Raised This Month: $51 Target: $400
 12% 

Java provides remote attack vector on all platforms


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
Lee
AlliedModders Donor
Join Date: Feb 2006
Old 07-13-2007 , 14:00   Java provides remote attack vector on all platforms
Reply With Quote #1

http://www.auscert.org.au/render.html?it=7664
http://www.java.com/en/download/manual.jsp

I could see this being a huge problem for many millions of people.
Lee is offline
Zenith77
Veteran Member
Join Date: Aug 2005
Old 07-13-2007 , 14:17   Re: Java provides remote attack vector on all platforms
Reply With Quote #2

I can't help but laugh.
__________________
Quote:
Originally Posted by phorelyph View Post
your retatred
Zenith77 is offline
Twilight Suzuka
bad
Join Date: Jul 2004
Location: CS lab
Old 07-13-2007 , 15:29   Re: Java provides remote attack vector on all platforms
Reply With Quote #3

Doesn't seem any worst than printf attacks
__________________
Twilight Suzuka is offline
Send a message via AIM to Twilight Suzuka Send a message via MSN to Twilight Suzuka
Zenith77
Veteran Member
Join Date: Aug 2005
Old 07-13-2007 , 15:53   Re: Java provides remote attack vector on all platforms
Reply With Quote #4

Quote:
Originally Posted by Twilight Suzuka View Post
Doesn't seem any worst than printf attacks
Yea, but from what little I understand on this is all that needs to happen is for the picture to load in a java app. Place this on a highly visited web site and o noes.
__________________
Quote:
Originally Posted by phorelyph View Post
your retatred
Zenith77 is offline
TheNewt
Donor
Join Date: Jun 2006
Location: Where I live.
Old 07-13-2007 , 15:57   Re: Java provides remote attack vector on all platforms
Reply With Quote #5

Okay... So basically another exploit that prays on the stupid? That is fantastic.
__________________
Quote:
toe3_ left the chat room. (G-lined (AUTO Excessive connections from a single host.))
TheNewt is offline
Lee
AlliedModders Donor
Join Date: Feb 2006
Old 07-13-2007 , 16:31   Re: Java provides remote attack vector on all platforms
Reply With Quote #6

I run my browsers and email clients without administrative privileges for obvious reasons, but I've resisted installing NoScript until now because there are so many sites that don't graciously handle Java and Javascript being disabled.

People who don't patch their software when they're aware of an update are indeed stupid, but you can't expect end users to monitor security bulletins. I only found out about this by coincidence when reading Slashdot. For something as ubiquitous and easily exploitable as Java, there should at the very least be a notification that a security update has been released.

What printf() attacks?

Last edited by Lee; 07-13-2007 at 16:33.
Lee is offline
commonbullet
Veteran Member
Join Date: Oct 2005
Old 07-13-2007 , 19:53   Re: Java provides remote attack vector on all platforms
Reply With Quote #7

This, I suppose:
http://en.wikipedia.org/wiki/Format_string_attacks

I guess jre users are notified about software updates (or automatically updated?) by default.

Last edited by commonbullet; 07-13-2007 at 20:00.
commonbullet is offline
Send a message via ICQ to commonbullet Send a message via MSN to commonbullet
Lee
AlliedModders Donor
Join Date: Feb 2006
Old 07-13-2007 , 20:08   Re: Java provides remote attack vector on all platforms
Reply With Quote #8

No.. At least I wasn't, and I wouldn't knowingly disable such a feature unless it became intrusive.

Edit: It probably does actually - once a month by default it seems. I opened the Java options dialogue in Control Panel and I'm immediately presented with the option to unblock it by my firewall. Theoretically that should have happened as soon as it checked for updates. I'm really not sure what I should blame for the auto-update not working, but if it does usually work, this is nowhere near as bad as I originally made out.

Edit: The update feature is a separate executable that was automatically allowed by my firewall when I ran it manually - meaning it was the first time it had ever been launched contrary to what the options dialogue displayed. I'm really confused.

Last edited by Lee; 07-13-2007 at 20:28.
Lee is offline
BAILOPAN
Join Date: Jan 2004
Old 07-13-2007 , 21:17   Re: Java provides remote attack vector on all platforms
Reply With Quote #9

FUD
__________________
egg
BAILOPAN is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 16:36.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode