Warning - Freak vulnerability on ecommerce

Status
Not open for further replies.

rolygate

Vaping Master
Supporting Member
ECF Veteran
Verified Member
Sep 24, 2009
8,354
12,402
ECF Towers
Incorrect. I've tested opera, chrome, and the default android browser that is installed on my Galaxy Note 4 -all latest versions - all fail.

As far as we know, this can only happen if you are running an A/V with its own proxy, such as Avast with the Web Shield turned on. Otherwise all the data so far including the security people's advice on browsers / OS / devices is wrong.

If you have no antivirus then this looks like a first. If you have Avast then update it (latest patch fixes the issue) or turn off the Web Shield. But - check the browser / OS list first, if your combo is listed as a fail, then that is the answer.
 

retired1

Administrator
Admin
Supporting Member
ECF Veteran
Verified Member
Apr 5, 2013
50,743
45,066
Texas
Incorrect. I've tested opera, chrome, and the default android browser that is installed on my Galaxy Note 4 -all latest versions - all fail.

Ensure you're installing the latest version from Google Play. If you're installing from the provider, it's not going to be up to date.
 

DreamWithin

Vaping Master
Supporting Member
ECF Veteran
Verified Member
Jun 15, 2012
3,078
1,102
New England
Thank you Roly for posting this including the Avast info. After I turned web shield off both my Firefox and Chrome passed. So I can confirm that the Avast web shield also affected my Chrome browser.

Make sure you update Avast to the latest version, then you can leave your web shield on :)

For some reason, the most current version was not automatically applied for me even though released almost a week ago, I had to manually run the update. So even if Avast says you're all up to date, open it up and choose "Settings" and then "Update" in the menu to see if you actually have the latest version (2015.10.2.2214)

EDIT: note that that version number was taken from the paid version. I'm not sure if there are any differences in version numbers for the free one
 

MacTechVpr

Vaping Master
ECF Veteran
Verified Member
Aug 24, 2013
5,723
14,401
Hollywood (Beach), FL
A security warning for ecommerce purchases has been published Friday March 7th.

Some browsers have an HTTPS encryption vulnerability that can lead to your data being stolen by the web traffic being intercepted and the code easily cracked.

Check to see if your browser passes the exploit test below.

Exploit test:
https://cve.freakattack.com

Mine, too. Apple is supposed to be releasing a patch, this coming week.

Thanks for the test link roly.

LB, Apple's update is live on the Apple Store page.

Good luck all.

:)
 
Last edited:
Status
Not open for further replies.

Users who are viewing this thread