Technical Discussion
  >> Security Related Issues


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | (show all)   Print Thread
Standard User bobble_bob
(knowledge is power) Sun 13-Mar-16 08:22:21
Print Post

Re: Malwarebytes vulnerability


[re: deleted] [link to this post]
 
Any word of a fix yet? Been 5 week now
Standard User Jax2
(member) Sun 13-Mar-16 09:19:55
Print Post

Re: Malwarebytes vulnerability


[re: bobble_bob] [link to this post]
 
Had a quick look on their Release History and the answer is no, the last update was on the 12th October 2015.
Standard User deleted
(deleted) Sun 13-Mar-16 10:38:53
Print Post

Re: Malwarebytes vulnerability


[re: bobble_bob] [link to this post]
 
Looks like the new 'fix' version (2.2.1) hasn't been released yet ...this is a comment from just a short while ago this morning:

You ever going to release this fix or should I start looking for another program that won't let me be exploited? "No software is perfect" but you said you were gonna fix it in 2-3 weeks not 2-3 months.


Register (or login) on our website and you will not see this ad.

Standard User bobble_bob
(knowledge is power) Sat 19-Mar-16 08:19:32
Print Post

Re: Malwarebytes vulnerability - update is out


[re: deleted] [link to this post]
 
https://forums.malwarebytes.org/topic/180348-mbam-22...
Standard User deleted
(deleted) Sat 19-Mar-16 10:45:32
Print Post

Re: Malwarebytes vulnerability - update is out


[re: bobble_bob] [link to this post]
 
Good to see that at last!
Although it can be downloaded now, it Looks as though within the coming week there'll be an update and it won't be necessary to uninstall the old version first:

We�ll be enabling automatic upgrades for current users beginning next week. If you�d like to upgrade before then, simply download the new version from the link above and install
Standard User bobble_bob
(knowledge is power) Sat 19-Mar-16 10:47:27
Print Post

Re: Malwarebytes vulnerability - update is out


[re: deleted] [link to this post]
 
I didnt unistall the previous version. Downloaded the file and installed over the top of the previous version
Standard User deleted
(deleted) Sat 19-Mar-16 10:57:11
Print Post

Re: Malwarebytes vulnerability - update is out


[re: bobble_bob] [link to this post]
 
Even better! Thanks smile
Standard User Chrysalis
(legend) Sun 27-Mar-16 16:44:17
Print Post

Re: Malwarebytes vulnerability


[re: Apprentice] [link to this post]
 
this is comical.

so a software security vendor needs to rely on people to tell them to follow modern encryption security practices?

They not alone in this problem.

e.g. software like avast and eset which have https scanning modules, will disable technologies such as OCSP and key pinning. Some version also have no tls 1.1/1.2 support.

Sky Fibre Pro BQM - IPv4
Standard User ukhardy07
(knowledge is power) Sun 27-Mar-16 17:23:39
Print Post

Re: Malwarebytes vulnerability


[re: Chrysalis] [link to this post]
 
TLS v1.1 is also an issue as it is prone to TLS over POODLE vulnerability. The only version to be used should be version 1.2 and support for SSL2, SSL3 and TLS v1, and v1.1 should be disabled - else an attacker is able to launch an attack whereby they can force a users session to downgrade and use older TLS or even worse SSL versions, even if TLS v1.2 is enabled... Thereby, the attacker is able to break the encryption used. This of course is an issue for those using ancient browsers.
Pages in this thread: 1 | [2] | (show all)   Print Thread

Jump to