Skip to: Site Navigation | Search | Content

Legit Reviews

Product Reviews - Industry Facts - Technology Issues

Legit News

New Java Zero-Day Exploit Kit Peddled for 5 Grand

Only three days ago on Sunday, Oracle patched yet another major zero-day security flaw in Java. The company isn't known for being keen on patching software vulnerabilities in its Java software and usually takes its time, but this one was so serious that they issued one very quickly and not according to any usual time schedule. In fact, the US Department of Homeland Security recommended that the software be disabled unless it was "absolutely necessary" to use it. Even after the patch was issued, the same advice was repeated on Monday by the department's Computer Emergency Readiness Team (US-CERT).

java250
This time however, an even worse zero-day flaw has been uncovered which very few people know about. This makes it much more dangerous, since the window of opportunity for exploitation is bigger. Security blogger Brian Krebs, discovered this new flaw by visiting an exclusive cybercrime forum where since Monday (Jan 14th) an exploit kit was being peddled by the site's admin for a staggering $5,000 to two lucky buyers - who were even invited to outbid each other! This exploit is present in the latest version of Java (v7 update 11) and crucially, not in any previous exploit kit, thereby allowing the seller to command a high price for it. His sales pitch is quoted below and it appears that the site's admin has since found a second buyer, because the thread has now been deleted.

 

The exploit kit works in the usual way through web browser vulnerabilities, exposed when Java is installed on the target's computer. So, the advice remains to uninstall Java from your computer - no one should be under the illusion that their computer is safe with this security hole-riddled software on it.

New Java 0day, selling to 2 people, 5k$ per person

And you thought Java had epically failed when the last 0day came out.

I lol'd. The best part is even-though java has failed once again and let users get compromised… guess what? I think you know what I'm going to say… there is yet another vulnerability in the latest version of java 7. I will not go into any details except with seriously interested buyers.

Code will be sold twice (it has been sold once already). It is not present in any known exploit pack including that very private version of [Blackhole] going for 10$k/month. I will accepting counter bids if you wish to outbid the competition. What you get? Unencrypted source files to the exploit (so you can have recrypted as necessary, I would warn you to be cautious who you allow to encrypt… they might try to steal a copy) Encrypted, weaponized version, simply modify the url in the php page that calls up the jar to your own executable url and you are set. You may pm me.

Posted by | Wed, Jan 16, 2013 - 10:45 PM


blog comments powered by Disqus

Recent Articles
  • Gigabyte Shows Off Upcoming Intel Z87 Motherboards
  • MSI Z77A-GD65 Gaming Series Motherboard Review
  • ASUS Xonar DGX and Xonar DSX Audio Cards Reviews
  • WD My Passport Ultra 1TB Storage Drive Review
  • ASUS PCE-AC66 Dual-Band 802.11 AC PCIe Wireless Card Review
  • Kingston MobileLite Wireless Card Reader Review
  • Seagate Desktop HDD.15 4TB vs WD Black 4TB Hard Drive Review
  • Kingston DataTraveler Ultimate 3.0 G3 32GB Flash Drive Review
  • Buffalo AirStation N600 Dual-Band Wireless Router Review
  • Be Quiet! Dark Power Pro 10 850W BN603 PSU Review
Recent News
  • ASRock Intel 8 Series Boards Are Waterproof - Conformal Coating
  • Google Checkout To Be Put To Pasture - Google Wallet Takes Over
  • Liquid Cooling Arrives To Smartphones - NEC Medias X
  • Diamond Multimedia Launches $50 Wireless Repeater Range Extender
  • Current be quiet! Power Supplies are Intel Haswell Ready
  • Onkyo Launches 9.2-Channel TX-NR929 Wireless Network A/V Receiver
  • MSI Readies First AMD Richland A10 APU Powered Gaming Laptops
  • Fractal Design Launches Node 304 Mini ITX Case in White
  • Call of Duty: Ghosts Reveal Trailer Released
  • NVIDIA Announces PhysX Support for Microsoft Xbox One Game Console

Socialize

  • Facebook
  • Twitter
  • YouTube

Search

Hot Topics

  • 4TB Seagate SATA 3.5" Hard Drive For $150 Shipped
  • ASRock Intel 8 Series Boards Get Conformal Coating
  • NAND Flash Contract Prices Drop due to Seasonality
  • Lian Li to Unveil New Products at COMPUTEX 2013
  • WD to Demonstrate 5mm SSHD at Computex
  • Gigabyte Shows Off Upcoming Intel Z87 Motherboards
  • TRENDnet TEW-647GA Wireless N Gaming Adapter $20 Shipped
  • Corsair CX430 V2 430W PSU For $18 Shipped AR
  • Diamond Multimedia Launches Wireless Repeater Range Extender
  • All current be quiet! power supplies are Haswell ready

Explore ::

  • News
  • Articles
  • Editorial
  • Interviews
  • Events
  • Folding
  • Forums

Content ::

  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • Bluetooth
  • Cooling
  • Miscellaneous

About ::

  • Contact
  • About Us
  • Disclaimer

Copyright © 2002-2013 Legit Reviews™ & LegitReviews.com - All Rights Reserved.

  • Home
  • Forums
  • Favorite
  • RSS Feeds
  • Shopping
  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • PC Cases
  • Cooling
  • Misc