Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Trend Micro Hacked - Serving Malicious Iframes
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
AV Programs - most users?! »
« Security Software Updates 22 Mar 2008  
AuthorAll Replies


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage

reply to SUMware
Re: Trend Micro Hacked - Serving Malicious Iframes

Good find -

Based on that incident, I'm glad I have NoScript enabled. This goes to demonstrate that "trusted sites" can still serve up malware.

It shoots down the often-repeated assumption that "careful browsing" is the silver bullet that eliminates the need for security tools.
--
Mayors of New York come from nowhere and go nowhere.
Wallace Sayre (apparently, so do governors... )


Bubba17
Less is More
Premium
join:2006-09-21

said by EGeezer See Profile :

This goes to demonstrate that "trusted sites" can still serve up malware.
Frustrating. I operate a locked-down IE7 .. greatly utilizing the trusted/NOT scheme.

Presently, should KIS7's web protection component fail to detect a trusted(s) compromise .. there is no second line.
--
"Fast is fine, but accuracy is everything" --Wyatt Earp


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage

The infection of legitimate and normally trusted websites also brings mitigation and recovery to the forefront. If one assumes that at some point they may be breached, then they can start putting together a response and recovery plan. One example is a mini-TTX where we "pretend" that our PC has been hacked, corrupted, logins stolen, ID and CC info captured etc. and our recent available backups may be suspect. From that point, practice or develop a response and document as needed.

Although this PPT relates to school and organizational training, many of the tips for planning and doing the exercise are applicable.
--
Mayors of New York come from nowhere and go nowhere.
Wallace Sayre (apparently, so do governors... )


webscanner

@web123.com

reply to Bubba17
said by Bubba17 See Profile :

Frustrating. I operate a locked-down IE7 .. greatly utilizing the trusted/NOT scheme.

Presently, should KIS7's web protection component fail to detect a trusted(s) compromise .. there is no second line.
Does the web scanner of *any* antivirus program really offer any needed protection?

If the antivirus program is going to catch the threat, would it not catch it just as well without the use of a web scanner?

I have often wondered if including a web scanner in an antivirus program was more marketing hype than truly being useful. Am I wrong?


JTM1051
Premium,MVM
join:2000-07-08
Moorpark, CA

reply to EGeezer
said by EGeezer See Profile :

...Based on that incident, I'm glad I have NoScript enabled. This goes to demonstrate that "trusted sites" can still serve up malware. ...
Ditto; using Fx with NoScript and all the "Additional restrictions for untrusted sites " (NoScript's Options > Plugins) enabled.

Since I only use IE for few sites that need/work best with IE, easy for me to lock down IE using customized settings for Trusted Sites, all other security zones set to max high settings.

Also using Online Armor's "Run Safer" setting for Fx, Opera and IE.
Forums » Up and Running » Security » SecurityAV Programs - most users?! »
« Security Software Updates 22 Mar 2008  


Wednesday, 25-Nov 23:34:41 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [105] New AT&T Ad Campaign Hits Back At Verizon
· [94] Apple Joins AT&T Verizon Snark Fest
· [92] Time Warner Cable Fires Broadside At Broadcasters
· [85] New Bill Takes Aim At Higher Verizon ETFs
· [58] TiVo Sees Record Customer Losses
· [48] In-Flight Internet Headed For Bumpy Landing?
· [33] Senators Want ACTA Made Public
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [28] Frontier Increases Modem Rental Fee
Most people now reading
· Shutting of Electricity Temporarily (up to 1 yr) to Save $$$ [Home Repair & Improvement]
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Telemarketing Hell: Heather's back [Spam, Scam and Phishbusters]
· Whats the big deal about being "Old School"....? [World of Warcraft]
· Fiber to the Premises [Comcast HSI]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]