CVE-2016-6287

The “http-client” egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied “Proxy” header could allow an attacker to direct all HTTP requests through a proxy (also known as a “httpoxy” attack). This affects all versions of http-client before 0.10.

CVE-2016-6830

The “process-execute” and “process-spawn” procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call. This would allow user-supplied argument/environment variable lists to trigger a buffer overrun. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).

Goodbye! Yahoo to rename itself 'Altaba' after Verizon Deal

It’s time to say goodbye to Yahoo!

While Yahoo’s core internet business was being sold to Verizon for $4.8 Billion, the remaining portions of the company left behind is renaming itself to Altaba Inc, which marks the sad ending of one of the most familiar brand names on the internet.

In a public filing with the Securities and Exchange Commission (SEC) on Monday, the company announced that

AVG Launches Powerful New Security and Tune-up Products for 2017

Avast & AVG Technologies combine together to power the latest in flagship security and tune-up products to tackle ransomware, hackers and data thieves, while keeping PCs fast and clean.

 

Prague, Czech Republic, January 10, 2017 – Avast Software, the leader in digital security products for consumers and businesses, today announced the release of the 2017 editions of AVG’s flagship products, AVG AntiVirus FREE, AVG Internet Security and AVG TuneUp. Released less than 120 days after Avast’s acquisition of AVG, these new products combine the best of both Avast’s and AVG’s technology to deliver unrivalled, family-friendly, security protection together with performance enhancements for customers’ PCs, and a clean, simple look and feel.

People using the AVG AntiVirus FREE and AVG Internet Security products will now gain real-time protection against ‘zero-second’ malware thanks to CyberCapture, the company’s proprietary, cloud-based smart file scanner. The latest versions protect users from viruses and malware including ransomware, prevent hacking, secure web and email activities, and ensure that private data stays private. The new user interface makes it very easy to install, navigate and manage all from one place.

A free performance scan using AVG TuneUp has been integrated into the security products to help customers reduce data clutter and keep their PC running smoothly. The full AVG TuneUp product is enhanced with a completely new Software Updater tool which automatically checks and installs the latest updates for the most popular and critical PC applications to eliminate vulnerabilities, fix bugs and add new features.

  • AVG AntiVirus FREE: the rapid increase in the quantity and impact of cyber threats today means protecting every PC is more important than ever before, and free users now benefit from:
    • Computer Protection: real-time protection that updates people’s security automatically and keeps their computers free of viruses, spyware, ransomware, rootkits, Trojans, and other nasty malware. Using advanced artificial intelligence and real-time analysis, it stops even the newest threats from reaching users.
    • Web & Email Protection: blocks unsafe links, downloads, and email attachments.
    • Pushed Priority Updates: ensures immediate protection and was previously only available in the paid edition.
    • New Passive Mode: allows people to personalize their security by allowing them to run two protection products together on their PC.
    • New Online Shield: scans for dangerous websites, links and downloads to keep users safe while they visit their favorite websites.

 

  • AVG Internet Security: for ironclad protection, users can upgrade to AVG Internet Security which additionally stops hackers, protects private data and secures payments.
    • Hacker Protection: Prevents cybercriminals from accessing users’ private files, photos, and passwords.
    • Private Data Protection: Allows users to encrypt and hide their most private photos and files, or permanently shred unwanted material.
    • Payment Protection: Ideal for browsing, shopping, or bank protection. It blocks spam and scams, and helps people avoid fake copycat websites to prevent them from accidentally giving passwords or credit card numbers to the bad guy. Uses Avast Secure DNS to protect online payments made, includes Anti-Spam feature.
    • New Secure DNS feature: verifies a website’s IP address using secure DNS servers to ensure the user is not being redirected to fake websites when shopping or banking online, therefore protecting people against fraud, scams and phishing attacks.

 

  • AVG TuneUp: users can enjoy a range of new and improved features:
    • Automatic Software Updater: AVG TuneUp builds on its core strengths of clearing out unnecessary files and improving PC performance using patented technologies to update most used applications, like Skype, Adobe reader, Flash and Chrome, automatically and silently in the background. AVG customers can choose to rely on the automatic updates, or perform manual checks as desired.
    • Sleep Mode: AVG TuneUp’s patented enhanced Sleep Mode technology improves speed by putting unused applications to ‘sleep’ and only running the necessary ones. This reduces battery and network drain to a minimum so PCs perform like they are just out of the box.

Vince Steckler, Chief Executive Officer at Avast, said, “The combination of AVG and Avast threat detection and analysis capabilities gives us unparalleled insight into cybercrime trends. We tracked, for example, that ransomware alone increased by over 105% between 2015 and 2016 and, based on our data, predict that this is only going to soar. Consumer awareness of security exploits is also at its height given the many ransomware and hacking incidents reported last year. In an age where we are all connecting more of the time, security is becoming a conscious decision and we encourage people to pick the products that are right for their particular needs.”

Download AVG AntiVirus Free, AVG Internet Security and AVG TuneUp at www.avg.com.

About Avast

Avast Software (www.avast.com), the global leader in digital security products for consumers and businesses, protects over 400 million people online. Avast offers products under the Avast and AVG brands, that protect people from threats on the internet with one of the most advanced threat detection networks in the world. Avast digital security products for Mobile, PC or Mac are top-ranked and certified by VB100, AV-Comparatives, AV-Test, OPSWAT, ICSA Labs, West Coast Labs and others. Avast is backed by leading global private equity firms CVC Capital Partners and Summit Partners.

 

Exploit kits and the problem of do-nothing malware

Exploit kits and the problem of do-nothing malware, Exploit-Kits, kits d'exploitation, exploit kit

The first two questions about malware are impossible to quickly answer in regards to exploit kits – and this is more than an IT communication problem.  “What does it do?” is the first question most people have about any new type of malware. That’s logical. Who would NOT want to know about the risks from […]

The post Exploit kits and the problem of do-nothing malware appeared first on Avira Blog.

Porn filter: is it enough to protect our children?

UK to create new porn filter – but is it enough to protect your kids?

The UK government has recently announced a range of new measures intended to help “police” the internet, identifying and prosecuting cybercriminals and terrorists for instance. In among the proposals of the digital economy bill are plans to restrict access to pornographic websites that breach specific guidelines.

Under the proposal, any websites depicting sex acts that would breach the regulations used by the British Board of Film Classification (BBFC) to issue certificates for movies will be banned. This ban will apply to all UK users – not just children.

Moves to improve online safety

This new filter is part of continued government efforts to protect children from accessing pornography online. Previous measures include “age gateways” on porn sites that will demand proof that the user is over-18 before allowing access.

The reality is that children are being exposed to (or choosing to access) more inappropriate images than ever before. Parents, teachers and healthcare professionals are increasingly concerned about what the long term effect of this exposure is, which explains these new initiatives to restrict access.

Will it work?

Already there are many people raising objections to this latest proposal, claiming that a block on certain websites is unfair to adults who are allowed to view pornography. Other complaints focus on the fact that many of the “banned” sex acts are completely legal for consenting adults to engage in. These objections have little bearing on children, but they could force the government to water down their proposals in the long term.

More problematic is the fact that web filters imposed by central governments around the world almost always have loopholes that are exploited by criminals to carry on as normal. It is entirely possible that a UK content filter will have similar gaps in coverage. Alternatively the use of anonymous web proxies will allow determined users to circumvent these safeguards.

Children need multiple layers of protection online

The proposed web filter will act as a robust baseline protection for your kids as they surf the web. But it will not be sufficient to keep them completely safe.

True internet security relies on using multiple layers of protection to keep unwanted content out. So it makes sense to install a secondary web content filtering tool like Panda Internet Security to catch anything that makes it through the government’s filters.

Panda Internet Security

Panda Internet Security has the added benefit of being able to detect and block attempts to circumvent security. If one of your kids tries to use an anonymous proxy for instance, the filter will detect and prevent access. You also have the added benefit of industry leading anti-malware protection included as part of your subscription.

Whether the government’s proposed porn filter is ever put in place remains to be seen. But there is nothing to stop you from installing your own filter to protect your children right now.

Click here to download a free trial of Panda Internet Security today.

The post Porn filter: is it enough to protect our children? appeared first on Panda Security Mediacenter.