Technical Discussion
  >> Security Related Issues


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | (show all)   Print Thread
Standard User deleted
(deleted) Sat 06-Feb-16 01:30:45
Print Post

Malwarebytes vulnerability


[link to this post]
 
I just read this regarding a vulnerability in MWB that may take up to 4 weeks to fix:
http://www.itpro.co.uk/security/25989/malwarebytes-c...
Standard User bobble_bob
(knowledge is power) Sat 06-Feb-16 09:50:33
Print Post

Re: Malwarebytes vulnerability


[re: deleted] [link to this post]
 
Seems a pretty basic error to make on their part not encrypting updates.
Standard User Banger
(eat-sleep-adslguide) Sat 06-Feb-16 21:12:09
Print Post

Re: Malwarebytes vulnerability


[re: deleted] [link to this post]
 
Thanks for the heads up.

Tim
www.xilo.net & freenetname
Billion 7800 on 24 Meg LLU
http://www.thinkbroadband.com/speedtest/results.html...


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Sun 07-Feb-16 10:51:04
Print Post

Re: Malwarebytes vulnerability


[re: Banger] [link to this post]
 
smile
Standard User Jax2
(member) Sun 07-Feb-16 17:10:11
Print Post

Re: Malwarebytes vulnerability


[re: deleted] [link to this post]
 
Thanks.

I see the article says "The company's CEO Marcin Kleczynski recommended customers use a workaround until the flaw has been completely eradicated, saying they should enable self-protection in the settings menu to "mitigate all of the reported vulnerabilities."

However in the free version you cannot do what he suggests as that option is greyed out. The only workaround would seem to be not to use the programme for the next month if you use the free version.
Standard User deleted
(deleted) Sun 07-Feb-16 17:40:12
Print Post

Re: Malwarebytes vulnerability


[re: Jax2] [link to this post]
 
Mine is the free version, and as you say, it won't be used for a month unless some assurance of it being fixed is issued.
Standard User mikejp
(member) Sat 13-Feb-16 12:50:34
Print Post

Re: Malwarebytes vulnerability


[re: deleted] [link to this post]
 
Have we any more news and has MWB made any sort of statement about this?
Standard User ggremlin
(experienced) Sat 13-Feb-16 12:53:54
Print Post

Re: Malwarebytes vulnerability


[re: deleted] [link to this post]
 
you could enable the trial of the paid version that lasts for a month, then revert to free after that.
Standard User deleted
(deleted) Sat 13-Feb-16 13:01:31
Print Post

Re: Malwarebytes vulnerability


[re: mikejp] [link to this post]
 
I haven't seen anything yet - haven't been looking particularly though.
I just decided to leave it alone for a few weeks and then check around.
Standard User Apprentice
(knowledge is power) Sat 13-Feb-16 13:36:27
Print Post

Re: Malwarebytes vulnerability


[re: mikejp] [link to this post]
 
https://blog.malwarebytes.org/news/2016/02/malwareby...

plusnet user
Standard User bobble_bob
(knowledge is power) Sun 13-Mar-16 08:22:21
Print Post

Re: Malwarebytes vulnerability


[re: deleted] [link to this post]
 
Any word of a fix yet? Been 5 week now
Standard User Jax2
(member) Sun 13-Mar-16 09:19:55
Print Post

Re: Malwarebytes vulnerability


[re: bobble_bob] [link to this post]
 
Had a quick look on their Release History and the answer is no, the last update was on the 12th October 2015.
Standard User deleted
(deleted) Sun 13-Mar-16 10:38:53
Print Post

Re: Malwarebytes vulnerability


[re: bobble_bob] [link to this post]
 
Looks like the new 'fix' version (2.2.1) hasn't been released yet ...this is a comment from just a short while ago this morning:

You ever going to release this fix or should I start looking for another program that won't let me be exploited? "No software is perfect" but you said you were gonna fix it in 2-3 weeks not 2-3 months.
Standard User bobble_bob
(knowledge is power) Sat 19-Mar-16 08:19:32
Print Post

Re: Malwarebytes vulnerability - update is out


[re: deleted] [link to this post]
 
https://forums.malwarebytes.org/topic/180348-mbam-22...
Standard User deleted
(deleted) Sat 19-Mar-16 10:45:32
Print Post

Re: Malwarebytes vulnerability - update is out


[re: bobble_bob] [link to this post]
 
Good to see that at last!
Although it can be downloaded now, it Looks as though within the coming week there'll be an update and it won't be necessary to uninstall the old version first:

We�ll be enabling automatic upgrades for current users beginning next week. If you�d like to upgrade before then, simply download the new version from the link above and install
Standard User bobble_bob
(knowledge is power) Sat 19-Mar-16 10:47:27
Print Post

Re: Malwarebytes vulnerability - update is out


[re: deleted] [link to this post]
 
I didnt unistall the previous version. Downloaded the file and installed over the top of the previous version
Standard User deleted
(deleted) Sat 19-Mar-16 10:57:11
Print Post

Re: Malwarebytes vulnerability - update is out


[re: bobble_bob] [link to this post]
 
Even better! Thanks smile
Standard User Chrysalis
(legend) Sun 27-Mar-16 16:44:17
Print Post

Re: Malwarebytes vulnerability


[re: Apprentice] [link to this post]
 
this is comical.

so a software security vendor needs to rely on people to tell them to follow modern encryption security practices?

They not alone in this problem.

e.g. software like avast and eset which have https scanning modules, will disable technologies such as OCSP and key pinning. Some version also have no tls 1.1/1.2 support.

Sky Fibre Pro BQM - IPv4
Standard User ukhardy07
(knowledge is power) Sun 27-Mar-16 17:23:39
Print Post

Re: Malwarebytes vulnerability


[re: Chrysalis] [link to this post]
 
TLS v1.1 is also an issue as it is prone to TLS over POODLE vulnerability. The only version to be used should be version 1.2 and support for SSL2, SSL3 and TLS v1, and v1.1 should be disabled - else an attacker is able to launch an attack whereby they can force a users session to downgrade and use older TLS or even worse SSL versions, even if TLS v1.2 is enabled... Thereby, the attacker is able to break the encryption used. This of course is an issue for those using ancient browsers.
Pages in this thread: 1 | 2 | (show all)   Print Thread

Jump to