![]() |
|
|
#1 |
![]() Join Date: Nov 2008
Location: HCM Vietnam
Posts: 2,180 (1.31/day)
Thanks: 323
Thanked 344 Times in 287 Posts
|
New Java Exploit!
I read this on Ars the other day and i thought i would re-post the information here as it seems like a pretty big exploit:
"A previously unknown and currently unpatched security hole in the latest version of the Java software framework is under attack online, according to security researchers and bloggers. Attack code that exploits vulnerability in Java's browser plugin has been added to the Blackhole, Cool, Nuclear Pack, and Redkit exploit kits, according to the Malware Don't Need Coffee blog, prompting its author to say that the bug is being "massively exploited in the wild." Miscreants use these products to turn compromised websites into platforms for silently installing keyloggers and other types of malicious software on the computers of unsuspecting visitors. KrebsOnSecurity reporter Brian Krebs said the curators of both Blackhole and Nuclear Pack have taken to the underweb to boast of the addition to their wares. It's not yet clear how many websites have been outfitted with the exploits. According to researchers at Alienvault Labs, the exploits work against fully patched installations of Java. Attack files are highly obfuscated and are most likely succeeding by bypassing security checks built in to the program. KrebsOnSecurity said the malware authors say the exploits work against all versions of Java 7. Update: Analysis from antivirus provider Kaspersky Lab indicates the exploits are already deployed on a variety of websites. "There appears to be multiple ad networks redirecting to Blackhole sites, amplifying the mass exploitation problem," Kaspersky Lab expert Kurt Baumgartner wrote. "We have seen ads from legitimate sites, especially in the UK, Brazil, and Russia, redirecting to domains hosting the current Blackhole implementation delivering the Java 0day. These sites include weather sites, news sites, and of course, adult sites." People who don't use Java much should once again consider unplugging Java from their browser, while those who don't use it at all may want to uninstall it altogether. The release notes for Java 7 Update 10—the most recent version—say users can disable the program from the browser by accessing the Java Control Panel. KrebsOnSecurity has instructions here for other ways to do this." - Dan Goodin - Jan 10 2013 Source: http://arstechnica.com/security/2013...d-in-the-wild/
__________________
![]() Thanks to BradleyKZN for polishing my sig
“oooooooooooh fire!!! and girls...GIRLS and fire!!!!!!! oooooooooooooh *runz around clapping hands together*” -Marineborn |
|
|
|
|
|
#2 |
|
Knowledgeable Posting Whore
Join Date: Aug 2010
Location: Seattle, WA
Posts: 5,760 (5.79/day)
Thanks: 1,277
Thanked 1,080 Times in 833 Posts
|
and theres my queue to uninstall Java.
__________________
Motocross is not just a sport, it's a lifestyle. ![]() File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1 “We will never know our full potential, unless we push ourselves to find it. -Travis Rice”
|
|
|
|
|
|
#3 |
![]() Join Date: Nov 2008
Location: HCM Vietnam
Posts: 2,180 (1.31/day)
Thanks: 323
Thanked 344 Times in 287 Posts
|
This is the scariest part: "We have seen ads from legitimate sites, especially in the UK, Brazil, and Russia, redirecting to domains hosting the current Blackhole implementation delivering the Java 0day. These sites include weather sites, news sites, and of course, adult sites."
I'm using Chrome and it's quite easy to set up so that you need to click to allow java to run on each site. I haven't uninstalled it yet, but i'm not going to be allowing it to run until an update comes out.
__________________
![]() Thanks to BradleyKZN for polishing my sig
“oooooooooooh fire!!! and girls...GIRLS and fire!!!!!!! oooooooooooooh *runz around clapping hands together*” -Marineborn |
|
|
|
|
|
#4 |
![]() |
a security hole in JAVA NOWAI
__________________
I am not here to be nice, I am not here to be polite BUT I am here to help ...
|
|
|
|
| The Following User Says Thank You to OneMoar For This Useful Post: |
|
|
#5 |
![]() Join Date: Sep 2010
Location: Nonlocal location
Posts: 1,897 (1.91/day)
Thanks: 62
Thanked 822 Times in 525 Posts
|
Wouldn't that be awesome if flash and java go away and never come back and get replaced with something more reliable and less buggy...
__________________
...the young Universe was filled with a hot dense soup of interacting protons, electrons and photons at about 2700ºC. When the protons and electrons joined to form hydrogen atoms, the light was set free |
|
|
|
|
|
#6 | |
![]() Join Date: Feb 2008
Location: Joplin, Mo
Posts: 4,543 (2.38/day)
Thanks: 175
Thanked 691 Times in 557 Posts
|
Quote:
in the last two years I have helped about a dozen friends and family members where, through a Java exploit, their computers were completely locked down, usually with programs that acted like anti-virus and wanted you to purchase their program to remove the virus that it in itself caused. These exploits are very serious and renders a computer useless, I am almost surprised Java hasn't been sued or gotten into some kind of trouble for this. The process to remove this malware is usually quite extensive, and varies from one instance to another.
__________________
A+, N+, S+, MCSE. Heatware STEAM ID Name: furi0nst0rmrage (0s are zeros) M O D E R N||W A R F A R E || 2 || CLUBHOUSE // TEAM “The amount exaltation of the processor cores can brings amazing floating” -sparkle |
|
|
|
|
|
|
#7 | ||
![]() Join Date: Jan 2012
Location: Dover, New Hampshire, USA
Posts: 4,257 (8.86/day)
Thanks: 1,274
Thanked 1,326 Times in 984 Posts
|
Quote:
![]() Quote:
__________________
MyHeat |
||
|
|
|
|
|
#8 | |
|
Fishfaced Nincompoop
Join Date: Feb 2006
Location: Sweden
Posts: 7,882 (2.98/day)
Thanks: 1,076
Thanked 1,445 Times in 1,151 Posts
|
Quote:
|
|
|
|
|
|
|
#9 |
|
"I go fast!1!11!1!"
Join Date: Oct 2008
Location: IA, USA
Posts: 10,575 (6.28/day)
Thanks: 1,755
Thanked 2,596 Times in 1,960 Posts
|
FYI, Update 11 apparently takes care of the vulnerability.
__________________
Golden Rule of Programming: Never assume. try { SteamDownload(); } catch (Steamception ex) { RageQuit(); } |
|
|
|
| The Following User Says Thank You to FordGT90Concept For This Useful Post: |
|
|
#10 |
![]() Join Date: Sep 2010
Location: Nonlocal location
Posts: 1,897 (1.91/day)
Thanks: 62
Thanked 822 Times in 525 Posts
|
I never quite understood the real purpose of Java. There are c/c++, .net and other programming languages. What's up with java? Yes in some cases some applications written on java work faster than others but in many other cases java apps are much slower.
Not sure but I think c/c++ and .net could handle it all.
__________________
...the young Universe was filled with a hot dense soup of interacting protons, electrons and photons at about 2700ºC. When the protons and electrons joined to form hydrogen atoms, the light was set free |
|
|
|
|
|
#11 | |
![]() Join Date: Feb 2008
Location: Joplin, Mo
Posts: 4,543 (2.38/day)
Thanks: 175
Thanked 691 Times in 557 Posts
|
Quote:
I find programming in Java a bit easier than c#. c++ / c# can handle it all.
__________________
A+, N+, S+, MCSE. Heatware STEAM ID Name: furi0nst0rmrage (0s are zeros) M O D E R N||W A R F A R E || 2 || CLUBHOUSE // TEAM “The amount exaltation of the processor cores can brings amazing floating” -sparkle |
|
|
|
|
| The Following User Says Thank You to 3870x2 For This Useful Post: |
|
|
#12 | |
![]() Join Date: Jan 2012
Location: Dover, New Hampshire, USA
Posts: 4,257 (8.86/day)
Thanks: 1,274
Thanked 1,326 Times in 984 Posts
|
Quote:
Java is good if your intent is to hit the largest audience you can. Newer ARM processors have Jazelle as well, which allows java byte code run in hardware as a third execution mode. So it doesn't have to be slow, it's just slow because of how its implemented. Java can be made to run fast and a lot of the time it does. +1: This too.
__________________
MyHeat |
|
|
|
|
|
|
#13 | |
![]() Join Date: Sep 2010
Location: Nonlocal location
Posts: 1,897 (1.91/day)
Thanks: 62
Thanked 822 Times in 525 Posts
|
Quote:
__________________
...the young Universe was filled with a hot dense soup of interacting protons, electrons and photons at about 2700ºC. When the protons and electrons joined to form hydrogen atoms, the light was set free |
|
|
|
|
|
|
#14 |
![]() Join Date: Jan 2009
Location: on top of that big mountain on mars(e Eu)
Posts: 1,419 (0.90/day)
Thanks: 39
Thanked 272 Times in 234 Posts
|
Seeing this now i feel better that i dont use java from quite some time now knowing its weakness for exploits.
|
|
|
|
|
|
#15 |
![]() Join Date: Mar 2010
Location: Moorsoldaten barracks
Posts: 2,183 (1.89/day)
Thanks: 709
Thanked 312 Times in 250 Posts
|
Sadly i have business software that requieres Java
__________________
![]() "Where's Carmack when you need him?" by cadaveca |
|
|
|
|
|
#16 | |
![]() Join Date: Sep 2010
Location: Nonlocal location
Posts: 1,897 (1.91/day)
Thanks: 62
Thanked 822 Times in 525 Posts
|
Quote:
__________________
...the young Universe was filled with a hot dense soup of interacting protons, electrons and photons at about 2700ºC. When the protons and electrons joined to form hydrogen atoms, the light was set free |
|
|
|
|
| The Following User Says Thank You to Drone For This Useful Post: |
|
|
#17 |
![]() |
This is good actually. Holes like this exist for just about everything. They're traded in very tight circles with people highly motivated to keep them secret. If someone gets a hold of one and wants to make a quick buck selling it instead of exploiting it then it's pretty much the end of that exploit. It will get identified and patched.
Honestly the best possible way to root out these long standing exploits in browsers/flash/java is to offer rewards for those exploits. Big ones. |
|
|
|
|
|
#18 |
![]() Join Date: Mar 2010
Location: Moorsoldaten barracks
Posts: 2,183 (1.89/day)
Thanks: 709
Thanked 312 Times in 250 Posts
|
Defender report of earlier today:
containerfile:C:\Users\...\AppData\LocalLow\Sun\Ja va\Deployment\cache\6.0\20\6aee21d4-46ec4b49 file:C:\Users\...\AppData\LocalLow\Sun\Java\Deploy ment\cache\6.0\20\6aee21d4-46ec4b49->h.class file:C:\Users\...\AppData\LocalLow\Sun\Java\Deploy ment\cache\6.0\20\6aee21d4-46ec4b49->r.class file:C:\Users\...\AppData\LocalLow\Sun\Java\Deploy ment\cache\6.0\20\6aee21d4-46ec4b49->van.class file:C:\Users\...\AppData\LocalLow\Sun\Java\Deploy ment\cache\6.0\20\6aee21d4-46ec4b49->zou.class Just now I installed Java update 11
__________________
![]() "Where's Carmack when you need him?" by cadaveca Last edited by erixx; Jan 17, 2013 at 11:00 PM. |
|
|
|
|
|
#19 | |
|
"I go fast!1!11!1!"
Join Date: Oct 2008
Location: IA, USA
Posts: 10,575 (6.28/day)
Thanks: 1,755
Thanked 2,596 Times in 1,960 Posts
|
Quote:
![]() That defies logic.
__________________
Golden Rule of Programming: Never assume. try { SteamDownload(); } catch (Steamception ex) { RageQuit(); } |
|
|
|
|
|
|
#20 |
![]() Join Date: Feb 2009
Location: Toronto
Posts: 151 (0.10/day)
Thanks: 0
Thanked 18 Times in 18 Posts
|
just disable the browser plugin, not remove java from the OS entirely (since obviously minecraft, jdownloader, all kinds of things need java)
how many SITES still use java when they can just make their thing in flash or by now webgl & unity
__________________
AMD Catalyst Driver Profiles List Some profiles for better crossfire scaling in some games OpenGL startup crash fix 1 or fix 2 |
|
|
|
|
|
#21 |
![]() Join Date: Sep 2010
Location: Nonlocal location
Posts: 1,897 (1.91/day)
Thanks: 62
Thanked 822 Times in 525 Posts
|
Malware Posing as Java Update 11
The malicious website has the misspelled message "A newer version of Java is require" in large, red letters.
__________________
...the young Universe was filled with a hot dense soup of interacting protons, electrons and photons at about 2700ºC. When the protons and electrons joined to form hydrogen atoms, the light was set free |
|
|
|
|
|
#22 |
![]() Join Date: Sep 2010
Location: Nonlocal location
Posts: 1,897 (1.91/day)
Thanks: 62
Thanked 822 Times in 525 Posts
|
If anyone cares java is gonna release its cumulative patch. It will arrive February 19.
__________________
...the young Universe was filled with a hot dense soup of interacting protons, electrons and photons at about 2700ºC. When the protons and electrons joined to form hydrogen atoms, the light was set free |
|
|
|
| The Following User Says Thank You to Drone For This Useful Post: |
|
|
#23 | |
![]() Join Date: Sep 2010
Location: Nonlocal location
Posts: 1,897 (1.91/day)
Thanks: 62
Thanked 822 Times in 525 Posts
|
Another Java Zero-Day Found
Quote:
__________________
...the young Universe was filled with a hot dense soup of interacting protons, electrons and photons at about 2700ºC. When the protons and electrons joined to form hydrogen atoms, the light was set free |
|
|
|
|
|
|
#24 |
![]() Join Date: Oct 2007
Location: Chicago
Posts: 4,503 (2.20/day)
Thanks: 1,525
Thanked 1,576 Times in 1,119 Posts
|
Ffs
__________________
“i dont care what consoles have they dont have mouse and keyboard” -crazyeyesreaper
![]() |
|
|
|
|
|
#25 | |
![]() Join Date: Oct 2008
Location: στο άλφα έως ωμέγα
Posts: 3,839 (2.28/day)
Thanks: 2,032
Thanked 1,416 Times in 1,115 Posts
|
Java update to fix two security exploits.
Java SE Downloads Oracle Security Alert for CVE-2013-1493 Quote:
|
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Nvidia Display Driver Service Exploit | skylamer | NVIDIA | 1 | Dec 25, 2012 05:57 PM |
| possible exploit? | Solaris17 | Comments & Feedback | 13 | Mar 15, 2010 11:25 AM |
| Java Runtime Environment 6 Update 13 (New) | Polarman | General Software | 0 | Mar 25, 2009 08:00 PM |
| Vista Exploit | TheMailMan78 | General Software | 3 | Feb 5, 2008 06:10 PM |
| IE Zero Day Exploit | Ice Czar | News | 0 | Apr 24, 2006 11:56 PM |