此主题已被锁定
Kerry 2022 年 11 月 16 日 下午 1:32
2
Remove all Discord CDN links
The chat program Discord is a known dumping ground for malware and malicious bots, and is widely used for command and control of serious malware including credential stealers, ransomware, and other things. Some malware can even use Discord to crash other players' games.

Sophos, an anti-malware publisher and research group, reports that the greatest amount of malware they've found on the Discord Content Distribution Network is, quote: "credential and personal information theft, a wide variety of stealer malware as well as more versatile RATs."

This means software that steals bank account info and Steam account info.

So by allowing games that link with Discord to run on Steam, ValveCorp is inadvertently putting their users and all the games on this platform at serious risk of catastrophic loss.

I believe that these games should be sanctioned or heavily restricted in their capability to link with Discord, and all links that lead to a Discord server should be considered a direct link to malware.

Source: https://news.sophos.com/en-us/2021/07/22/malware-increasingly-targets-discord-for-abuse/

EDIT: I will not allow this thread to be derailed by any method. Attempts to bring up previous threads are obvious attempts to derail a thread and will be treated as such.

Each creator who makes a post that attempts to derail this thread will result in one singular chain of action:

Mute, block, report. You're not worthy of my time if you keep trying to derail the thread and troll me. You're not going to get a rise out of me.

EDIT: I'm sick and tired of some people (not naming names) being so stuck-up and closed-minded that they cannot admit that other people have different experiences.

The technically-impossible happens all the time. Just because YOU haven't seen it happen, doesn't mean weird crap doesn't happen!
最后由 Kerry 编辑于; 2022 年 11 月 17 日 下午 4:44
< >
正在显示第 571 - 585 条,共 599 条留言
Kerry 2022 年 11 月 18 日 下午 4:08 
引用自 Start_Running
引用自 Kerry Freeman

I was actually using malware scanners at the time of infection - Avast, to be precise. The malware bypassed it.

Also, it was reading as safe from Avast, and several others.
Given your words and behaviour...Imma set my X button to auto fire.

Given yours, I'd take anything you said with a huge grain of salt.
Kerry 2022 年 11 月 18 日 下午 4:10 
引用自 Tito Shivan
引用自 Kerry Freeman
I hate being mocked and belittled. As most people do.
I'm talking seriously. That is still one of the most common way to get malware 'through a picture'.
Stegosploit malware are a quite more rare attack vector, not the kind of effort you'd regularly see.

So I'm personally defaulting to some of the old tricks being the culprit.

Agreed... and if it were anyone but me talking, I'd agree with you.

Oftentimes a lot of my problems with computers can be chalked up to just plain bad luck.
Kiddiec͕̤̱͋̿͑͠at 🃏 2022 年 11 月 18 日 下午 4:15 
引用自 Kerry Freeman
引用自 Mad Scientist
Valve is not putting their users at risk by others allowing the use of Discord.

Account security is on the users. If they would stop believing every random "support", "moderator", "employee" account that messages them as a clear scam by not enabling filtering or allowing full public messaging is the users choice. Only allowing friends messages is a way to keep the account secure. Not clicking random links is a good idea too.

Valve is not responsible for others security mishaps.

Explain how I got hacked then, despite following every basic cybersecurity rule in the book.
Simple. Clearly you missed something important that you should have been doing,

...such as not running applications received via chat from NatashaPudding99,

...or maybe you downloaded some "MP4s" from a Youtube description, that were actually exes whose file name ended in ".mp4.exe" and had an MP4 icon, and you still had the setting "Hide extensions of known file types" checked on your Windows PC (which Microsoft stupidly sets to on by default - thus leaving their users vulnerable to this kind of phishing attack) thus causing them to appear as just a regular video file when they were, in fact, actually malware,

...or maybe you just let your nephew use your computer and he installed "GTA 5M" on his own,
or maybe it was your gamer grandma or grandpa - whoever you've been letting use your machine, and you didn't monitor their activity to make sure that they didn't get your machine infected - or here's an idea... just don't let them use your laptop and tell them to get their own,

...then again, maybe you did tell them to get their own and they used it anyways, without your permission, while you were asleep, or at the store, or at school, or at work or something,

...or maybe you took a free USB from the bucket of unpackaged USBs, labeled "FREE USBs", at a tech convention, and thus installed malware into your computer by plugging it in and getting hit by a BadUSB attack,

...or maybe someone didn't even need to make a BadUSB, maybe while you were turned away from your PC, someone at high-school, college, or the library, inserted a USB switchblade like the Rubber Ducky into your USB port for... oh... about 3 to 5 seconds should be long enough to do the trick if they wrote their scripts correctly... and infected you with something that way,

...or maybe you used a Bluetooth device with your PC but the device was infected with a worm,

...or maybe you downloaded an illegal copy of something that had been modified to include extra software that got injected into the executable,

...or maybe you were just feeling tired while reading a Discord chat and started to doze off and accidentally clicked to download something in your drowsiness or as your head began to fall for a bit in your drowsiness ...then later you see it in your downloads folder and think that it's a legitimate program that you forgot about,

...or maybe you had all scripts turned on in your browser (not using NoScript) or "don't ask me before downloading" set in the permissions (Mozilla did a bad recently by automatically switching people's permissions from "Ask every time" to "don't ask before downloading" automatically during an update) and through one of these delivery methods got hit by a drive-by-download, which placed the malware in your downloads folder, looking like a legitimate program (basically don't ever trust any programs in the downloads folder unless you're 100% sure that you downloaded them yourself because it's a folder that is vulnerable to drive-by-downloads)


...just to name a few mistakes that someone could have easily made, which would get malware onto their system that either is already there or allows propagation of further malware downloads via installing auto-clicker malware.


:seewhatyoudid:
Kiddiec͕̤̱͋̿͑͠at 🃏 2022 年 11 月 18 日 下午 4:49 
...or maybe someone nearby used a packet-sniffer to steal your cookies,

...or maybe when you were browsing to some site to download something like Audacity or Spotify, or maybe some drawing program, some ads might have come up on the download page that made themselves look like the download button but what clicking the ad actually caused you to download was a keylogger or remote access trojan instead of what you were after - and if the malware author was clever enough, they would have made sure their malware also installed the software that you were actually trying to download (legitimately) so that you wouldn't suspect anything after the installation of both the legitimate program that you were after AND the malware was complete,

...or maybe a third-party installed it while you were using a TeamViewer login or some other remote-desktop session, depending on the software that you use, you don't even need to necessarily give them authorization or consent if the software is already running with administrative privileges and automatically accepts remote access sessions (TeamViewer used to have an issue where people could break into sessions that they hadn't even been told about due to vulnerabilities in the parent company's service),

引用自 Satoru
Im not sure why everyone is trying to convince the OP when its pretty obvious the OP doesn't actually understand anything at all. And wants to blame 'everyone else' for their own phishing compromise and thinks "yes lets ban the most popular communications program off of steam" as opposed to "how can I educate myself to not fall for phishing attacks"
Based off of what they've written, I'm not even sure that the attack vector that they got hit by was, in fact, actually Discord. Someone can compromise a system in a variety of other ways and then begin compromising accounts which are accessed by that system. All it really takes is a remote access trojan and they can start logging everything you do that they might consider worth hijacking.

引用自 Kerry Freeman
...
Explain how I got hacked then, despite following every basic cybersecurity rule in the book.
Hey, which book did you follow, btw? :yondercat:

引用自 Kerry Freeman
...
#:~:text=But%20the%20greatest%20percentage%20of%20the%20malware%20we%20found%20have%20a%20focus%20on%20credential%20and%20personal%20information%20theft%2C%20a%20wide%20variety%20of%20stealer%20malware%20as%20well%20as%20more%20versatile%20RATs.

#:~:text=Like%20any%20developer,nearby%20in%20gameplay%3A
...
I don't know if you're using a browser that jumps to text like that, but mine doesn't.

引用自 Leonardo Da Pinchi
...
There's a saying in cybersecurity. you can make the most flawless system and the world will provide a better idiot.
That's true, however, people shouldn't kid themselves... they ain't making even close to flawless systems.

Even the software & OSes with the best protections are just filled with zero-days that are yet to be discovered; some of which are extremely complex and will probably only be discovered by A.I.s and others are surprisingly simple.

Now, I can't know for sure about undiscovered zero-day vulnerabilities but past events do, to some extent, predict future events, and there's still quirks to computers that aren't very well known, such as the interference that can be caused by cosmic rays (not exactly hacker-stuff but still - and in theory it could be if someone could control those rays & have an awareness of what they were hitting in the hardware)

引用自 Kerry Freeman
...
I did none of those things. So again, explain how my first account got stolen.
Considering that we're not going to know for sure, this is probably as good of an explanation as any :
https://www.youtube.com/watch?v=AaZ_RSt0KP8
...obviously, that's not how an account gets stolen but this video is also making guesses about several anomalous events that have happened in computing.


:redcircle: :ycircle: :gcircle: :bluecircle: :pcircle:
Kerry 2022 年 11 月 18 日 下午 5:48 
引用自 Kerry Freeman

Explain how I got hacked then, despite following every basic cybersecurity rule in the book.
Simple. Clearly you missed something important that you should have been doing,

...such as not running applications received via chat from NatashaPudding99,

...or maybe you downloaded some "MP4s" from a Youtube description, that were actually exes whose file name ended in ".mp4.exe" and had an MP4 icon, and you still had the setting "Hide extensions of known file types" checked on your Windows PC (which Microsoft stupidly sets to on by default - thus leaving their users vulnerable to this kind of phishing attack) thus causing them to appear as just a regular video file when they were, in fact, actually malware,

...or maybe you just let your nephew use your computer and he installed "GTA 5M" on his own,
or maybe it was your gamer grandma or grandpa - whoever you've been letting use your machine, and you didn't monitor their activity to make sure that they didn't get your machine infected - or here's an idea... just don't let them use your laptop and tell them to get their own,

...then again, maybe you did tell them to get their own and they used it anyways, without your permission, while you were asleep, or at the store, or at school, or at work or something,

...or maybe you took a free USB from the bucket of unpackaged USBs, labeled "FREE USBs", at a tech convention, and thus installed malware into your computer by plugging it in and getting hit by a BadUSB attack,

...or maybe someone didn't even need to make a BadUSB, maybe while you were turned away from your PC, someone at high-school, college, or the library, inserted a USB switchblade like the Rubber Ducky into your USB port for... oh... about 3 to 5 seconds should be long enough to do the trick if they wrote their scripts correctly... and infected you with something that way,

...or maybe you used a Bluetooth device with your PC but the device was infected with a worm,

...or maybe you downloaded an illegal copy of something that had been modified to include extra software that got injected into the executable,

...or maybe you were just feeling tired while reading a Discord chat and started to doze off and accidentally clicked to download something in your drowsiness or as your head began to fall for a bit in your drowsiness ...then later you see it in your downloads folder and think that it's a legitimate program that you forgot about,

...or maybe you had all scripts turned on in your browser (not using NoScript) or "don't ask me before downloading" set in the permissions (Mozilla did a bad recently by automatically switching people's permissions from "Ask every time" to "don't ask before downloading" automatically during an update) and through one of these delivery methods got hit by a drive-by-download, which placed the malware in your downloads folder, looking like a legitimate program (basically don't ever trust any programs in the downloads folder unless you're 100% sure that you downloaded them yourself because it's a folder that is vulnerable to drive-by-downloads)


...just to name a few mistakes that someone could have easily made, which would get malware onto their system that either is already there or allows propagation of further malware downloads via installing auto-clicker malware.


:seewhatyoudid:


1. I don't run strange applications.
2. I don't download random internet stuff
3. I Don't have a nephew or anyone else who does games in my family
4. See 3
5. I Don't go to conventions
6. School computers were in the lab, secured under lock and key, I never used my own computer equipment at school or anywhere else
6. I Don't use untrusted hardware
7. See 6
8. I Don't use Bluetooth
9. I Don't use pirated programs

10. I could have gotten tired, or emotionally compromised, though it's unlikely.
11. Windows Defender SmartScreen is enabled

That eliminates all of your mistakes, at least the ones you listed.
最后由 Kerry 编辑于; 2022 年 11 月 18 日 下午 6:04
Kerry 2022 年 11 月 18 日 下午 5:51 
...or maybe someone nearby used a packet-sniffer to steal your cookies,

...or maybe when you were browsing to some site to download something like Audacity or Spotify, or maybe some drawing program, some ads might have come up on the download page that made themselves look like the download button but what clicking the ad actually caused you to download was a keylogger or remote access trojan instead of what you were after - and if the malware author was clever enough, they would have made sure their malware also installed the software that you were actually trying to download (legitimately) so that you wouldn't suspect anything after the installation of both the legitimate program that you were after AND the malware was complete,

...or maybe a third-party installed it while you were using a TeamViewer login or some other remote-desktop session, depending on the software that you use, you don't even need to necessarily give them authorization or consent if the software is already running with administrative privileges and automatically accepts remote access sessions (TeamViewer used to have an issue where people could break into sessions that they hadn't even been told about due to vulnerabilities in the parent company's service),

引用自 Satoru
Im not sure why everyone is trying to convince the OP when its pretty obvious the OP doesn't actually understand anything at all. And wants to blame 'everyone else' for their own phishing compromise and thinks "yes lets ban the most popular communications program off of steam" as opposed to "how can I educate myself to not fall for phishing attacks"
Based off of what they've written, I'm not even sure that the attack vector that they got hit by was, in fact, actually Discord. Someone can compromise a system in a variety of other ways and then begin compromising accounts which are accessed by that system. All it really takes is a remote access trojan and they can start logging everything you do that they might consider worth hijacking.

引用自 Kerry Freeman
...
Explain how I got hacked then, despite following every basic cybersecurity rule in the book.
Hey, which book did you follow, btw? :yondercat:

引用自 Kerry Freeman
...
#:~:text=But%20the%20greatest%20percentage%20of%20the%20malware%20we%20found%20have%20a%20focus%20on%20credential%20and%20personal%20information%20theft%2C%20a%20wide%20variety%20of%20stealer%20malware%20as%20well%20as%20more%20versatile%20RATs.

#:~:text=Like%20any%20developer,nearby%20in%20gameplay%3A
...
I don't know if you're using a browser that jumps to text like that, but mine doesn't.

引用自 Leonardo Da Pinchi
...
There's a saying in cybersecurity. you can make the most flawless system and the world will provide a better idiot.
That's true, however, people shouldn't kid themselves... they ain't making even close to flawless systems.

Even the software & OSes with the best protections are just filled with zero-days that are yet to be discovered; some of which are extremely complex and will probably only be discovered by A.I.s and others are surprisingly simple.

Now, I can't know for sure about undiscovered zero-day vulnerabilities but past events do, to some extent, predict future events, and there's still quirks to computers that aren't very well known, such as the interference that can be caused by cosmic rays (not exactly hacker-stuff but still - and in theory it could be if someone could control those rays & have an awareness of what they were hitting in the hardware)

引用自 Kerry Freeman
...
I did none of those things. So again, explain how my first account got stolen.
Considering that we're not going to know for sure, this is probably as good of an explanation as any :
https://www.youtube.com/watch?v=AaZ_RSt0KP8
...obviously, that's not how an account gets stolen but this video is also making guesses about several anomalous events that have happened in computing.


:redcircle: :ycircle: :gcircle: :bluecircle: :pcircle:

I don't download random programs or use third-party remote access software.

Thank you for trying to help me out here.
Boblin the Goblin 2022 年 11 月 18 日 下午 5:55 
引用自 Kerry Freeman
...or maybe someone nearby used a packet-sniffer to steal your cookies,

...or maybe when you were browsing to some site to download something like Audacity or Spotify, or maybe some drawing program, some ads might have come up on the download page that made themselves look like the download button but what clicking the ad actually caused you to download was a keylogger or remote access trojan instead of what you were after - and if the malware author was clever enough, they would have made sure their malware also installed the software that you were actually trying to download (legitimately) so that you wouldn't suspect anything after the installation of both the legitimate program that you were after AND the malware was complete,

...or maybe a third-party installed it while you were using a TeamViewer login or some other remote-desktop session, depending on the software that you use, you don't even need to necessarily give them authorization or consent if the software is already running with administrative privileges and automatically accepts remote access sessions (TeamViewer used to have an issue where people could break into sessions that they hadn't even been told about due to vulnerabilities in the parent company's service),


Based off of what they've written, I'm not even sure that the attack vector that they got hit by was, in fact, actually Discord. Someone can compromise a system in a variety of other ways and then begin compromising accounts which are accessed by that system. All it really takes is a remote access trojan and they can start logging everything you do that they might consider worth hijacking.


Hey, which book did you follow, btw? :yondercat:


I don't know if you're using a browser that jumps to text like that, but mine doesn't.


That's true, however, people shouldn't kid themselves... they ain't making even close to flawless systems.

Even the software & OSes with the best protections are just filled with zero-days that are yet to be discovered; some of which are extremely complex and will probably only be discovered by A.I.s and others are surprisingly simple.

Now, I can't know for sure about undiscovered zero-day vulnerabilities but past events do, to some extent, predict future events, and there's still quirks to computers that aren't very well known, such as the interference that can be caused by cosmic rays (not exactly hacker-stuff but still - and in theory it could be if someone could control those rays & have an awareness of what they were hitting in the hardware)


Considering that we're not going to know for sure, this is probably as good of an explanation as any :
https://www.youtube.com/watch?v=AaZ_RSt0KP8
...obviously, that's not how an account gets stolen but this video is also making guesses about several anomalous events that have happened in computing.


:redcircle: :ycircle: :gcircle: :bluecircle: :pcircle:

I don't download random programs or use third-party remote access software.

Thank you for trying to help me out here.


Dude, you also thought you were under a hacker attack by your ISP.
Kerry 2022 年 11 月 18 日 下午 5:57 
引用自 KittenGrindr
引用自 Kerry Freeman

I don't download random programs or use third-party remote access software.

Thank you for trying to help me out here.


Dude, you also thought you were under a hacker attack by your ISP.

No, I thought someone AT my ISP was attempting to hack me. Big difference.

I notified them, and they took care of it.
最后由 Kerry 编辑于; 2022 年 11 月 18 日 下午 6:01
Kiddiec͕̤̱͋̿͑͠at 🃏 2022 年 11 月 18 日 下午 6:04 
引用自 Kerry Freeman
Remove all Discord CDN links

Pretty sure that nowhere on Steam does Valve endorse or encourage the use of Discord
(aside from their lack of maintenance on Steam chat, giving people incentive to find something that functions better)
and even if they implemented a policy that no Discord links were allowed on the platform, any developers or companies who prefer to use third-party services ...would still just use third-party serviced; they just wouldn't link them here but users would still find their way to them.

...
...or maybe you just let your nephew use your computer and he installed "GTA 5M" on his own,
or maybe it was your gamer grandma or grandpa - whoever you've been letting use your machine, and you didn't monitor their activity to make sure that they didn't get your machine infected - or here's an idea... just don't let them use your laptop and tell them to get their own,

...then again, maybe you did tell them to get their own and they used it anyways, without your permission, while you were asleep, or at the store, or at school, or at work or something,
...
引用自 Kerry Freeman
...
3. I Don't have a nephew or anyone else who does games in my family
4. See 3
...
They don't have to do games. They just have to use your computer.
Malware comes from places other than games.

So, unless you're telling me that you don't have family, or friends, or anyone in the physical world who knows about your computer, then the option / possibility is still present.

引用自 Kerry Freeman
...
5. I Don't go to conventions
...
BadUSB doesn't have to come from a convention.
Literally any USB that has been formatted to be one will still work in the same manner.

引用自 Kerry Freeman
...
6. I Don't use untrusted hardware
7. See 6
...
Well, you still could have been betrayed by hardware or software that you DID trust but didn't realize was compromised.

引用自 Kerry Freeman
... 9. I Don't use pirated programs ...
That's what everyone says. :coconutlaugh:

引用自 Kerry Freeman
...
11. Windows Defender SmartScreen is enabled
...
And you ACTUALLY think that's a complete and foolproof, all encompassing, solution to drive-by-downloads and cross-site-scripting (XSS) attacks? *lol*
Well, that's probably the vector where you're most vulnerable then if you actually think that Defender & SmartScreen are going to protect you from everything.

By the way, earlier you claimed that Discord only filters things based on reports - well guess what...?
So does SmartScreen :
https://www.google.com/search?q=SmartScreen
引用自 Microsoft
"
How can SmartScreen help protect me in Microsoft Edge?
https://support.microsoft.com › en-us › microsoft-edge
Screening downloads: SmartScreen checks your downloads against a list of reported malicious software sites and programs known to be unsafe."


:redcircle: :ycircle: :gcircle: :bluecircle: :pcircle:
Kerry 2022 年 11 月 18 日 下午 6:08 
引用自 Kerry Freeman
Remove all Discord CDN links

Pretty sure that nowhere on Steam does Valve endorse or encourage the use of Discord
(aside from their lack of maintenance on Steam chat, giving people incentive to find something that functions better)
and even if they implemented a policy that no Discord links were allowed on the platform, any developers or companies who prefer to use third-party services ...would still just use third-party serviced; they just wouldn't link them here but users would still find their way to them.

...
...or maybe you just let your nephew use your computer and he installed "GTA 5M" on his own,
or maybe it was your gamer grandma or grandpa - whoever you've been letting use your machine, and you didn't monitor their activity to make sure that they didn't get your machine infected - or here's an idea... just don't let them use your laptop and tell them to get their own,

...then again, maybe you did tell them to get their own and they used it anyways, without your permission, while you were asleep, or at the store, or at school, or at work or something,
...
引用自 Kerry Freeman
...
3. I Don't have a nephew or anyone else who does games in my family
4. See 3
...
They don't have to do games. They just have to use your computer.
Malware comes from places other than games.

So, unless you're telling me that you don't have family, or friends, or anyone in the physical world who knows about your computer, then the option / possibility is still present.

引用自 Kerry Freeman
...
5. I Don't go to conventions
...
BadUSB doesn't have to come from a convention.
Literally any USB that has been formatted to be one will still work in the same manner.

引用自 Kerry Freeman
...
6. I Don't use untrusted hardware
7. See 6
...
Well, you still could have been betrayed by hardware or software that you DID trust but didn't realize was compromised.

引用自 Kerry Freeman
... 9. I Don't use pirated programs ...
That's what everyone says. :coconutlaugh:

引用自 Kerry Freeman
...
11. Windows Defender SmartScreen is enabled
...
And you ACTUALLY think that's a complete and foolproof, all encompassing, solution to drive-by-downloads and cross-site-scripting (XSS) attacks? *lol*
Well, that's probably the vector where you're most vulnerable then if you actually think that Defender & SmartScreen are going to protect you from everything.

By the way, earlier you claimed that Discord only filters things based on reports - well guess what...?
So does SmartScreen :
https://www.google.com/search?q=SmartScreen
引用自 Microsoft
"
How can SmartScreen help protect me in Microsoft Edge?
https://support.microsoft.com › en-us › microsoft-edge
Screening downloads: SmartScreen checks your downloads against a list of reported malicious software sites and programs known to be unsafe."


:redcircle: :ycircle: :gcircle: :bluecircle: :pcircle:

My points are:

1. Nobody uses my computer terminal but me.
2. See 1.
3. I don't use strange USBs. I use my own - and they all come from a trusted vendor
4. I don't use strange hardware, all my hardware comes from a trusted vendor
5. I don't use pirated programs
6. I don't believe it's complete and foolproof. I do have other antimalware - Avast.

Unauthorized remote access could have happened, but as it was unauthorized, I neither knew about it, nor did I give permission - hence the term unauthorized.
最后由 Kerry 编辑于; 2022 年 11 月 18 日 下午 6:12
Kiddiec͕̤̱͋̿͑͠at 🃏 2022 年 11 月 18 日 下午 6:20 
引用自 Kerry Freeman
... I don't download random programs or use third-party remote access software. ...
The whole point of "remote access" ...is that a system (such as yours) is accessed remotely.

So you don't have to use remote access, you just have to be running a program which can facilitate it or have a setting in the OS turned on which allows it to occur.

If you're not using such software (as far as you're aware) then you're probably fine on that front but it's still something that might be worth looking into, in part because Microsoft / Windows has several settings configured by default in ways that are not conducive to user security.

引用自 Kerry Freeman
...
1. Nobody uses my computer terminal but me.
...
...that you know of.

引用自 Kerry Freeman
...
3. I don't use strange USBs. I use my own - and they all come from a trusted vendor
4. I don't use strange hardware, all my hardware comes from a trusted vendor
...
...which could still have vulnerabilities of its own or get compromised at some point between retail & your usage of it with your computer, especially if it has wireless & internet capabilities & you've been using either of them. Sadly that's just how the world works. It's a low-probability that this is an attack vector that would result in your gaming accounts getting stolen but it's still a possibility.

引用自 Kerry Freeman
...
6. I don't believe it's complete and foolproof. I do have other antimalware. I use Avast.
Just as a scanner or as real-time anti-virus? If it's just a scanner then you need to tell it to manually scan everything that you download or it's not getting scanned & also if it's just the scanner then it still will do zero to protect you against drive-by-downloads & XSS.

Consider using NoScript in order to block most scripts by default (mainstream ones such as Google, & Youtube are turned on by default) and get a menu that lets you selectively enable & disable scripts from specific domains & vendors as you choose.

引用自 Kerry Freeman
引用自 AmsterdamHeavy
...
Again, reading comprehension...the silent killer.

I have been using Steam since the outset. I have been using Discord since the outset.

I have NEVER been stupid enough to give my credentials away or to click on links that say they are going to give me a gazillion steambucks, either....or magic GTA5 applications from god knows who.

Here's the thing... nor have I.
Presuming that you're correct & never misclick, & also aren't sharing your PC with others (as you claim you aren't), & you got your own laptop / desktop, you might want to make sure your room is getting locked properly and maybe get a video security system for your room, just to be sure that people aren't installing malware on your computer then because SOMEONE had to accept those downloads and run the executable files or scripts in order for that to happen.

...or you could just start by trying to up your software security first by making sure that settings are properly locked down, you're blocking potentially malicious scripts with AdBlock & NoScript, etc. and being careful what you download / run.


:seewhatyoudid:
最后由 Kiddiec͕̤̱͋̿͑͠at 🃏 编辑于; 2022 年 11 月 18 日 下午 6:24
Kerry 2022 年 11 月 18 日 下午 7:09 
引用自 Kerry Freeman
... I don't download random programs or use third-party remote access software. ...
The whole point of "remote access" ...is that a system (such as yours) is accessed remotely.

So you don't have to use remote access, you just have to be running a program which can facilitate it or have a setting in the OS turned on which allows it to occur.

If you're not using such software (as far as you're aware) then you're probably fine on that front but it's still something that might be worth looking into, in part because Microsoft / Windows has several settings configured by default in ways that are not conducive to user security.

引用自 Kerry Freeman
...
1. Nobody uses my computer terminal but me.
...
...that you know of.

引用自 Kerry Freeman
...
3. I don't use strange USBs. I use my own - and they all come from a trusted vendor
4. I don't use strange hardware, all my hardware comes from a trusted vendor
...
...which could still have vulnerabilities of its own or get compromised at some point between retail & your usage of it with your computer, especially if it has wireless & internet capabilities & you've been using either of them. Sadly that's just how the world works. It's a low-probability that this is an attack vector that would result in your gaming accounts getting stolen but it's still a possibility.

引用自 Kerry Freeman
...
6. I don't believe it's complete and foolproof. I do have other antimalware. I use Avast.
Just as a scanner or as real-time anti-virus? If it's just a scanner then you need to tell it to manually scan everything that you download or it's not getting scanned & also if it's just the scanner then it still will do zero to protect you against drive-by-downloads & XSS.

Consider using NoScript in order to block most scripts by default (mainstream ones such as Google, & Youtube are turned on by default) and get a menu that lets you selectively enable & disable scripts from specific domains & vendors as you choose.

引用自 Kerry Freeman

Here's the thing... nor have I.
Presuming that you're correct & never misclick, & also aren't sharing your PC with others (as you claim you aren't), & you got your own laptop / desktop, you might want to make sure your room is getting locked properly and maybe get a video security system for your room, just to be sure that people aren't installing malware on your computer then because SOMEONE had to accept those downloads and run the executable files or scripts in order for that to happen.

...or you could just start by trying to up your software security first by making sure that settings are properly locked down, you're blocking potentially malicious scripts with AdBlock & NoScript, etc. and being careful what you download / run.


:seewhatyoudid:

1. I've locked out remote access by any and all personnel. They'd have to be on site to do anything malicious.

2. I KNOW nobody uses my computer but me. My house is locked down and secured by recording cameras, inside and out. There's only two people in the house other than me, and that's my mother (who doesn't know the first thing about computers) and my landlord (who fixes 'em.)

3. All my hardware comes directly from the manufacturer through a vendor. None of it is "used". It's then assembled into a PC on-site.

4. I use Avast as a real-time anti-malware protection agent.

5. My mother doesn't touch my PC. My landlord does repairs on it when things need to be replaced and maintenance (compressed air blowouts, etcetera) when things get dusty or dirty.

6. I trust my family and my landlord. My settings are locked down and I'm extremely careful what I download and run. I'm very thorough in these matters.
最后由 Kerry 编辑于; 2022 年 11 月 18 日 下午 7:10
Boblin the Goblin 2022 年 11 月 18 日 下午 8:21 
引用自 Kerry Freeman
引用自 KittenGrindr


Dude, you also thought you were under a hacker attack by your ISP.

No, I thought someone AT my ISP was attempting to hack me. Big difference.

I notified them, and they took care of it.


As in they made a note because nothing was actually happening.
Kerry 2022 年 11 月 18 日 下午 9:41 
引用自 KittenGrindr
引用自 Kerry Freeman

No, I thought someone AT my ISP was attempting to hack me. Big difference.

I notified them, and they took care of it.


As in they made a note because nothing was actually happening.

Can't be sure of that.
Lily McFluffy Butt 2022 年 11 月 19 日 上午 2:55 
引用自 Kerry Freeman
4. I use Avast as a real-time anti-malware protection agent.

Oh... oh no. As someone who used to use Avast as my primary antivirus, I beg you to stop using it, it sucks. Use Malwarebytes, please. I had far better luck with that than Avast.

Do you know what Malwarebytes found on my computer that Avast failed to find? A ♥♥♥♥♥♥♥ trojan.
最后由 Lily McFluffy Butt 编辑于; 2022 年 11 月 19 日 上午 3:53
< >
正在显示第 571 - 585 条,共 599 条留言
每页显示数: 1530 50

发帖日期: 2022 年 11 月 16 日 下午 1:32
回复数: 599