Showing posts with label Java. Show all posts
Showing posts with label Java. Show all posts

Monday, September 16, 2013

Big Business continues to ignore the Java threats

Big Business continues to ignore the threat that in itself can conceal the use of outdated versions of Java, the company said in a research Websence. According to this the company, about four fifths Java users in the corporate sector are not using the latest version of this environment .

Having missed the part of corporate traffic through its own cloud computing Websence ThreatSeeker Intelligence Cloud, the company found that about 40 % Java-queries go through interpreter Java 6 Standard Edition, though, that the version of Java 7 Standard Edition was released two years ago. Oracle completed the technical support Java 6SE in April of this year.

The analyst said that some may use the Java SE 6 for compatibility reasons , but most people are in danger of hacking exploits due to obsolete versions of the product. The general trend also indicates that about 81 % of browsers are vulnerable to at least two fresh problems with Java - CVE- 2013 -2473 and CVE- 2013 - 2463 identified in June of this year.

Thursday, March 7, 2013

Successfully hacked Chrome, Firefox, IE 10, Java, Win 8


At Pwn2Own hacking  contest was successfully hacked Chrome, Firefox, IE 10, Java, Win 8


The first day of competition Pwn2Own, held each year at the conference CanSecWes, proved fruitful as ever - were demonstrated working industry practices previously unknown vulnerabilities in Chrome, Firefox, IE 10, Windows 8 and Java. In all cases, the attack was carried out in the processing in the browser specially decorated web-pages, the opening of which ended with complete control over the system. When demonstrating the attack relies on the most recent stable releases of browsers and operating systems Windows 7, 8 and Mac OS X Mountain Lion with all available updates in the default configuration.

In accordance with the terms of the tender, the detailed information of all the demonstrated 0-day vulnerabilities will be published only after the release of the manufacturers updates with the removal of these vulnerabilities. Part of the success of this year's Pwn2Own is associated with a significant increase in the amount of remuneration. For example, for the demonstration of hacking Chrome browser will be paid compensation of 100 thousand dollars for hacking IE - 75,000 dollars for hacking Firefox - 60 thousand dollars for hacking Safari - 65 thousand dollars, for breaking through the IE plug-in Adobe Reader XI - 70,000 dollars for breaking plugins for Adobe Flash and Java on 20 thousand dollars. At the same time the competition will be held adjacent Pwnium, which will be offered to break the Chrome OS on the device Samsung Series 5550 Chromebook. The total prize fund will Pwnium 3.14159 million and the maximum amount of compensation - 150 thousand dollars.

Wednesday, February 27, 2013

The discovery of new vulnerabilities in the latest version of Java


System compromise in Java


Experts of Security Explorations reported Oracle developers of two gap, allowing completely bypass sandbox restrictions Java.

According to the new notification researchers Security Explorations, the latest version of Java were discovered two new vulnerabilities that can completely bypass the restrictions built into the platform sandbox. Thus, according to the expert Adam Gowdiak, gaps affect current versions of Java 7 SE, in particular component Reflection API, which you can get around the limitations "in an interesting way."

Govdiak also said that he tested the original release of Java SE 7, Java SE 7 Update 11 and Java SE 7 Update 15. According to Security Explorations, Oracle developers have already received all the information and PoC-code, and pledged to take action.

Wednesday, February 13, 2013

Yahoo! offers developers a tool based on a vulnerable version of Java


Application that provides a company uses a version of Java 6 Update 7, containing a number of vulnerabilities.

While Apple, Mozilla, and other tech giants are taking various steps to prevent the use of unsafe client versions Java, Yahoo! offers users a free tool for creating web-sites that require unsafe version of Java, released over 4 years ago.

Activities include a tool called SiteBuilder, which contains a number of vulnerabilities and may subject the user's computer the risk of infection. Danger seen in the fact that the tool uses a vulnerable version of Java 6 Update 7.

Monday, September 3, 2012

Oracle knew about the presence of 0-day Java vulnerabilities in April

Security Explorations company said it released Oracle solution does not correct all vulnerabilities in Java

Oracle has released a security alert, which eliminated the zero-day vulnerability in Java (CVE-2012-4681). Recall that last week of the first public exploit this vulnerability reported Atif Mushtaq from the company FireEye. According to experts, hackers used a gap in Java for the implementation of targeted attacks, but in the near future to exploit it was supposed to be accessible to a wide range of cyberhawks.

The next day, the company Rapid 7 said about adding a module to exploit CVE-2012-4681 for a tool to pentesterov Metasploit, and Brian Krebs, citing its own sources, said that his version of the exploit works and authors BlackHole. Quoting one of the leaders of BlackHole, Krebs wrote that the price of such an exploit could be about $ 100,000.

Saturday, September 1, 2012

Oracle has released patches for urgent Java 6 and 7

Extraordinary patch for an 0-day vulnerability


Oracle has released extraordinary patch for an 0-day vulnerability, which in recent days have begun to actively exploit some cybercriminal groups.

Updates for JDK and JRE 6 Update 7, JDK and JRE 6 Update 34 contains patches for four vulnerabilities Java, including the notorious CVE-2012-4681. Oracle has emphasized: given the danger of this threat, it is strongly recommended that all users install the patch data as soon as possible.

The vulnerability affects only the desktop version of the plugin Java, working through a web browser, they do not touch the server version or separate Java-applications.

Tuesday, August 28, 2012

Exploit the vulnerability of 0-day in Java


Exploit the vulnerability of 0-day in Java can cost $ 100,000


Exploit module is already available in Metasploit, and possibly in the BlackHole.

For the past few days on the Internet is discussed actively zero-day vulnerability in the environment Oracle Java, which is actively maintained during targeted attacks. First reported the vulnerability of experts FireEye, who talked about what address the server is used by an exploit.

In its notification expert FireEye, Atif Mushtaq noted that in the near future to exploit vulnerabilities in Java will become widely available, and attackers can use it very actively. Total overnight company Rapid 7 introduced a module exploit platform Metasploit. This module exploits a vulnerability in JRE for the latest versions of browsers Mozilla Firefox, Internet Explorer, and Safari on platforms Linux, Windows and Macintosh.