Showing posts with label Plugin. Show all posts
Showing posts with label Plugin. Show all posts

Sunday, 1 March 2015

EFF: Install New Computer Ever Again

EFF

If you buy a new computer that must first install all over again, because the software that comes standard is not to be trusted. That secures the American civil rights movement EFF. Following are programs like Superfish and PrivDog who intercepted the SSL traffic of users to inject ads and thus users exposed themselves to all kinds of risks.

This week it was announced that next Superfish, standard on some Lenovo notebooks shipped, other programs intercepting SSL traffic. One of these programs was PrivDog . A vulnerability in certain versions of PrivDog caused the software each certificate which replaced the Internet came and intercepted by a self-signed certificate. Even though it was about certificates that were not valid in the first place.

The Decentralized SSL Observatory of the EFF, which gathers information from the HTTPS Everywhere plugin for Firefox, has collected more than 17,000 different certificates PrivDog users. "Each of these licenses may be an attack. Unfortunately there is no way to know this for sure" says Joseph Bonneau of the Electronic Frontier Foundation (EFF).

"So what have we learned from this Lenovo / Superfish / Komodia / PrivDog debacle? For users, we have learned that the software is pre-installed on your computer can not be trusted, which means that reinstalling a clean operating system standard now procedure must be if someone has bought a new computer, " said Bonneau. The main lesson, he says, for software companies, which must stop intercepting SSL traffic of their users.

Monday, 15 December 2014

'SoakSoak' Malware Infected 100,000+ Wordpress Websites




At over 100,000+ WordPress sites researchers have found malicious code that attempts to infect visitors with malware. The code is loaded from the Russian domain SoakSoak. Google would now more than 11,000 infected websites have put on a blacklist.


Visitors who use Firefox or Chrome receive when visiting these WordPress sites a warning that the site contains malware. According to security firm Sucuri is the number of affected sites much larger and would amount to more than 100,000 WordPress installations. Also on the forum WordPress complain many users SoakSoak on their website.

How the attackers managed to get the malicious code on the WordPress sites is still unknown, but it is suspected that the sites a vulnerable version of the WordPress Slider Revolution use premium plugin. By September WordPress sites with a vulnerable version of the plug-in even though the target of attacks.