Skip to: Site Navigation | Search | Content

Legit Reviews

Product Reviews - Industry Facts - Technology Issues

Legit News

Latest JAVA Flaw Exploited Widely Within Days

Within days of its discovery by threat protection firm FireEye, a flaw in JAVA (not to be confused with JavaScript) is being widely exploited. It takes the form of a drive-by download and has originated from a Chinese web site, with the page hosting the exploit being timestamped August 22, 2012. The attack that FireEye detected and blocked attempted to install the Poison Ivy rootkit.

This flaw affects all versions of Oracle's JAVA 7 (v1.7) on all supported platforms. Interestingly, JAVA 6 and earlier don't have this flaw. Crucially, Oracle have not yet made a patch available, hence making this a zero-day exploit. Oracle has a bad track record of releasing timely patches and it's next scheduled update for JAVA is a long time away, on October 16, 2012. However, with all the bad publicity that this exploit is generating, hopefully they'll release a patch sooner.


The attack will soon be added to infamous malware, Blackhole Exploit Kit, if it hasn't been done so already and will allow an attacker to take over a machine. It's recommended that JAVA be either uninstalled from the PC, or browser integration disabled, to mitigate the threat. Running quality internet security software will also help to guard against this threat.

Need to access intranet pages that require Java in your browser? Use your client firewall to disallow access to non-intranet resources for javaw.exe (on Windows).

Another solution is to surf the net using your favourite browser with Java disabled, and have an alternate browser available for the occasional site that needs it (Java is not JavaScript, you almost never need it).

Sophos

Posted by | Mon, Aug 27, 2012 - 08:56 PM


blog comments powered by Disqus

Recent Articles
  • Fractal Design Node 605 Silent HTPC Case Review
  • AMD Kabini Mainstream APU Notebook Platform Preview
  • OCZ Vertex 450 256GB SSD Review
  • Gigabyte Shows Off Upcoming Intel Z87 Motherboards
  • MSI Z77A-GD65 Gaming Series Motherboard Review
  • ASUS Xonar DGX and Xonar DSX Audio Cards Reviews
  • WD My Passport Ultra 1TB Storage Drive Review
  • ASUS PCE-AC66 Dual-Band 802.11 AC PCIe Wireless Card Review
  • Kingston MobileLite Wireless Card Reader Review
  • Seagate Desktop HDD.15 4TB vs WD Black 4TB Hard Drive Review
Recent News
  • How To Fix a Laptop
  • EVGA Precision X 4.2.0 Released
  • Apple 1 1976 Computer To Be Auctioned This Weekend
  • NVIDIA Releases GeForce 320.18 WHQL Video Card Drivers
  • OCZ Launches the Next Generation Vertex 450 Series SSDs
  • Inno3D GeForce GTX 780 HerculeZ 2000 - Custom Card
  • ZOTAC Introduces GeForce GTX 780
  • NVIDIA Launches GeForce GTX 780 Video Card
  • AMD Announces New 2013 Mobile APU Series
  • Xbox One Reveal 2013 Highlights

Socialize

  • Facebook
  • Twitter
  • YouTube

Search

Hot Topics

  • Ozeri Touch 440 lb Digital Bath Scale $29 Shipped
  • EVGA Precision X 4.2.0 Released
  • Fractal Design Node 605 Silent HTPC Case Review
  • OCZ Technology Partners with NETGEAR
  • USB 3.0 PCIe Card For $3 AR
  • NVIDIA Releases GeForce 320.18 WHQL drivers
  • OCZ Launches the Next Generation Vertex 450 Series SSDs
  • Velocity Micro announces desktops powered by GeForce GTX780
  • Inno3D GeForce GTX 780 HerculeZ 2000
  • ZOTAC Introduces GeForce GTX 780

Explore ::

  • News
  • Articles
  • Editorial
  • Interviews
  • Events
  • Folding
  • Forums

Content ::

  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • Bluetooth
  • Cooling
  • Miscellaneous

About ::

  • Contact
  • About Us
  • Disclaimer

Copyright © 2002-2013 Legit Reviews™ & LegitReviews.com - All Rights Reserved.

  • Home
  • Forums
  • Favorite
  • RSS Feeds
  • Shopping
  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • PC Cases
  • Cooling
  • Misc