Welcome, Guest. Please login or register.
May 23, 13, 03:41 AM

Login with username, password and session length
Gallery Pic
Sorry, you do not have permission to view pictures!
Todays Calendar
Birthdays:
There are no birthdays today.

Events:
There are no events today.
Members
Total Members: 80
Latest: garythegardener
Stats
Total Posts: 93079
Total Topics: 9517
Online Today: 11
Online Ever: 127
(Nov 02, 12, 06:30 AM)
Users Online
Users: 0
Guests: 7
Total: 7
adverts
RoboForm: Learn more...
Strimmer
Secunia
Recent
[Yesterday at 06:22 PM]

by Lyn
[Yesterday at 12:25 PM]

[Yesterday at 10:01 AM]

[Yesterday at 08:41 AM]

[Yesterday at 07:35 AM]

by Babs
[May 21, 13, 06:14 PM]

[May 21, 13, 05:49 PM]

[May 21, 13, 04:07 PM]

by Babs
[May 20, 13, 04:30 PM]

[May 20, 13, 11:44 AM]
Well Bogled
Baron 67
Derek 35
Yvonne 31
Welcome To Our Local





Pages: [1]   Go Down
  Print  
Author Topic: Java exploit in the wild - here we go again...  (Read 1515 times)
0 Members and 1 Guest are viewing this topic.
Richard
Landlord
***

Bogle Points: 0
Offline Offline

Posts: 47776


Let it snow :-)


« on: Aug 28, 12, 08:15 AM »

It's a naughty one - it allows your machine to be forced to run any code the attacker wants, regardless of your browser.

The Windows version is in the wild, but theoretically a different payload on the same exploit could infect Mac or Linux too.

http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html

Until this is patched, I strongly recommend you kill your Java stone dead... it's highly unlikely you need it installed at all, I haven't had it on my machine in a year or more and haven't missed it.
Logged

Your other host, Genial Host...      richard@our-local.co.uk

ಇದನ್ನು ಫಕಿಂಗ್ ಕ್ವಿಟ್ Or something like that.
Baron
Foreskin
Barfly
***

Bogle Points: 67
Offline Offline

Gender: Male
Posts: 12256


Here Kitty Kitty...


« Reply #1 on: Aug 28, 12, 09:41 AM »

I currently don't have Java installed, and there is only one programme that requires it, and I am buggered if I can remember what it is..... Grin
Logged

It's my party, my rules................naked men only...
crikey
junk male
Barfly
***

Bogle Points: 18
Offline Offline

Gender: Male
Posts: 4605


Not far to go, now


« Reply #2 on: Aug 28, 12, 06:37 PM »

Got a java update alert tonight - wonder if it's the fix? Have ignored it, for now.
Logged

I used to have a handle on life, but it broke.
fairyhedgehog
Hedgehog in Residence
Barfly
***

Bogle Points: 0
Offline Offline

Posts: 2658



WWW
« Reply #3 on: Aug 29, 12, 06:45 AM »

Thanks. I've uninstalled Java.
Logged

fairyhedgehog
Hedgehog in Residence
Barfly
***

Bogle Points: 0
Offline Offline

Posts: 2658



WWW
« Reply #4 on: Aug 29, 12, 07:28 AM »

And now I've discovered I need Java to run BlogBridge (my blog reader). Is it safe to reinstall it yet?
Logged

Richard
Landlord
***

Bogle Points: 0
Offline Offline

Posts: 47776


Let it snow :-)


« Reply #5 on: Aug 29, 12, 08:23 AM »

And now I've discovered I need Java to run BlogBridge (my blog reader). Is it safe to reinstall it yet?

Unless Oracle break their usually-strict patch cycle - they don't normally do that even when they're in deep shit - you're looking at the middle of October  Undecided

You may have to resort to reading blogs in your browser like the rest of us?
Logged

Your other host, Genial Host...      richard@our-local.co.uk

ಇದನ್ನು ಫಕಿಂಗ್ ಕ್ವಿಟ್ Or something like that.
fairyhedgehog
Hedgehog in Residence
Barfly
***

Bogle Points: 0
Offline Offline

Posts: 2658



WWW
« Reply #6 on: Aug 29, 12, 08:51 AM »

I'm back to using my Google list - which will never unsubscribe from anything and doesn't organise blogs, so it's a chaotic mess. If I miss any of your posts, I apologise in advance!
Logged

Derek
Being a nuisance
Landlord
***

Bogle Points: 35
Offline Offline

Gender: Male
Posts: 12310


The old git who sits in the corner moaning


WWW
« Reply #7 on: Aug 30, 12, 07:58 PM »

Java update out now
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html

if you must use Java go, & get it
but even better is to uninstall Java & avoid the risks completely
Logged

Old Spikey
Microsoft MVP/Windows - Security
For help with spyware or hijackers thespykiller

Derek
Being a nuisance
Landlord
***

Bogle Points: 35
Offline Offline

Gender: Male
Posts: 12310


The old git who sits in the corner moaning


WWW
« Reply #8 on: Aug 31, 12, 08:08 PM »

and the newest version of Java released yesterday is alleged to be vulnerable to  a new set of 0 day exploits and poc for them have been issued by the same "security analysts" as had the original releases
Logged

Old Spikey
Microsoft MVP/Windows - Security
For help with spyware or hijackers thespykiller

Richard
Landlord
***

Bogle Points: 0
Offline Offline

Posts: 47776


Let it snow :-)


« Reply #9 on: Aug 31, 12, 08:46 PM »

No surprises there - Java is insecure by design and always will be... and there's no need for it to be installed at all for 99% of home users.

http://arstechnica.com/security/2012/08/critical-bug-discovered-in-newest-java/
Logged

Your other host, Genial Host...      richard@our-local.co.uk

ಇದನ್ನು ಫಕಿಂಗ್ ಕ್ವಿಟ್ Or something like that.
Langston
I am the only person in the world who is exactly the same as everybody else.
Barfly
***

Bogle Points: 0
Offline Offline

Gender: Male
Posts: 20938


Tämä on väärin


WWW
« Reply #10 on: Aug 31, 12, 09:17 PM »

No surprises there - Java is insecure by design and always will be... and there's no need for it to be installed at all for 99% of home users.

http://arstechnica.com/security/2012/08/critical-bug-discovered-in-newest-java/
Not having it really f*cks up OpenOffice, particularly the database.
Do you know of an alternative?
Logged

Richard
Landlord
***

Bogle Points: 0
Offline Offline

Posts: 47776


Let it snow :-)


« Reply #11 on: Sep 01, 12, 12:43 AM »

Not having it really f*cks up OpenOffice, particularly the database.
Do you know of an alternative?

Up to date versions of OO and LibreOffice should both work fine without it... I've not discovered anything LibreOffice can't do without it, and when I recently did a fresh install without Java installed I wasn't prompted for it.
Logged

Your other host, Genial Host...      richard@our-local.co.uk

ಇದನ್ನು ಫಕಿಂಗ್ ಕ್ವಿಟ್ Or something like that.
Langston
I am the only person in the world who is exactly the same as everybody else.
Barfly
***

Bogle Points: 0
Offline Offline

Gender: Male
Posts: 20938


Tämä on väärin


WWW
« Reply #12 on: Sep 01, 12, 08:14 AM »

The database still requires it (OO 3.4.1). I will look into LibreOffice.
Logged

Casper the Ghost
I wonder what this button does . . . . .
Barfly
***

Bogle Points: 0
Offline Offline

Gender: Male
Posts: 2981


Livin on the Dark Side


« Reply #13 on: Sep 01, 12, 07:17 PM »

Oracle say they have released a patch to fix it now. Smiley
Logged

Now what should I put here?? Let me have a think.....
Langston
I am the only person in the world who is exactly the same as everybody else.
Barfly
***

Bogle Points: 0
Offline Offline

Gender: Male
Posts: 20938


Tämä on väärin


WWW
« Reply #14 on: Sep 02, 12, 09:08 PM »

Up to date versions of OO and LibreOffice should both work fine without it... I've not discovered anything LibreOffice can't do without it, and when I recently did a fresh install without Java installed I wasn't prompted for it.
I've just installed LibreOffice and that won't run OO databases without Java RTE either.
Logged

Richard
Landlord
***

Bogle Points: 0
Offline Offline

Posts: 47776


Let it snow :-)


« Reply #15 on: Sep 03, 12, 07:07 AM »

I've just installed LibreOffice and that won't run OO databases without Java RTE either.

That's odd, because it's working just fine here.  thinking

I wonder if it's because my database began life in Foxpro so it's using a different filter?
Logged

Your other host, Genial Host...      richard@our-local.co.uk

ಇದನ್ನು ಫಕಿಂಗ್ ಕ್ವಿಟ್ Or something like that.
Langston
I am the only person in the world who is exactly the same as everybody else.
Barfly
***

Bogle Points: 0
Offline Offline

Gender: Male
Posts: 20938


Tämä on väärin


WWW
« Reply #16 on: Sep 03, 12, 07:18 AM »

That's odd, because it's working just fine here.  thinking

I wonder if it's because my database began life in Foxpro so it's using a different filter?

I have no idea. As soon as I try table view it tells me it requires JRE to perform that action. I'll either have to find a way of converting the information, or put Java back on ( which I'd rather not).
Logged

Casper the Ghost
I wonder what this button does . . . . .
Barfly
***

Bogle Points: 0
Offline Offline

Gender: Male
Posts: 2981


Livin on the Dark Side


« Reply #17 on: Sep 03, 12, 10:59 PM »

Mine auto-updated itself tonight so I assume I am now patched. Smiley
Logged

Now what should I put here?? Let me have a think.....
Pages: [1]   Go Up
  Print  
Jump to: