+ Reply to Thread
Results 1 to 15 of 15
  1. #1
    ΜΟΛΩΝ ΛΑΒΕ no1_vern's Avatar
    Join Date
    Apr 2002
    Location
    Albany, Ga.
    Posts
    18,479

    Exclamation Disable JAVA Now - 0-day exploit hits web

     
    Disable Java NOW, users told, as 0-day exploit hits web • The Register

    All operating systems, browsers vulnerable
    By Neil McAllister in San Francisco

    Posted in Security, 27th August 2012 23:42 GMT

    A new browser-based exploit for a Java vulnerability that allows attackers to execute arbitrary code on client systems has been spotted in the wild – and because of Oracle's Java patch schedule, it may be some time before a fix becomes widely available.

    The vulnerability is present in the Java Runtime Environment (JRE) version 1.7 or later, Atif Mushtaq of security firm FireEye reported on Sunday, while PCs with Java versions 1.6 or earlier installed are not at risk.

    The vulnerability allows attackers to use a custom web page to force systems to download and run an arbitrary payload – for example, a keylogger or some other type of malware. The payload does not need to be a Java app itself.

    In the form in which it was discovered, the exploit only works on Windows machines, because the payload that it downloads is a Windows executable. But the hackers behind the Metasploit penetration testing software say they have studied the exploit and found that it could just as easily be used to attack machines running Linux or Mac OS X, given the appropriate payload.
    Disabling Java immediately is strongly encouraged!

    In Firefox: Press Firefox button -> Add-ons, go to Plugins and click the "Disable" button next to anything named "Java".
    In Chrome: Type in: "chrome://plugins/" into the address bar (no speech marks). Scroll down to Java and click disable.
    In Opera: Type in "opera: plugins" into the address bar (no speech marks). Scroll down to:
    Java(TM) Platform <click on> Disable.
    Java Deployment Toolkit <click on> Disable.

    EDIT:

    I do not have to disable javascript, just JAVA.
    Last edited by no1_vern; August 28th, 2012 at 12:02 PM.
    They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.

    TechIMO Folding@home Team #111 - Crunching for the cure!
    dulce bellum inexpertis

  2. #2
    PC Upgrade Procrastinator ShyguyXPC's Avatar
    Join Date
    Sep 2004
    Location
    Minnesota
    Posts
    17,361
    good for me, seems I never reinstalled Java in the form of Plugins or addons for Chrome or FF, looked and its not present.


    looked through task manager for anything Java or Oracle related, nothing, short of going through the registry, looks like i never reinstalled it after my OS reinstall a few months ago.



    Another related article I just saw over at XPC posted by their news bot.

    Unpatched Java vulnerability exploited in targeted attacks, researchers say
    Last edited by ShyguyXPC; August 28th, 2012 at 12:10 PM.
    i7 940//Corsair H60//EVGA X58 SLI LE//6GB Corsair Vengeance 1600MHz//2x EVGA GTX 560 Ti FPB SLI//NZXT Hale82 850W//CM 690 II Advanced//Win7 64//WD 74GB V-raptor, 750GB Black, 1.5TB Green

    TechIMO Folding@home Team #111 - Crunching for the cure!

  3. #3
    Super Stealthy Moderator RicheemxX's Avatar
    Join Date
    Jan 2003
    Location
    Outside the box
    Posts
    8,489
    Blog Entries
    4
    Here is a quick easy detection site to see if you have java enabled or not

    Is Java Exploitable? powered by Rapid7

    I had it running, they still use it on a few sites I visit so I had to reinstall it after the last exploit popped up.

    Most places say disable it, I'm just going to go ahead and remove it for now. Oracle is usually pretty quick on updates so if you need it down the road you can always re-install it once they get it patched.

    BTW - JavaScript and JAVA are two entirely different things (just sayin )

    TechIMO Folding@home Team #111 - Crunching for the cure!
    “Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”

  4. #4
    PC Upgrade Procrastinator ShyguyXPC's Avatar
    Join Date
    Sep 2004
    Location
    Minnesota
    Posts
    17,361
    yep, disabled on my end, and not installed.

    Thanks for the link Rich, will add it to my FB postings of this, for those that even read them. LOL
    i7 940//Corsair H60//EVGA X58 SLI LE//6GB Corsair Vengeance 1600MHz//2x EVGA GTX 560 Ti FPB SLI//NZXT Hale82 850W//CM 690 II Advanced//Win7 64//WD 74GB V-raptor, 750GB Black, 1.5TB Green

    TechIMO Folding@home Team #111 - Crunching for the cure!

  5. #5
    Super Stealthy Moderator RicheemxX's Avatar
    Join Date
    Jan 2003
    Location
    Outside the box
    Posts
    8,489
    Blog Entries
    4
    You can go directly to the java site as well How do I test whether Java is working on my computer? - but that only tells you if its working and not if its the affected version.

    I guess Oracle's next update isn't until Oct so unless they release an emergency patch it might be a bit of a wait. Guess I won't be playing any browser based java games for now
    Last edited by RicheemxX; August 28th, 2012 at 01:53 PM.

    TechIMO Folding@home Team #111 - Crunching for the cure!
    “Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”

  6. #6
    Millwright stroyal's Avatar
    Join Date
    Dec 2002
    Location
    New Hampshire
    Posts
    8,059
    From what I heard, Oracle only updates 3 times a year, and the next is October, as Rich posted.
    Hard Sayin Not Knowin

  7. #7
    Millwright stroyal's Avatar
    Join Date
    Dec 2002
    Location
    New Hampshire
    Posts
    8,059
    Probably a stupid question, but one of my 7 machines, had Java in "Add and Remove Programs".

    I removed it, but was it the same thing??
    Last edited by stroyal; August 31st, 2012 at 12:13 AM.
    Hard Sayin Not Knowin

  8. #8
    Super Stealthy Moderator RicheemxX's Avatar
    Join Date
    Jan 2003
    Location
    Outside the box
    Posts
    8,489
    Blog Entries
    4
    Yeah Java is added as a program in the add-remove box. If you uninstalled it then as with any other program it should be gone. That is what I did for now as I couldn't get it to turn off in IE and figured since it's disabled I might as well not even have it on the computer anymore.

    JavaSript, which is often confused with being part of Java, really has nothing to do with it. JavaScript is a markup language that is found in HTML and runs from your browser. Java is a stand alone programing language that has to run from within the java application.

    TechIMO Folding@home Team #111 - Crunching for the cure!
    “Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”

  9. #9
    Millwright stroyal's Avatar
    Join Date
    Dec 2002
    Location
    New Hampshire
    Posts
    8,059
    So the one in Add and Remove programs, was for IE.

    I was surprised, none of my XP machines, had java anyplace, and My win7 laptop had it in both places.
    Ubuntu was clean also.

    I knew Java script was different, but I can't say I know much more about either.
    Hard Sayin Not Knowin

  10. #10
    Super Stealthy Moderator RicheemxX's Avatar
    Join Date
    Jan 2003
    Location
    Outside the box
    Posts
    8,489
    Blog Entries
    4
    The java program is for the entire pc, it doesn't matter which browser you are using it opens up the program itself. So uninstalling it removes it as an option for everything. But FF, Chrome ect makes it easy (or easier) to turn it off or on. For me IE was the only one making it a PITA.

    TechIMO Folding@home Team #111 - Crunching for the cure!
    “Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”

  11. #11
    Ultimate Member CERuppel's Avatar
    Join Date
    Oct 2001
    Location
    Michigan, USA
    Posts
    1,419
    I just saw this?!?

    Man, those must have been some goooood meds...

    Thank you, Vern.

    PS: Firefox Add-On Updater (link off of the Add-Ons settings page) immediately offered me a "New" version of Java... I know I got the script installed, and I had just un-installed Java, so I thought "OK, just need to restart and everything will be nice". I am more out of touch than I knew, because of course Firefox is still offering me a "New" Java... Just sort of FYI, and wanted to know if anyone else had noticed this.

  12. #12
    Super Stealthy Moderator RicheemxX's Avatar
    Join Date
    Jan 2003
    Location
    Outside the box
    Posts
    8,489
    Blog Entries
    4
    Looks like they released a new patch today, now sure how I missed that news
    Oracle patches Java 7 vulnerability | MacFixIt - CNET Reviews

    TechIMO Folding@home Team #111 - Crunching for the cure!
    “Because The People Who Are Crazy Enough To Think They Can Change The World, Are The Ones Who Do.”

  13. #13
    Millwright stroyal's Avatar
    Join Date
    Dec 2002
    Location
    New Hampshire
    Posts
    8,059
    They deviated from their schedule?

    I guess I'll wait till I need it.
    Hard Sayin Not Knowin

  14. #14
    Millwright stroyal's Avatar
    Join Date
    Dec 2002
    Location
    New Hampshire
    Posts
    8,059
    There are 4 Ubuntu updates with Java in the name.
    2 are NetX, and the other 2 are web browser plugins.
    Hard Sayin Not Knowin

  15. #15
    I Void Warranties KarmaKiller's Avatar
    Join Date
    Feb 2007
    Location
    Springfield
    Posts
    13,484
    Blog Entries
    5
    They released a patch to fix this, but the patch already has been picked apart and they still left some gaping security holes in it.. =\
    Here we go again: Critical flaw found in just-patched Java • The Register
    Q6600@4Ghz | i7 920@4.4Ghz |E6320@3.5Ghz
    FAQ's ~ Team Stats
    My PC

    TechIMO Folding@home Team #111 - Crunching for the cure!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Java.ByteVerify.exploit -hidden
    By sevenal in forum Technical Support
    Replies: 2
    Last Post: January 30th, 2011, 02:18 PM
  2. Windows Zero-Day Exploit - Patch now!
    By vass0922 in forum Security and Privacy Issues
    Replies: 0
    Last Post: October 23rd, 2008, 08:11 PM
  3. Twister hits AFA, once a day
    By Beemer in forum IMO Community
    Replies: 0
    Last Post: April 11th, 2006, 09:21 PM
  4. Bomb hits Green Zone second day in a row
    By pickel in forum IMO Community
    Replies: 40
    Last Post: December 16th, 2004, 08:45 PM
  5. disable scripting and java applet
    By Howard I. No in forum General Tech Discussion
    Replies: 4
    Last Post: September 29th, 2002, 10:17 AM

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Recommended Sites: ResellerRatings Store Reviews