2 new Adobe Flash 0-Day exploits in the wild. Disable Flash
Moderator: Wiz Feinberg
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
2 new Adobe Flash 0-Day exploits in the wild. Disable Flash
On Thursday, January 22, I wrote a security blog article about new Flash Player vulnerabilities that are being exploited in the wild. Adobe patched one of the two holes, but left the other one open. I expect that Adobe will soon release a second out of band patch for exploit #2.
In the meantime, if you visit websites that run advertising from ad networks and you have a Windows PC and are browsing with either Firefox or Internet Explorer, you are at risk of a drive-by download of malware. My article explains all this and shows you how to stay protected until Adobe patches this for good.
In the meantime, if you visit websites that run advertising from ad networks and you have a Windows PC and are browsing with either Firefox or Internet Explorer, you are at risk of a drive-by download of malware. My article explains all this and shows you how to stay protected until Adobe patches this for good.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
- Richard Sinkler
- Posts: 17676
- Joined: 15 Aug 1998 12:01 am
- Location: aka: Rusty Strings -- Missoula, Montana
Something weird happened to me today. But, I use Chrome. I was on some news site and clicked on a video. Anew smaller window appeared with some text (sorry, I didn't write it down) and an "OK " button. I didn't like the looks of it and wouldn't click the button. But I tried to close the window with the x button in the upper right corner. Window wouldn't close. I tried to close Chrome, but couldn't. Couldn't navigate away from Chrome to any other running programs. It was similar to that FBI ransomeware bug. But, I was able to start task manager and kill Chrome. Everything looked cool, but I ran a full scan with MalwareBytes. Found nothing. Since it happened when clicking on a video, could this be related?
Carter D10 8p/7k, Dekley S10 3p/4k C6 setup, Regal RD40 Dobro, Recording King Professional Dobro, NV400, NV112, Ibanez Gio guitar, Epiphone SG Special (open G slide
and regular G tuning guitar) . Playing for 55 years and still counting.
and regular G tuning guitar) . Playing for 55 years and still counting.
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
It is unlikely that what happened to you was due to the Angler Exploit kit. It doesn't currently target Chrome browsers at all.
I will update this and my blog article when Adobe patches every part of this exploit attack.
BTW: I am directly in touch with the researcher who discovered this situation.
I will update this and my blog article when Adobe patches every part of this exploit attack.
BTW: I am directly in touch with the researcher who discovered this situation.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
- Richard Sinkler
- Posts: 17676
- Joined: 15 Aug 1998 12:01 am
- Location: aka: Rusty Strings -- Missoula, Montana
Thanks. It will be a great day when HTML5 video finally knocks Flash out.
Carter D10 8p/7k, Dekley S10 3p/4k C6 setup, Regal RD40 Dobro, Recording King Professional Dobro, NV400, NV112, Ibanez Gio guitar, Epiphone SG Special (open G slide
and regular G tuning guitar) . Playing for 55 years and still counting.
and regular G tuning guitar) . Playing for 55 years and still counting.
-
- Posts: 1565
- Joined: 15 Apr 2003 12:01 am
- Location: Texas
I ran a new Flash update yesterday based on the invitation it offered me - maybe that was the other patch?
At any rate, I dislike ads, and I can't tolerate all the Flash videos starting simultaneously when I load a group of Firefox tabs, so I have Adblock Plus to kill ads, but also have the add-on Flashblock as well. With that, nothing "Flash" opens unless I explicitly click on the icon.
I'll disable it anyway, based on the advice here. I've never been a web video junkie.
At any rate, I dislike ads, and I can't tolerate all the Flash videos starting simultaneously when I load a group of Firefox tabs, so I have Adblock Plus to kill ads, but also have the add-on Flashblock as well. With that, nothing "Flash" opens unless I explicitly click on the icon.
I'll disable it anyway, based on the advice here. I've never been a web video junkie.
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
Nope. That fixed an earlier exploit vector. It is Flash 16.0.0.287 and is still exploited silently and downloads malware. The real fix will have a higher number than .287.Dave Potter wrote:I ran a new Flash update yesterday based on the invitation it offered me - maybe that was the other patch?
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
- Posts: 1565
- Joined: 15 Apr 2003 12:01 am
- Location: Texas
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
Not normally. The miscreants buy advertising on ad networks. They submit normal ads to get approved. After a certain amount of time they begin serving compromised ads in Flash format. Hidden codes do the dirty work.Dave Potter wrote:Do YouTube videos present this kind of threat?
My researcher friend who discovered this new threat told me that Malwarebytes Anti-Exploit stopped an attack in his virtual machine in his lab. I am testing MBAE myself and will report back here if it actually blocks an attempted exploit.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
- Scott Duckworth
- Posts: 3464
- Joined: 6 Apr 2013 8:41 am
- Location: Etowah, TN Western Foothills of the Smokies
- Contact:
Yahoo News had a big article about this yesterday...
Amateur Radio Operator NA4IT (Extra)
http://www.qsl.net/na4it
I may, in fact, be nuts. However, I am screwed onto the right bolt... Jesus!
http://www.qsl.net/na4it
I may, in fact, be nuts. However, I am screwed onto the right bolt... Jesus!
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
I have posted three updates since writing my blog article about the current Flash Player exploits. Update 3 (today) describes another patched version of Flash Player, 16.0.0.296, which is only available via automatic Flash Updates (Control Panel Flash applet > Advanced).
For those using non-Windows operating systems, or whose account privileges are insufficient to install such browser plugins, you're still safest disabling Flash until Adobe releases the new update to everybody (manual downloading and installation).
The manual update will become available this week, as Adobe sees fit. Perhaps they have run into to compatibility problems caused by it (this happens with security patches).
For those using non-Windows operating systems, or whose account privileges are insufficient to install such browser plugins, you're still safest disabling Flash until Adobe releases the new update to everybody (manual downloading and installation).
The manual update will become available this week, as Adobe sees fit. Perhaps they have run into to compatibility problems caused by it (this happens with security patches).
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
- Todd Goad
- Posts: 410
- Joined: 20 Jul 2012 7:17 am
- Location: Gray, Georgia, USA
Wiz, I show that I have the latest flash player beta version installed. ( Your version16.0.0.296 Latest Version16.0.0.287 ).
Is this the correct latest version? I am not sure what BETA means? I'm guessing it is a test version. Am I right?
Please let me know what I should do, if anything?
Thanks,
Todd
Is this the correct latest version? I am not sure what BETA means? I'm guessing it is a test version. Am I right?
Please let me know what I should do, if anything?
Thanks,
Todd
Todd
Mullen G2 "THE SAVIOR" BJS Bars Peterson Stroboflip Tuner NV400 GoodrichL20
Mullen G2 "THE SAVIOR" BJS Bars Peterson Stroboflip Tuner NV400 GoodrichL20
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
Beta indicates that Adobe has not finished quality testing that version. It won't surprise me if they have to patch the pach that is still to be release to the GP.Todd Goad wrote:Wiz, I show that I have the latest flash player beta version installed. ( Your version16.0.0.296 Latest Version16.0.0.287 ).
Is this the correct latest version? I am not sure what BETA means? I'm guessing it is a test version. Am I right?
Please let me know what I should do, if anything?
Thanks,
Todd
As for what you can do, all that is outlined fully in my blog article.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
Adobe has resolved the version discrepancies. You can now manually download version 16.0.0.296 from the Flash Player Download Center.
All the links and details are on my followup blog article I posted this afternoon.
All the links and details are on my followup blog article I posted this afternoon.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
- Jon Light (deceased)
- Posts: 14336
- Joined: 4 Aug 1998 11:00 pm
- Location: Saugerties, NY
- Contact:
- Sonny Jenkins
- Posts: 4413
- Joined: 19 Sep 2000 12:01 am
- Location: Texas Masonic Retirement Center,,,Arlington Tx
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
Absolutely NOT. The Flash Player update only prevents further exploits that affected the previous versions. Any malware that was dropped onto your computer will remain until it is located and removed by a qualified security program that recognizes the threat and knows its component locations.Sonny Jenkins wrote:So if the plug in says it is up to date does that mean that whatever malware MAY have been put on my computer,,is now eliminated by the update?
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
- Sonny Jenkins
- Posts: 4413
- Joined: 19 Sep 2000 12:01 am
- Location: Texas Masonic Retirement Center,,,Arlington Tx
Like malwarebytes? Speaking of which, I run the free version at least once or twice a week,,,and it ALWAYS finds one (1) item, which I quarantine. Several months ago I signed up for the 30 day trial, set it to scan once a week,,,,it always found 20-25 items? Does the free version that is run manually not do as thorough a scan as the paid version?
- Wiz Feinberg
- Posts: 6103
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- Contact:
The free version of MBAM does full threat scans, but do not do the following:
Hyper Scans
Scan/Database Update Scheduler
Malicious website blocking
Realtime protection
Chameleon Driver
Possibly, PUPs detection
It's been so long since I had that version I don't even remember what it lacked.
Hyper Scans
Scan/Database Update Scheduler
Malicious website blocking
Realtime protection
Chameleon Driver
Possibly, PUPs detection
It's been so long since I had that version I don't even remember what it lacked.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog