ie8 fix
Click Here

Spyware, viruses, & security forum: NEWS - August 30, 2012

by: Carol~ August 30, 2012 8:46 AM PDT

Like this

0 people like this thread

Staff pick

NEWS - August 30, 2012

by Carol~ Moderator - 8/30/12 8:46 AM

Chorus Grows Louder to Disable Java 7 After Exploit Hits Mainstream

More security researchers are recommending users disable the current version of Java after zero-day exploits gained traction in the Web world.

Patrick Runald, director of security research for Websense, told PC World today that his team had uncovered more than 100 infected domains - a figure expected to rise sharply after the exploit code for the Java vulnerabilities was added in recent days to the popular hacker tool Blackhole.

The original attack, believed to be based in China, is based on two vulnerabilities in one .jar file in Java 7.

Because of Java's ubiquitousness within Web sites, and Oracle's failure to date to release a patch out of its normal quarterly rotation, companies this week began recommending users disable Java browser plugins to help prevent the malicious code from entering machines through compromised Web sites.

"The beauty of this bug class is that it provides 100 percent reliability and is multiplatform. Hence this will shortly become the penetration test Swiss knife for the next couple of years (as did its older brother CVE-2008-5353)," wrote an Immunity developer Esteban Guillardoy earlier this week.

US-CERT recommended as a workaround disabling the Java plugin in browsers such as Safari, Chrome, Firefox and Internet Explorer. Apple's Lion and Mountain Lion also use Java 7 while Leopard and Snow Leopard do not.

Continued : https://threatpost.com/en_us/blogs/chorus-grows-louder-disable-java-7-after-exploit-hits-mainstream-082912

Related:
Java 0-day exploit served from over 100 sites
Care to Disable the Java Plugin?
________________________________________

From the Mozilla Security Blog:

Update - Aug 29, 2012: Protecting Users Against Java Security Vulnerability

We've been closely monitoring the recent Java security vulnerability and evaluating different options to best protect our users.

Our goal is to provide protection to Firefox users against this actively exploited vulnerability in Java while also leaving the user in control so they can choose to allow Java on important sites that they trust.

We are still working out the implementation details, but our solution will accomplish two primary objectives:

1. By default, vulnerable versions of Java will be disabled for our Firefox users.
2. Users will be provided the option to enable Java through a clear and visible message that will be displayed anytime the user views a page using Java.

We'll provide additional updates when items are finalized. In the interim, we still advise users to disable the Java plugin as described below.

Continued : https://blog.mozilla.org/security/2012/08/28/protecting-users-against-java-security-vulnerability/

Forum Icon Legend

  • UnreadUnread
  • ReadRead
  • Locked threadLocked thread
  •   
  •   
  •   
  •   
  •   
  •   
  •   
  • ModeratorModerator
  • CNET StaffCNET Staff
  • Samsung StaffSamsung Staff
  • Norton Authorized Support TeamNorton Authorized Support Team
  • AVG StaffAVG Staff
  • avast! Staffavast! Staff
  • Webroot Support TeamWebroot Support Team
  • Acer Customer Experience TeamAcer Customer Experience Team
  • Windows Outreach TeamWindows Outreach Team
  • DISH staffDISH staff
  • Dell StaffDell Staff
  • Intel StaffIntel Staff
  • QuestionQuestion
  • Resolved questionResolved question
  • General discussionGeneral discussion
  • TipTip
  • Alert or warningAlert or warning
  • PraisePraise
  • RantRant

You are e-mailing the following post: Post Subject

Your e-mail address is used only to let the recipient know who sent the e-mail and in case of transmission error. Neither your address nor the recipient's address will be used for any other purpose.

Sorry, there was a problem emailing this post. Please try again.

Submit Email Cancel

Thank you. Sent email to

Close

Thank you. Sent email to

Close

You are reporting the following post: Post Subject

If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.

Offensive: Sexually explicit or offensive language

Spam: Advertisements or commercial links

Disruptive posting: Flaming or offending other users

Illegal activities: Promote cracked software, or other illegal content

Sorry, there was a problem submitting your post. Please try again.

Submit Report Cancel

Your message has been submitted and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.

Close

Your message has been submitted and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.

Close

You are posting a reply to: Post Subject

The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to the CNET Forums policies for details. All submitted content is subject to CBS Interactive Site Terms of Use.

You are currently tracking this discussion. Click here to manage your tracked discussions.

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

Sorry, there was a problem submitting your post. Please try again.

Sorry, there was a problem generating the preview. Please try again.

Duplicate posts are not allowed in the forums. Please edit your post and submit again.

Submit Reply Preview Cancel

Thank you, , your post has been submitted and will appear on our site shortly.

Close