Technical Discussion
  >> Security Related Issues


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | 3 | 4 | >> (show all)   Print Thread
Standard User deleted
(deleted) Fri 11-Jan-13 12:39:01
Print Post

Java7 zero-day vunerability


[link to this post]
 
Java 7 0day Actively Exploited In The Wild
January 10, 2013
There is a 0day vulnerability (identified flaw, with no patch available) being actively exploited across the Internet in Java. This 0day has already been incorporated into Cool Exploit Kit and Blackhole, in addition to Nuclear Pack and Redkit. Proof of concept code is already publicly available and we expect to see fully functioning exploit code incorporated into even more exploit frameworks within the next few days.

What does this mean to you?
� This vulnerability affects Java 7 versions up to and including the current version of Java, 7u10
� Even if you're only running Java 6, users will be forced to automatically upgrade to version 7 in February of this year. This means further exposure to this vulnerability.
What you can do now to avoid being exploited
� Disable Java entirely
� If you don't need Java, remove it from the system entirely
� Lower and manage desktop privileges with solutions like PowerBroker for Windows
� Scan and detect this vulnerability with Retina Network
Standard User deleted
(deleted) Fri 11-Jan-13 22:55:08
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
(CNN) -- The critical Java vulnerability that is currently under attack was made possible by an incomplete patch Oracle developers issued last year to fix an earlier security bug, a researcher said.

The revelation, made Friday by Adam Gowdiak of Poland-based Security Explorations, is the latest black eye for Oracle's Java software framework which is installed on more than 1 billion PCs, smartphones, and other devices.
Standard User bobble_bob
(experienced) Sun 13-Jan-13 08:00:26
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Firefox disabled mine automatically, will leave it like that until the fix

Im assuming there isnt any malicious code out there yet, just a possibility due to the exploit?


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Sun 13-Jan-13 08:52:25
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
I can't see why you'd make that assumption?
Standard User bobble_bob
(experienced) Sun 13-Jan-13 10:12:59
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Actually yea sorry misread the article
Standard User XRaySpeX
(eat-sleep-adslguide) Sun 13-Jan-13 10:50:05
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Presume the vulnerability would only be exploited at malicious webpages? Eg. not at TBB Speed Test.

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 19 Meg WBC
Standard User Danh_Gbwe
(newbie) Sun 13-Jan-13 11:13:41
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
In reply to a post by bobble_bob:
Firefox disabled mine automatically, will leave it like that until the fix


It's been this way for a long, long time. I can't remember the last time Firefox enabled it without a warning.
Standard User bobble_bob
(experienced) Sun 13-Jan-13 11:34:56
Print Post

Re: Java7 zero-day vunerability


[re: Danh_Gbwe] [link to this post]
 
Mine hasnt been, think it did with version 6 but not with version 7 until now
Standard User bobble_bob
(experienced) Sun 13-Jan-13 11:36:10
Print Post

Re: Java7 zero-day vunerability


[re: XRaySpeX] [link to this post]
 
Not necessarily according to articles ive read as even legit sites could have code injected into them. They will patch it in a few days anyway so best to just be safe until then
Standard User Zadeks
(experienced) Sun 13-Jan-13 11:57:56
Print Post

Re: Java7 zero-day vunerability


[re: XRaySpeX] [link to this post]
 
No, legit sites are compromised all the time. The only way to be safe is to uninstall Java or disable the web plug-in.
Standard User bobble_bob
(experienced) Sun 13-Jan-13 12:00:37
Print Post

Re: Java7 zero-day vunerability


[re: Zadeks] [link to this post]
 
Out of curiosity, how would you put malicious code on a legit site? Do they need to hack into the web server to do it or is there other ways around it?
Standard User Zadeks
(experienced) Sun 13-Jan-13 12:05:55
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
- Compromise the advert server, altering the javascript served by the advert
- Exploit a vulnerability in a script running on a webserver (Wordpress, Joomla, etc).
- Exploit a vulnerability in out-of-date software running on a server (Apache, PHP, etc)

Lots of points of entry.
Standard User deleted
(deleted) Sun 13-Jan-13 13:31:50
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
In the latest Sophos newsletter there is an item :- Protect against latest Java zero-day vulnerability right now: Mal/JavaJar-B
http://nakedsecurity.sophos.com/2013/01/10/protect-y... which is in broad agreement with many other warnings.

I have un-installed Java and so far the only downside is not being able to use the usual tbb speedtest. The flash-based test seems just as good but I can't see how to log my results.
I miss the ability to view results as a graph which I find useful to get an over-view of results.

To add to our potential gloom, Sophos has posted this :-

"Vulnerability reported in Foxit PDF plugin for Firefox - how to mitigate it"
http://nakedsecurity.sophos.com/2013/01/11/vulnerabi...

We live in interesting times!
Standard User bobble_bob
(experienced) Sun 13-Jan-13 15:32:43
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Thing is every piece of software will have vulnerability, but usually they're patched pretty quickly. Java release the next lot of regular fixes on the 15, so probably will have this issue fixed too...until the next time
Standard User deleted
(deleted) Sun 13-Jan-13 21:38:00
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
There is a new Java release available http://www.neowin.net/news/java-runtime-environment-...
Standard User Zadeks
(experienced) Sun 13-Jan-13 22:02:49
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
Unlike Chrome, Adobe Flash & Reader, Java doesn't have a built-in automatic background update facility. This is why it is one of the most exploited pieces of software.
Standard User XRaySpeX
(eat-sleep-adslguide) Sun 13-Jan-13 22:27:03
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Just had Java 7 u11 installed. Is that OK?

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 19 Meg WBC
Standard User deleted
(deleted) Sun 13-Jan-13 23:43:31
Print Post

Re: Java7 zero-day vunerability


[re: XRaySpeX] [link to this post]
 
Er, no, apparently not.

http://www.forbes.com/sites/andygreenberg/2013/01/13...

http://uk.reuters.com/article/2013/01/13/java-oracle...
Standard User camieabz
(sensei) Mon 14-Jan-13 01:00:28
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Ahh, the old "I don't use it, so no one should" solution.

~ Camieabz ~

All Connection Data ~ Some plusnet links

mod'er·a'tion n.
Synonyms: temperance, restraint, modesty.
Standard User deleted
(deleted) Mon 14-Jan-13 01:02:51
Print Post

Re: Java7 zero-day vunerability


[re: camieabz] [link to this post]
 
I'm using it though, but it's not safe.
Standard User camieabz
(sensei) Mon 14-Jan-13 14:16:29
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Not you; the first article author.

~ Camieabz ~

All Connection Data ~ Some plusnet links

mod'er·a'tion n.
Synonyms: temperance, restraint, modesty.
Standard User bobble_bob
(experienced) Mon 14-Jan-13 17:18:45
Print Post

Re: Java7 zero-day vunerability


[re: Zadeks] [link to this post]
 
It automatically checks for updates tho and tells you about them. Might not install automatically, but you do know when new versions are out. (although it only checks weekly i think)
Standard User Zadeks
(experienced) Mon 14-Jan-13 17:20:21
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
Most people ignore the update icons in the Windows tray. Totally useless feature.
Standard User techguy
(committed) Mon 14-Jan-13 17:27:41
Print Post

Re: Java7 zero-day vunerability


[re: Zadeks] [link to this post]
 
All software will have a bug or two, the problem here is that Oracle takes a while to fix them.


Best advice is, as always, be careful where you surf.

Virgin (ADSL) => Namesco => Newnet => O2 => Plusnet => Zen => Newnet => Zen => Freeola => Vivaciti (using O2 Wholesale DSL) => Xilo (C&W Wholesale) => Xilo (O2 Wholesale)
Note: I don't lay turf for anyone. astro or otherwise, all views and opinions expressed are my own based on experience.

Edited by techguy (Mon 14-Jan-13 17:30:10)

Standard User Zadeks
(experienced) Mon 14-Jan-13 17:31:06
Print Post

Re: Java7 zero-day vunerability


[re: techguy] [link to this post]
 
Thanks for stating the obvious. Other companies such as Microsoft, Google & Adobe have done the right thing by enabling automatic background updates. Java doesn't place nice with UAC, and favours a user account with full admin rights (XP style). It's such a mess.
Standard User deleted
(deleted) Mon 14-Jan-13 22:12:08
Print Post

Re: Java7 zero-day vunerability


[re: Zadeks] [link to this post]
 
A mess indeed when you get the US Dept for Homeland Security coming out with warning that even after the latest patch Java is very risky.

Just had this posting from ZDnet :-
"Homeland Security warns Java still poses risks after security fix"

"some security experts are warning that the new software -- Java 7 (Update 11), which was released on Sunday -- may not actually protect against hackers attempting to remotely execute code on user machines."

http://www.zdnet.com/homeland-security-warns-java-st...

I'm going to try to carry on without Java even though I found today I could not access parts of some sites like for example DHL where I found could not track an order. Not a big problem.
Standard User gomezz
(eat-sleep-adslguide) Mon 14-Jan-13 22:34:24
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
My only minor irritation is not being able to display the F1 live timing.

O2 Standard (8Mbps LLU)
Standard User Zadeks
(experienced) Tue 15-Jan-13 09:44:18
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Which part of the DHL website requires Java?

Please provide a link.

BTW, if you run Chrome, you can whitelist plug-ins to run on certain websites only.
Standard User deleted
(deleted) Tue 15-Jan-13 10:11:26
Print Post

Re: Java7 zero-day vunerability


[re: Zadeks] [link to this post]
 
Silly me! the problem I thought I had was due to disabled Java SCRIPT.

I do know it is not the same....mea culpa!

Still did not track my order but the goods are not urgent and I ain't going out in this weather
Standard User bobble_bob
(experienced) Tue 05-Feb-13 23:32:33
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Is it possible via some virus/malware or whatever, for disabled java addons to be enabled again without the user knowing?
Standard User Zadeks
(experienced) Mon 11-Feb-13 12:47:01
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
Maybe, but malware enabling disabled add-ons should be the least of your worries. Your system has already been compromised!
Standard User Pipexer
(eat-sleep-adslguide) Mon 11-Feb-13 13:34:27
Print Post

Re: Java7 zero-day vunerability


[re: Zadeks] [link to this post]
 
Indeed.

Zen 8000 Pro
Pages in this thread: 1 | 2 | 3 | 4 | >> (show all)   Print Thread

Jump to