Technical Discussion
  >> Security Related Issues


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | 3 | 4 | (show all)   Print Thread
Standard User bobble_bob
(experienced) Sun 13-Jan-13 12:00:37
Print Post

Re: Java7 zero-day vunerability


[re: Zadeks] [link to this post]
 
Out of curiosity, how would you put malicious code on a legit site? Do they need to hack into the web server to do it or is there other ways around it?
Standard User Zadeks
(experienced) Sun 13-Jan-13 12:05:55
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
- Compromise the advert server, altering the javascript served by the advert
- Exploit a vulnerability in a script running on a webserver (Wordpress, Joomla, etc).
- Exploit a vulnerability in out-of-date software running on a server (Apache, PHP, etc)

Lots of points of entry.
Standard User deleted
(deleted) Sun 13-Jan-13 13:31:50
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
In the latest Sophos newsletter there is an item :- Protect against latest Java zero-day vulnerability right now: Mal/JavaJar-B
http://nakedsecurity.sophos.com/2013/01/10/protect-y... which is in broad agreement with many other warnings.

I have un-installed Java and so far the only downside is not being able to use the usual tbb speedtest. The flash-based test seems just as good but I can't see how to log my results.
I miss the ability to view results as a graph which I find useful to get an over-view of results.

To add to our potential gloom, Sophos has posted this :-

"Vulnerability reported in Foxit PDF plugin for Firefox - how to mitigate it"
http://nakedsecurity.sophos.com/2013/01/11/vulnerabi...

We live in interesting times!


Register (or login) on our website and you will not see this ad.

Standard User bobble_bob
(experienced) Sun 13-Jan-13 15:32:43
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Thing is every piece of software will have vulnerability, but usually they're patched pretty quickly. Java release the next lot of regular fixes on the 15, so probably will have this issue fixed too...until the next time
Standard User deleted
(deleted) Sun 13-Jan-13 21:38:00
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
There is a new Java release available http://www.neowin.net/news/java-runtime-environment-...
Standard User Zadeks
(experienced) Sun 13-Jan-13 22:02:49
Print Post

Re: Java7 zero-day vunerability


[re: bobble_bob] [link to this post]
 
Unlike Chrome, Adobe Flash & Reader, Java doesn't have a built-in automatic background update facility. This is why it is one of the most exploited pieces of software.
Standard User XRaySpeX
(eat-sleep-adslguide) Sun 13-Jan-13 22:27:03
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Just had Java 7 u11 installed. Is that OK?

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 19 Meg WBC
Standard User deleted
(deleted) Sun 13-Jan-13 23:43:31
Print Post

Re: Java7 zero-day vunerability


[re: XRaySpeX] [link to this post]
 
Er, no, apparently not.

http://www.forbes.com/sites/andygreenberg/2013/01/13...

http://uk.reuters.com/article/2013/01/13/java-oracle...
Standard User camieabz
(sensei) Mon 14-Jan-13 01:00:28
Print Post

Re: Java7 zero-day vunerability


[re: deleted] [link to this post]
 
Ahh, the old "I don't use it, so no one should" solution.

~ Camieabz ~

All Connection Data ~ Some plusnet links

mod'er·a'tion n.
Synonyms: temperance, restraint, modesty.
Standard User deleted
(deleted) Mon 14-Jan-13 01:02:51
Print Post

Re: Java7 zero-day vunerability


[re: camieabz] [link to this post]
 
I'm using it though, but it's not safe.
Pages in this thread: 1 | [2] | 3 | 4 | (show all)   Print Thread

Jump to