Latest threats, vulnerabilities, exploits to be aware of

Discussion in 'Operating Systems' started by alanm, Jan 27, 2022.

  1. KissSh0t

    KissSh0t Ancient Guru

    Messages:
    13,944
    Likes Received:
    7,761
    GPU:
    ASUS 3060 OC 12GB
    Paid, yes it did.

    I'd have to say it's "too good" at finding stuff.... it even sees things as disabling UAC or System Restore as potential problems, or even cracks for games... I have quite a large collection of cracks for physical disc copies of old pc games and it went ham on those.

    You can create a white list for locations it shouldn't look, and also mark things it sees as problems as things you don't want it doing anything about.
     
    Software Dev Expert likes this.
  2. Software Dev Expert

    Software Dev Expert Active Member

    Messages:
    68
    Likes Received:
    5
    GPU:
    Integrated
    Oh no!
    Do you mean it recognises the fact that the pirated games are not legit copies?
    Or do you mean that malware is rightly detected?
     
  3. KissSh0t

    KissSh0t Ancient Guru

    Messages:
    13,944
    Likes Received:
    7,761
    GPU:
    ASUS 3060 OC 12GB
    They aren't the games themselves, those are on disc... it's the cracks for the games which are zipped and kept for if I ever want to install whatever game... so I don't need the games in the disc drive, something these days isn't a problem.. but for physical old games it is.

    It's not "matware", it's a software hack I guess is the term, but yeah Loaris Trojan Remover is quite good.
     
  4. Chastity

    Chastity Ancient Guru

    Messages:
    3,744
    Likes Received:
    1,668
    GPU:
    Nitro 5700XT/6800M
    They're called "NoCD cracks"
     
    KissSh0t likes this.

  5. 386SX

    386SX Ancient Guru

    Messages:
    2,084
    Likes Received:
    2,243
    GPU:
    AMD Vega64 RedDevil
    All EU citizens will have a hard time when this goes live:
    https://www.heise.de/news/EU-erteil...uenden-gemeinsame-Werbeplattform-7492868.html
    (Sorry, German link)

    TL;DR:
    EU agreed to an EU-wide ad platform.
    Well nothing "security related" so far ..

    But "user tracking" is part of the process and done by ISPs with a user token they send with your uplink's traffic to identify you through whole Europe.

    They say you only will receive this after you opt-in to that and intentionally agree with this option.

    Well ... they have to "track" if you agreed or not (requirement by GDPR), so welcome to the club anyways.

    So good bye privacy! It was a nice time when you were around. Hope to see you again ...

    Edit: seems to be related:
    https://techcrunch.com/2023/01/09/trustpid-joint-venture/
     
    Last edited: Feb 11, 2023
  6. RealNC

    RealNC Ancient Guru

    Messages:
    5,089
    Likes Received:
    3,370
    GPU:
    4070 Ti Super
    At first it's opt-in, then it will become opt-out, then it will become really hard to opt-out, and finally it will be mandatory :p
     
    386SX likes this.
  7. Software Dev Expert

    Software Dev Expert Active Member

    Messages:
    68
    Likes Received:
    5
    GPU:
    Integrated
    I’m keen to read. Please send an English link.Thanks
     
  8. 386SX

    386SX Ancient Guru

    Messages:
    2,084
    Likes Received:
    2,243
    GPU:
    AMD Vega64 RedDevil
    This seems to be what was planned. It's live already.

    https://www.trustpid.com/

    This site got blocked by my Adblock, you'll have to disable it to view it. 'Nuff said.

    Edit: well they say currently it's just on mobile plans, at least in Germany.
     
  9. Software Dev Expert

    Software Dev Expert Active Member

    Messages:
    68
    Likes Received:
    5
    GPU:
    Integrated
    Thanks!
    Selecting “pause for this site” will generally ensure the No adblocker test passes
     
  10. 386SX

    386SX Ancient Guru

    Messages:
    2,084
    Likes Received:
    2,243
    GPU:
    AMD Vega64 RedDevil
    https://kb.cert.org/vuls/id/782720

    Vulnerability in TPM 2.0

     

  11. alanm

    alanm Ancient Guru

    Messages:
    12,269
    Likes Received:
    4,472
    GPU:
    RTX 4080
    UEFI bootkit malware that defeats secure boot on Windows 11/10

    ESET security researchers have discovered an UEFI bootkit malware that defeats secure boot on Windows 11 and Windows 10 devices. Named BlackLotus, it is considered the first UEFI bootkit malware that has been detected in the wild...

    https://www.ghacks.net/2023/03/02/w...-blacklotus-uefi-bootkit-defeats-secure-boot/

    and...

    Malware dev claims to sell new BlackLotus Windows UEFI bootkit

    A threat actor is selling on hacking forums what they claim to be a new UEFI bootkit named BlackLotus, a malicious tool with capabilities usually linked to state-backed threat groups...

    https://www.bleepingcomputer.com/ne...-to-sell-new-blacklotus-windows-uefi-bootkit/
     
    386SX likes this.
  12. Astyanax

    Astyanax Ancient Guru

    Messages:
    17,035
    Likes Received:
    7,378
    GPU:
    GTX 1080ti
    its concerning that these folks want to try to tell us that this is the first.......
     
    386SX likes this.
  13. 386SX

    386SX Ancient Guru

    Messages:
    2,084
    Likes Received:
    2,243
    GPU:
    AMD Vega64 RedDevil
    Oh little do they know ... :D
    I once built one back thrn in 2014 or '15. Was "phun" to play with, but seriously concerning. But bypassing Secure Boot is new.
     
  14. 386SX

    386SX Ancient Guru

    Messages:
    2,084
    Likes Received:
    2,243
    GPU:
    AMD Vega64 RedDevil
    Latest "threat": biometric access control (fingerprints)

    A criminal locked his mobile phone by fingerprint. Later he got caught and the police locked him away. They asked him to unlock his phone and he denied.

    Cops then were very creative and said "Well, OK then, no issue." and went over to the standard procedure of "identification", which includes .... *drum roll* ... taking the suspect's full name, address and other stuff ... including fingerprints!! :D
    (In Germany you must go through this ID process if required by the police or you could be sent to jail until you cooperate.)

    So they took the fingerprints from identification process and were able to unlock the suspect's phone with it.
     
  15. Astyanax

    Astyanax Ancient Guru

    Messages:
    17,035
    Likes Received:
    7,378
    GPU:
    GTX 1080ti
    they asked, or they had a warrant for it? no warrant, illegal search, not admissable in court.
     

  16. Ghosty

    Ghosty Ancient Guru

    Messages:
    7,983
    Likes Received:
    1,189
    GPU:
    RTX 3050
    They can just say the owner of the phone granted them permission. Makes no difference.
     
  17. Astyanax

    Astyanax Ancient Guru

    Messages:
    17,035
    Likes Received:
    7,378
    GPU:
    GTX 1080ti
    no, they can't.
     
    386SX likes this.
  18. 386SX

    386SX Ancient Guru

    Messages:
    2,084
    Likes Received:
    2,243
    GPU:
    AMD Vega64 RedDevil
    The proof acquired through searching the mobile phone was accepted by the judge and the criminal was charged for drug trafficking.

    Taking finger prints is allowed in general (by law, to get your ID) if you are part of an investigation of some kind.
    The law explicitely says the prints then "may be processed further by a digital system". Because it is described this loosely, police can take them and feed them into ANY "digital device", like a criminal database or like in this case entered into the "digital system" of the mobile phone.

    Germany, YES, we can't. :D

    Edit: sources (German, use Google translate):
    https://www.lawblog.de/archives/2023/03/10/ihren-fingerabdruck-bitte/

    https://www.burhoff.de/asp_weitere_beschluesse/inhalte/7646.htm
     
    fantaskarsef likes this.
  19. Ghosty

    Ghosty Ancient Guru

    Messages:
    7,983
    Likes Received:
    1,189
    GPU:
    RTX 3050
    Easy way around it is to not to use your index finder. Problem solved.
     
  20. 386SX

    386SX Ancient Guru

    Messages:
    2,084
    Likes Received:
    2,243
    GPU:
    AMD Vega64 RedDevil
    In Germany they take prints of all five fingers of both hands. Every finger is "rolled" from one side to the other to give detailled prints.
     

Share This Page