multiple platforms, such as Microsoft Windows, Linux, and Apple Mac OS X.</div> </td> </tr> <tr> <td style="vertical-align: top" class="ms-rtetablecells" width="63"> <div>CVE-2009-3867</div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="62"> <p align="right">2,638,311</p> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="75"> <div align="right">1,119,191</div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="323"> <div>Another remote code execution, multi-platform issue caused by improper parsing of long file:// URL arguments.</div> </td> </tr> <tr> <td style="vertical-align: top" class="ms-rtetablecells" width="62"> <div>CVE-2010-0094</div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="65"> <p align="right">213,502</p> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="78"> <div align="right">173,123</div> </td> <td style="vertical-align: top" class="ms-rtetablecells" width="319"> <div>Another deserialization issue, very similar to CVE-2008-5353.</div> </td> </tr> </tbody></table> </div>
Which if I borrow from Alex2364 here's a screenshot of MSE on his PC



Now luckily of you've been updating your Java you're ok cause these have all been patched

I was on my brother's PC a couple days ago and saw some of the similar exploits, I'm not sure if they were successful or not cause they were in protected mode but I don't think he'd updated his Java in a while.

Just a reminder to update your third party software (flash, java, reader) cause it's now become the main point of attack instead of Windows.

I recommending going to www.ninite.com clicking on java, flash and reader and letting it update it for you.

http://blogs.technet.com/b/mmpc/arch...-the-java.aspx

Last edited by #1 STUNNA; 10-19-2010 at 01:21 PM.
Old 10-19-2010, 01:53 PM
  #3  
Suzuka Master
iTrader: (4)
 
EL19's Avatar
 
Join Date: Nov 2006
Location: DC
Age: 37
Posts: 5,340
Received 193 Likes on 150 Posts
good info!
Old 10-19-2010, 01:53 PM
  #4  
Senior Moderator
 
Yumcha's Avatar
 
Join Date: Dec 2001
Posts: 167,238
Received 22,653 Likes on 13,892 Posts
Good thread, Stunna...
Old 10-19-2010, 01:56 PM
  #5  
Go Giants
 
Whiskers's Avatar
 
Join Date: Aug 2004
Location: PA
Age: 52
Posts: 69,901
Received 1,231 Likes on 821 Posts
Been hearing good things about Avast Free.
Old 10-19-2010, 02:09 PM
  #6  
Needs more Lemon Pledge
 
stogie1020's Avatar
 
Join Date: Mar 2005
Location: Phoenix, AZ
Age: 51
Posts: 52,768
Received 2,000 Likes on 1,173 Posts
Old 10-19-2010, 02:17 PM
  #7  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
now for a little advice on how to configure Adobe Reader. Reader like most adobe software is riddled with security holes and they've been getting their ass handed to them as of late on the security front. There are some a couple settings you can change that will help this though.

If you open reader and go to preferences (ctrl + k) and
1. click on "Javascript" and turn off javascript.
2. Then go to "Trust Manager" and turn off "Allow opening of non-pdf file attachments with external applications"

Now if you're wondering if you should've had a holy shit WTF moment while reading the last two the answer is yes. By default reader allows javascript aka the java exploits I mentioned above to be run via PDF! As are external applications, so you open a PDF and it runs a malicous exe! WTF! Why does reader need to run java or external applications!?!?

I turned these off a few months ago and I'm glad that I did. Recently I was browsing a shady site and I moused over or accidentally clicked on a flash banner and bam! Reader opens up real fast with a blank PDF and this PDF wants to run Javascript! Luckily I had turned Java off for PDFs and so Reader was waiting for me to approve this PDF to run Java which I of course declined. Then the same thing happened a few days later. I wonder if I had java turned on would that blank empty PDF have even opened or would it have just done it's exploit in the background.

As for downsides, I've yet to see a legit PDF prompt me to run Javascript or open an external application. So please do yourself the favor and turn those settings off.
Old 10-19-2010, 02:20 PM
  #8  
Three Wheelin'
 
alex2364's Avatar
 
Join Date: Oct 2000
Location: Northern VA
Posts: 1,666
Received 63 Likes on 37 Posts
I feel so special now.
Old 10-19-2010, 02:24 PM
  #9  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
It might be a good idea for you guy to clean out your java cache since apparently CCleaner doesn't clean that.

you can clean your java cache by in Vasta/7 just do a seach for "Java" click on the java control panel, click settins for Temp internet files and then choose delete. For XP click control panel and then choose the java control panel the rest of the steps are the same.
Old 10-19-2010, 02:25 PM
  #10  
5o9
'05 TSX 6MT
 
5o9's Avatar
 
Join Date: Mar 2006
Posts: 623
Likes: 0
Received 0 Likes on 0 Posts
^ Thanks

I could not find a javascript option
Old 10-19-2010, 02:25 PM
  #11  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
Originally Posted by alex2364
I feel so special now.
yes, you're special! You're 1 out of 6 million that MSE has detected in the past few months. You can add Mizouse and my brother to the list too.
Old 10-19-2010, 02:44 PM
  #12  
Three Wheelin'
 
alex2364's Avatar
 
Join Date: Oct 2000
Location: Northern VA
Posts: 1,666
Received 63 Likes on 37 Posts
Because of this thread, I did a full scan on my computer and it found an "Exploit:Java/CVE-2009-3867.LM". I wonder where I'm getting all these things from.
Old 10-19-2010, 02:57 PM
  #13  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
You shouldn't have to worry about those because the whole is patched. You have the malicous file but it can't execute cause it doesn't work.

Just like I can have the files for Conficker on my PC but it can't do shit cause Windows 7 isn't vulnerable to it.

But yeah some shady site is trying to fuck up your world
Old 10-19-2010, 03:11 PM
  #14  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,330
Received 2,049 Likes on 1,135 Posts
You could just buy a mac and skip this thread.
Old 10-19-2010, 03:18 PM
  #15  
Team Owner
 
TS_eXpeed's Avatar
 
Join Date: Jun 2007
Posts: 23,451
Received 54 Likes on 27 Posts

Oh noes! An 'official' thread not started by a mod.

Originally Posted by doopstr
You could just buy a mac and skip this thread.
Old 10-19-2010, 03:22 PM
  #16  
Go Giants
 
Whiskers's Avatar
 
Join Date: Aug 2004
Location: PA
Age: 52
Posts: 69,901
Received 1,231 Likes on 821 Posts
Originally Posted by doopstr
You could just buy a mac and skip this thread.
Old 10-19-2010, 03:27 PM
  #17  
Az User
 
03SSMTL-S's Avatar
 
Join Date: Feb 2005
Location: parts unknown
Age: 45
Posts: 12,488
Received 2,486 Likes on 1,645 Posts
http://www.bleepingcomputer.com/comb...o-use-combofix

COMBOFIX FTW

love this program used it so many times and fixed so many computers
Old 10-19-2010, 03:31 PM
  #18  
Team Owner
 
svtmike's Avatar
 
Join Date: Oct 2003
Location: Chicago
Age: 59
Posts: 37,663
Received 3,863 Likes on 2,030 Posts
Originally Posted by TS_eXpeed

Oh noes! An 'official' thread not started by a mod.
My thoughts exactly. I recommend renaming him to #1 Doucher again though instead of ban-hammering.
Old 10-19-2010, 03:36 PM
  #19  
nnInn
 
jupitersolo's Avatar
 
Join Date: Mar 2006
Posts: 37,670
Received 1,084 Likes on 646 Posts
IIRC it didn't have the "official" in the title when the thread started.
Old 10-19-2010, 03:40 PM
  #20  
Needs more Lemon Pledge
 
stogie1020's Avatar
 
Join Date: Mar 2005
Location: Phoenix, AZ
Age: 51
Posts: 52,768
Received 2,000 Likes on 1,173 Posts
Originally Posted by jupitersolo
IIRC it didn't have the "official" in the title when the thread started.
SHHHHHHhhhhhh!
Old 10-19-2010, 03:46 PM
  #21  
Team Owner
 
svtmike's Avatar
 
Join Date: Oct 2003
Location: Chicago
Age: 59
Posts: 37,663
Received 3,863 Likes on 2,030 Posts
Originally Posted by jupitersolo
IIRC it didn't have the "official" in the title when the thread started.
Old 10-19-2010, 03:47 PM
  #22  
1919
 
Scottman111's Avatar
 
Join Date: Mar 2005
Age: 38
Posts: 21,467
Likes: 0
Received 162 Likes on 134 Posts
Originally Posted by 03SSMTL-S
http://www.bleepingcomputer.com/comb...o-use-combofix

COMBOFIX FTW

love this program used it so many times and fixed so many computers



I've rarely found anything that it couldn't fix, even though sometimes it involved some tweaking.

And always download a new copy when you use it, and only from that link!
Old 10-19-2010, 04:01 PM
  #23  
nnInn
 
jupitersolo's Avatar
 
Join Date: Mar 2006
Posts: 37,670
Received 1,084 Likes on 646 Posts
Originally Posted by stogie1020
SHHHHHHhhhhhh!
Originally Posted by svtmike
Just gotta say he's not THAT stupid.
Old 10-19-2010, 04:04 PM
  #24  
Senior Moderator
 
Ken1997TL's Avatar
 
Join Date: May 2003
Location: Better Neighborhood, Arizona
Posts: 45,634
Received 2,328 Likes on 1,308 Posts
Originally Posted by doopstr
You could just buy a mac and skip this thread.
A deserialization issue in vulnerable versions of JRE (Java Runtime Environment) allows remote code execution through Java-enabled browsers on multiple platforms, such as Microsoft Windows, Linux, and Apple Mac OS X.
Fail..
Old 10-19-2010, 06:12 PM
  #25  
Suzuka Master
 
mcflyguy24's Avatar
 
Join Date: Feb 2007
Location: Oreland, Pa
Age: 41
Posts: 5,846
Received 24 Likes on 20 Posts
Thank you for this thread. I went and turned off all the java shit in reader and had no idea that was how reader was able to get pdf exploits until this. What do you think is better to use AVG free or MSE for security? I don't wanna pay money cos I haven't had any issues with good free anti-virus software lately.
Old 10-19-2010, 06:13 PM
  #26  
Senior Moderator
 
Ken1997TL's Avatar
 
Join Date: May 2003
Location: Better Neighborhood, Arizona
Posts: 45,634
Received 2,328 Likes on 1,308 Posts
Microsoft Security Essentials doesn't noticeably slow down my machine and occasionally picks something up. I browse safe and sane websites though, so your mileage may vary.
Old 10-19-2010, 07:00 PM
  #27  
Team Owner
 
svtmike's Avatar
 
Join Date: Oct 2003
Location: Chicago
Age: 59
Posts: 37,663
Received 3,863 Likes on 2,030 Posts
I use MSE on all of my home computers as well. It's been solid except on my son's XP machine where he managed to contract a virus (he doesn't do a good job of keeping it up to date). It was a quick/easy repair once I killed the infection and updated MSE.
Old 10-20-2010, 12:55 AM
  #28  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
MSE

And my title didn't originally have the word official in it, yumcha edited the title.

Also yeah the thing with these exploits in 3rd party software is that they're usually cross platform so don't get all high and mighty
Old 10-20-2010, 01:07 AM
  #29  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
Since I've been on this forum I think I've given pretty much all the tips I've got right now for securing your Computer. Let's review shall we.

1. Block 3rd party cookies which are usually for tracking you and sending you junk mail. This is done in your browsers cookie/content/privacy options. I've noticed in the past few months that I don't get junk email anymore, IDK if it's cause Hotmail really stepped it's game up or what but I haven't seen any unsolicited junk hit my inbox in months and I kinda like it.

2. Install MVPS HOSTS File, it blocks ad servers and known servers that serve malware. This leads to a safer, less annoying and faster internet experience. I put a shortcut too rename the HOSTS file on their desktop and have them use it if the encounter a site that causes an issue, which isn't very often. www.mvps.org/winhelp2002/hosts.htm http://www.mvps.org/winhelp2002/hostsfaq.htm#Rename

3. Go to www.ninite.com and install updates for your software, update them when they tell you too.

4. Run MSE, it's the best free AV I've used. Nothings perfect but I don't really have any complaints about it. www.microsoft.com/security_essentials

5. Use Google Chrome, it's sandboxed browser adds another layer of protection, the sandbox even works in XP so it's definite improvement over any of the competitors not to mention speed and UI. www.google.com/chrome

6. Disable Javascript and prevent PDFs from opening executable files in Adobe Reader. Even if you use Foxit reader or any other 3rd party reader you're still vulnerable to an exe exploit. https://acurazine.com/forums/showpos...20&postcount=7

That's pretty much all the changes I make on a computer to secure it. I've done this on a bunch of computers and I've yet to be called back for a malware infection. I'm not saying it's bulletproof I'm just speaking from my experience so far.

Last edited by #1 STUNNA; 10-20-2010 at 01:14 AM.
Old 10-20-2010, 07:46 AM
  #30  
Go Giants
 
Whiskers's Avatar
 
Join Date: Aug 2004
Location: PA
Age: 52
Posts: 69,901
Received 1,231 Likes on 821 Posts
I make $65 for every virus I clean out....So stop it.
Old 10-20-2010, 08:51 AM
  #31  
Drifting
iTrader: (1)
 
rza49311's Avatar
 
Join Date: Feb 2006
Location: Southern VA
Age: 45
Posts: 3,072
Received 8 Likes on 6 Posts
Originally Posted by #1 STUNNA
Since I've been on this forum I think I've given pretty much all the tips I've got right now for securing your Computer. Let's review shall we.
8. Use common sense(think before you click)...Often overlooked and doesn't require a download or update
Old 10-20-2010, 08:54 AM
  #32  
Unofficial Goat
iTrader: (1)
 
The Dougler's Avatar
 
Join Date: Jul 2006
Location: Toronto
Age: 39
Posts: 15,744
Received 112 Likes on 89 Posts
Thoughts about including other random helpful utilities in this thread or do they warrant their own thread?
Old 10-20-2010, 09:31 AM
  #33  
nnInn
 
jupitersolo's Avatar
 
Join Date: Mar 2006
Posts: 37,670
Received 1,084 Likes on 646 Posts
Originally Posted by rza49311
8. Use common sense(think before you click)...Often overlooked and doesn't require a download or update
99% of the time, the head w/o brains is surfing...
Old 10-20-2010, 10:37 AM
  #34  
1919
 
Scottman111's Avatar
 
Join Date: Mar 2005
Age: 38
Posts: 21,467
Likes: 0
Received 162 Likes on 134 Posts
Originally Posted by rza49311
8. Use common sense(think before you click)...Often overlooked and doesn't require a download or update
Wouldn't that be nice. Seems like a lot of people using their work computers care even less. I really don't know how a company can survive without a web filter.
Old 10-20-2010, 11:01 AM
  #35  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 43,382
Received 10,120 Likes on 6,108 Posts
Originally Posted by Whiskers
I make $65 for every virus I clean out....So stop it.
isn't it fucked up when you have to go back to client 3 or 4 times!? I have this client who just kept getting viruses, every few months I'd be back over fixing it. Eventually her PC died so I had to rebuild it, I put her on Windows 7, installed MSE and the HOSTS file and I haven't had to go over there for malware since. But there's lots of other fish in the sea.

Originally Posted by rza49311
8. Use common sense(think before you click)...Often overlooked and doesn't require a download or update
I tell people this but I can't enforce it.

Originally Posted by The Dougler
Thoughts about including other random helpful utilities in this thread or do they warrant their own thread?
https://acurazine.com/forums/technology-16/software-tip-week-740534/
Originally Posted by jupitersolo
99% of the time, the head w/o brains is surfing...
Old 10-20-2010, 11:13 AM
  #36  
Drifting
iTrader: (1)
 
rza49311's Avatar
 
Join Date: Feb 2006
Location: Southern VA
Age: 45
Posts: 3,072
Received 8 Likes on 6 Posts
Originally Posted by rza49311
8. Use common sense(think before you click)...Often overlooked and doesn't require a download or update
Originally Posted by jupitersolo
99% of the time, the head w/o brains is surfing...
Originally Posted by Scottman111
Wouldn't that be nice. Seems like a lot of people using their work computers care even less. I really don't know how a company can survive without a web filter.
Originally Posted by #1 STUNNA

I tell people this but I can't enforce it.
:
I think the most annoying one is email. I get calls from people "i'm not sure if this is legit or not" after I shown them 100 times how to hover over to see the links :sniper:
Old 10-20-2010, 11:14 AM
  #37  
Drifting
iTrader: (1)
 
rza49311's Avatar
 
Join Date: Feb 2006
Location: Southern VA
Age: 45
Posts: 3,072
Received 8 Likes on 6 Posts
Originally Posted by rza49311
8. Use common sense(think before you click)...Often overlooked and doesn't require a download or update
Originally Posted by jupitersolo
99% of the time, the head w/o brains is surfing...
Originally Posted by Scottman111
Wouldn't that be nice. Seems like a lot of people using their work computers care even less. I really don't know how a company can survive without a web filter.
Originally Posted by #1 STUNNA

I tell people this but I can't enforce it.
:
I think the most annoying one is email. I get calls from people "i'm not sure if this is legit or not" after I shown them 100 times how to hover over to see the links
Old 10-20-2010, 08:03 PM
  #38  
My Member is Registered
 
Cruz_msl's Avatar
 
Join Date: Oct 2003
Location: 2678.51 miles east of California
Posts: 3,545
Received 2 Likes on 2 Posts
Great thread Stunna, thanks
Old 10-20-2010, 08:21 PM
  #39  
Moderator
iTrader: (1)
 
justnspace's Avatar
 
Join Date: Feb 2010
Posts: 86,295
Received 16,260 Likes on 11,971 Posts
Thanks.

*edit

MSE for 64bit win7??
hurry im unprotected.

nvm I dled from ninite

Last edited by justnspace; 10-20-2010 at 08:34 PM.
Old 10-20-2010, 09:04 PM
  #40  
Turd Polisher
iTrader: (1)
 
TylerT's Avatar
 
Join Date: Jul 2007
Location: San Diego
Age: 35
Posts: 6,802
Received 3,006 Likes on 1,514 Posts
^ Ninite is awesome, we use it on our deployments .

All great info in this thread, MSE is a great program.


Quick Reply: The Official Internet/Computer Security News Discussion Thread



All times are GMT -5. The time now is 05:38 PM.