Java security threat

Discussion in 'Computers & Tech' started by waltky, Jan 11, 2013.

  1. waltky

    waltky Well-Known Member

    Joined:
    Jan 26, 2009
    Messages:
    30,071
    Likes Received:
    1,204
    Trophy Points:
    113
    Gender:
    Male
    Java security weakness...
    :omg:
    U.S. warns on Java software as security concerns escalate
    11 Jan.`13 - The U.S. Department of Homeland Security urged computer users to disable Oracle Corp's Java software, amplifying security experts' prior warnings to hundreds of millions of consumers and businesses that use it to surf the Web.
    See also:

    Critical Patch Updates, Security Alerts and Third Party Bulletin
     
  2. Ctrl

    Ctrl Well-Known Member Past Donor

    Joined:
    Oct 11, 2008
    Messages:
    25,745
    Likes Received:
    1,944
    Trophy Points:
    113
    Always has been. Terrible, terrible environment. Fun to program... but... yeah.
     
  3. waltky

    waltky Well-Known Member

    Joined:
    Jan 26, 2009
    Messages:
    30,071
    Likes Received:
    1,204
    Trophy Points:
    113
    Gender:
    Male
    Thanks to MMC over at Political Bullpen...
    :cool:
    How to Disable Java
    January 11, 2013 - Java is a handy, cross-platform language that's been mightily abused by hackers. With the discovery of a new Java vulnerability that affects even the most up-to-date version, many experts advise everyone to simply disable Java. Here's how.
     
  4. waltky

    waltky Well-Known Member

    Joined:
    Jan 26, 2009
    Messages:
    30,071
    Likes Received:
    1,204
    Trophy Points:
    113
    Gender:
    Male
    Dey workin' onna fix...
    :thumbsup:
    Oracle Corp to fix Java security flaw "shortly"
    12 Jan.`12 - Oracle Corp said it is preparing an update to address a flaw in its widely used Java software after the U.S. Department of Homeland Security urged computer users to disable the program in web browsers because criminal hackers are exploiting a security bug to attack PCs.
     
  5. waltky

    waltky Well-Known Member

    Joined:
    Jan 26, 2009
    Messages:
    30,071
    Likes Received:
    1,204
    Trophy Points:
    113
    Gender:
    Male
    Just to be on the safe side - think I'll keep it disabled till the 'all clear' is sounded...
    :wink:
    Oracle says Java is fixed; feds maintain warning
    Jan 14,`13 -- Oracle Corp. said Monday it has released a fix for the flaw in its Java software that raised an alarm from the U.S. Department of Homeland Security last week. Even after the patch was issued, the federal agency continued to recommend that users disable Java in their Web browsers.
     
  6. Indofred

    Indofred Banned at Members Request

    Joined:
    Jul 4, 2012
    Messages:
    3,103
    Likes Received:
    315
    Trophy Points:
    83
    or just use Avira anti virus.
    That cures the problem.
     
  7. mutmekep

    mutmekep New Member

    Joined:
    Apr 25, 2012
    Messages:
    6,223
    Likes Received:
    46
    Trophy Points:
    0
    Antivirals can never solve all problems , blackhats are as good in their job as commercial programmers .
    I was trying to remove a highjacker from boss 's computer yesterday , superantispyware, avira and malwarebytes couldn't find anything so i googled and there was like 6 updates of removal instructions since July !
    I am using scriptblock addon for firefox only and never had an issue with web security (if you don't have it just disable java) , of course there is no such thing as a perfectly safe environment .
     
  8. Ctrl

    Ctrl Well-Known Member Past Donor

    Joined:
    Oct 11, 2008
    Messages:
    25,745
    Likes Received:
    1,944
    Trophy Points:
    113
    Cough... linux... cough...
     
  9. mutmekep

    mutmekep New Member

    Joined:
    Apr 25, 2012
    Messages:
    6,223
    Likes Received:
    46
    Trophy Points:
    0
    There is malware for linux but even if we consider it safe who will teach +55 year old bosses how to use it ?
     
  10. Ctrl

    Ctrl Well-Known Member Past Donor

    Joined:
    Oct 11, 2008
    Messages:
    25,745
    Likes Received:
    1,944
    Trophy Points:
    113
    This isn't malware. This is a polymorphic java trojan. It has 0 effect on linux. Viruses, trojans... these have no affect on linux. Linux uses role based security to do everything. Nothing launches with root permissions... unless you specifically open a terminal and launch it as such... which is a really stupid thing to do. You can make the decision to install something wicked, and provide credentials... but that is how it would have to be done.

    "malware" is a catchall for anything that "does not behave as you desire" that is not a virus or a trojan.

    Malware can affect active sessions in a browser. It does not affect the OS. You might get a browser redirect/hijack.. and the ultimate solution to any such nonsense is to open your package manager and click reinstall.

    You pick a desktop environment that looks similar to windows... and show them that if they want a program they open the package manager and search for a term related to what they want to do, and click the install button. Oh and everything is free and there is no loss of productivity due to viruses.

    I do it just about every week.
     
  11. Ctrl

    Ctrl Well-Known Member Past Donor

    Joined:
    Oct 11, 2008
    Messages:
    25,745
    Likes Received:
    1,944
    Trophy Points:
    113

Share This Page