Archive for Java

New Java Exploit In The Wild…. And Flash Isn’t Immune Either

Posted in Commentary with tags , , on March 2, 2013 by itnerd

I’m quickly getting to the point where I want to run my computer without any plug-ins. I say that because of two new developments:

  • A new Java exploit is out there and may currently be used by those who would do bad things. Any browser that has Java v1.6 Update 41 or Java v1.7 Update 15 is vulnerable. Keep in mind that those are the most recent versions of Java. Not good. 
  • There’s a new note on Apple’s support site that informs users that Adobe Flash versions older than 11.6.602.171 have been blocked by Safari’s web plug-in-blocking mechanism. This affects Mac OS X 10.6, OS X Lion, OS X Mountain Lion and the fix is to update to Flash version 11.6.602.171.

Now, I’m not affected by the latest Java vulnerability because I’ve dumped it from my Mac. But the fact that Apple is blocking older versions of Flash says to me that I should do the same to Flash. If only it were that simple. There’s lots of sites that use Flash rather using HTML5. But the good news is that with all the iDevices out there, Flash will become a thing of the past. When that day comes, I will be putting Flash into the trash. And my computer will be more secure because of it.

Apple Laptops Hacked…. Java To Blame Along With The Chinese

Posted in Commentary with tags , , on February 19, 2013 by itnerd

All Things Digital is reporting that computers owned by Apple employees were hacked by the Chinese. What makes this worse is that this group is thought to be responsible for the hack of Facebook recently. And even worse than that, is that Java was used yet again to perpetrate the hack:

Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers,” the company said in a statement to AllThingsD. “The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.

The likely source according to the The Next Web is a popular site for iPhone developers called iPhoneDevSDK. As it stands, the site is infected with the marware that is the source of this hack. Visiting this site is NOT recommended.

As for the link to the Chinese, here’s what the New York Times had to say:

In an article published Monday evening, The New York Times reported that one group of Chinese cyberattackers, which has been tied to a specific military unit of China’s People’s Liberation Army, leveraged the social connections of its targets to send malicious e-mails that eventually allowed them to compromise thousands of organizations, ranging from Coca-Cola to the International Olympic Committee.

Now, if you haven’t got rid of Java from your Mac, or PC, or LINUX box, I would highly recommend doing it now. It is beyond clear that you are unsafe with Java so you would be making yourself very secure by doing so. But if you must have Java on your computer for whatever reason, Oracle has fresh updates of Java for you to download and install. For whatever security that brings you.

 

Facebook Hacked Via Java Flaw…. Time To Change Your Password

Posted in Commentary with tags , , on February 16, 2013 by itnerd

The title sounds alarmist, but these days you never know the extent of any hack. Thus it’s better to be safe than sorry. In any case, The news leaked out yesterday that Facebook was hacked:

“Last month, Facebook Security discovered that our systems had been targeted in a sophisticated attack,” the blog post reads. “We have found no evidence that Facebook user data was compromised. As part of our ongoing investigation, we are working continuously and closely with our own internal engineering teams, with security teams at other companies, and with law enforcement authorities to learn everything we can about the attack, and how to prevent similar incidents in the future.”

Lovely, what makes this scary is the fact that the site was hacked via a Java vulnerability:

The lesson, for those who haven’t heard it several dozen times already: Disable Java in your browser. (Security blogger Brian Krebs offers a useful guide to disabling Java in any browser here.) Oracle has made clear over the last year that it can’t or won’t suss out and patch the endless collection of hackable flaws in its most widespread consumer program. In multiple cases the company has sat on information about a vulnerability in the software for months, allowing attackers to take advantage of the bug to compromise users via invisible browser-based attacks.

For those of you keeping score at home, Twitter was hacked in a similar way not too long ago. You can bet that Oracle is going to get a phone call about this.

Another thing that troubles me is the fact that this happened a month ago, but they’re only letting the world know now. That’s a #fail. I’m a big believer that companies should disclose this sort of thing when they happen for the security of their users. I also believe that if they don’t want to do that on their own, there should be laws that require it with stiff penalties if they don’t. As it stands now, a lot of Facebook users are wondering if any of their personal info has fallen into the hands of evil doers.

Java Disabled On Macs….. Again

Posted in Commentary with tags , on January 31, 2013 by itnerd

The news is all over the internet that Apple has apparently used their anti-marware function in OS X to disable Java again. You might recall that they have done this before when there was a zero day exploit in the popular plug in. I’m guessing Apple knows something that the rest of us don’t because it’s safe to assume that wouldn’t do this for giggles.

I’ve said it before and I’ll say it again. I think it’s time to take the hint. Java is insecure. I’ve ditched it from all my Macs and the only place where I do run it is in my Parallels virtual machines which make up XP, Vista, and Windows 7 flavours. That way if anything gets infected, it’s only going to be on a virtual machine that can be restored to a virgin state and has no data to grab by evil doers.

Take the hint and ditch it, you’ll be better off.

 

I Have Sent Java To The Trash On My Mac

Posted in Commentary with tags , , on January 21, 2013 by itnerd

After all of the security issues with Java including the most recent one which had an out of cycle fix due to the fact that it was very dangerous, I became really wary of having it on my system. That was until I read this:

“This and previous Java vulnerabilities have been widely targeted by attackers, and new Java vulnerabilities are likely to be discovered,” DHS said in an updated alert published on the CERT Web site. “To defend against this and future Java vulnerabilities, consider disabling Java in Web browsers until adequate updates are available.”

Even though I am in Canada, I still pay attention to what DHS has to say. That spooked me into removing it from my system entirely. Now if you’re on a Mac like I am, here are instructions for you which are very simple to run. For PC users, here are instructions for you to work from which are equally as easy.

If you ask me, unless you need to run Java, I would say that you should get rid of it. You’ll be safer without it.

Oracle Patches Java Zero Day Exploit To Make You Safe…. For Now….

Posted in Commentary with tags , , on January 14, 2013 by itnerd

Java users can breath easy…. At least for now. Oracle has released an update to Java that patches the zero day exploit that I’ve previously covered. Users should update to Java 7 Update 11 as soon as they can. Not only does it fix this zero day exploit, but it makes you more secure in a whole host of ways. So if you have Mac, PC,or another platform that runs Java, do what Nike tells you to do. Just do it and upgrade today. Of course, if you don’t need Java, you should disable or uninstall it. That will make you a whole lot safer.

Any bets on how long it will take for the next Java exploit to appear?

Java Has A New Zero Day Exploit….. Disable Java NOW! [UPDATED]

Posted in Commentary with tags , on January 10, 2013 by itnerd

Java is quickly becoming a target for those who want to do evil. A new zero day exploit is in the wild and it’s being used by criminals. It’s documented here. It’s apparently being used for evil as we speak:

The hackers who maintain Blackhole and Nuclear Pack – competing crimeware products that are made to be stitched into hacked sites and use browser flaws to foist malware — say they’ve added a brand new exploit that attacks a previously unknown and currently unpatched security hole in Java.

The curator of Blackhole, a miscreant who uses the nickname “Paunch,” announced yesterday on several Underweb forums that the Java zero-day was a “New Year’s Gift,” to customers who use his exploit kit. Paunch bragged that his was the first to include the powerful offensive weapon, but shortly afterwards the same announcement was made by the maker and seller of Nuclear Pack.

According to both crimeware authors, the vulnerability exists in all versions of Java 7, including the latest — Java 7 Update 10. This information could not be immediately verified, but if you have Java installed, it would be a very good idea to unplug Java from your browser, or uninstall this program entirely if you don’t need it.

Lovely. Seeing as this is the latest in a number of holes in Java, perhaps it’s time to ditch Java completely. It’s becoming clear that Oracle cannot keep Java secure.

UPDATE: MacRumors is reporting that Apple through it’s anti marware application built into OS X is disabling it on Macs with Java installed. So it sounds like Tim Cook and company have made the choice easy for Mac users by not giving them any choice at all.

Java On Macs Starts To Transition From Apple To Oracle

Posted in Commentary with tags , , on October 20, 2012 by itnerd

This week there were two seperate updates to the Apple supplied Java that’s on most Macs. But what was interesting was the fact that the updates actually removed something. If you’re running Lion or Mountain Lion, any versions of Java before version 7 gets removed automatically. If you’re running Snow Leopard, the update will configure Web browsers to not automatically run Java applets.

Now why would Apple do that? Oracle now supplies Mac users with Java. Thus it makes sense for Apple to exit from the responsibility of having to update something it doesn’t make. Therefore if there’s another Flashback Trojan, Apple can always point the finger at Oracle. Interesting strategy. But it doesn’t make OS X any safer. That’s really what matters. It would be really nice if security was the focus rather than optics.

Yet Another New Java Zero Day Exploit Discovered

Posted in Commentary with tags , on September 26, 2012 by itnerd

Clearly, the case for dumping Java is being made with all of these zero day exploits popping up. The latest one goes something like this:

The bug, which was publicly reported on the Full Disclosure security mailing list Tuesday by Adam Gowdiak, the founder and CEO of Polish security firm Security Explorations, can be leveraged to hijack a machine equipped with Java, letting attackers install malware on the system.

Windows PCs and Macs are equally at risk if their users have installed Java, or in the case of OS X, are running 10.6, aka Snow Leopard, or earlier. Snow Leopard was the last edition where Apple bundled Java with the operating system.

All currently-support versions of Java, including Java 5, Java 6 and Java 7, contain the bug.

Well, that’s a #fail. There is a fix coming… We think:

The company also told him that the bug will be patched in a future Java security update, but that it did not name which. The next on Oracle’s quarterly schedule will ship Oct. 16.

The company in question is Oracle who is responsible for Java. One hopes that this fixes things. But seriously. Oracle has to get their stuff together as these security issues are getting sad.

Latest Java Update To Fix Vulnerabilities Has Even More Vulnerabilities….. WTF?

Posted in Commentary with tags , on September 2, 2012 by itnerd

You have to question how seriously Oracle takes security. They had a version of Java that had vulnerabilities that were being actively exploited. They then came out with an update that dealt with that last Thursday. But now it seems that Oracle has new issues with Java:

Security researchers from Poland-based security firm Security Explorations claim to have discovered a vulnerability in the Java 7 security update released Thursday that can be exploited to escape the Java sandbox and execute arbitrary code on the underlying system.

Security Explorations sent a report about the vulnerability to Oracle on Friday together with a proof-of-concept exploit, Adam Gowdiak, the security company’s founder and CEO said Friday via email.

The company doesn’t plan to release any technical details about the vulnerability publicly until Oracle addresses it, Gowdiak said.

This sucks. Given that Oracle had to rush out a patch to fix a major security issue with Java, you’d think they’d make sure that it was actually secure. This whole episode leaves me with the impression that Oracle doesn’t take security in the Java environment seriously. You can also safely bet that whatever issues that do exist in Java that Security Explorations found, the bad guys are looking for as you read this. Not a good thing if you ask me.

So, how can you stay safe? In my case, I actually need Java so I can’t uninstall it. But for the masses, you don’t need Java. Disable it until Oracle get a fix released (which I hope is actually secure this time). But if I were you I’d get rid of it and make your computer more secure since Oracle can’t seem to get security right.