| Windows 7: New Java Exploit Fetches $5,000 Per Buyer; Krebs on Security |
16 Jan 2013
|
#1 | | Windows 7 Home Premium 64-bit Service Pack 1 Lost in disambiguation |
New Java Exploit Fetches $5,000 Per Buyer; Krebs on Security New Java Exploit Fetches $5,000 Per Buyer — Krebs on Security Quote: Less than 24 hours after Oracle patched a dangerous security hole in its Java software that was being used to seize control over Windows PCs, miscreants in the Underweb were already selling an exploit for a different and apparently still-unpatched zero-day vulnerability in Java, KrebsOnSecurity has learned.
On Sunday, Oracle rushed out a fix for a critical bug in Java that had been folded into exploit kits, crimeware made to automate the exploitation of computers via Web browser vulnerabilities. On Monday, an administrator of an exclusive cybercrime forum posted a message saying he was selling a new Java 0day to a lucky two buyers. The cost: starting at $5,000 each.
The hacker forum admin’s message, portions of which are excerpted below, promised weaponized and source code versions of the exploit. This seller also said his Java 0day — in the latest version of Java (Java 7 Update 11) — was not yet part of any exploit kits, including the Cool Exploit Kit I wrote about last week that rents for $10,000 per month. Is Oracle neglecting the consumer users it inherited from Sun? | Security - InfoWorld Quote: Though the purported new zero-day exploit has yet to be officially confirmed, it's certainly plausible. First, per Krebs: "I don't have the exploit or the source code or anything. That said, this was a sales thread posted by an administrator of this exclusive crime forum. It would be somewhat rare and ill-advised for a person in such a position to try to scam forum members, especially for just $5k."
Second, a critique of the latest Java patch by the OpenJDK community found that "while Oracle's quick fix appears to have broken the exploit chain ... building another chain could be possible -- and may already have happened within the shadows of the black-hat cracker community."
Last edited by Urthboundmisfit; 17 Jan 2013 at 03:33 AM..
Reason: add 2nd link
| My System Specs |
| System Manufacturer/Model Number Gateway NV59C Notebook OS Windows 7 Home Premium 64-bit Service Pack 1 CPU Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz Motherboard Gateway V1.08 Memory 8GB Kingston DDR3 Graphics Card Intel HD Graphics Sound Card Realtek High Definition Audio Screen Resolution 1366x768 Hard Drives WDC WD2500BPVT-75JJ5T0 Other Info MSSE AV, FFox, Ex-PLODE-r 9 |
16 Jan 2013
|
#2 | | Windows 7 Home Premium x64 Indiana/Florida U.S.A. |
Java will be belly up one of these days. Just recently had to reinstall it..... but keep it disabled. | My System Specs | | Computer type Laptop System Manufacturer/Model Number Asus G74Sx OS Windows 7 Home Premium x64 CPU Intel i7 2670 Qm @2.20 Motherboard AsusTek G74Sx,1.0 Memory 16 GB DDR3 Graphics Card Nvidia Geforce GTX 560M -2040mb Monitor(s) Displays Generic Screen Resolution 1600 x 900 Hard Drives Crucial M4 128 gb SSD Internal/ 500gb Western Digital internal @ 7200 rpm (love the dual internal drives!)
1t Western Digital External, 500gb Western Digital External
500gb Seagate External x 2 Antivirus Avast Free Browser Opera/Maxthon3/Comodo Dragon (very rarely) |
16 Jan 2013
|
#3 | | Windows 7 Home Premium 64 bit. SP-1 Northern Ohio |
Is it just me or does it seem like every sense Oracle bought Sun Micro Java it has been exploited with revenge. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home made Desktop OS Windows 7 Home Premium 64 bit. SP-1 CPU Intel i7-960-3.2 @ 4.25 Motherboard ASUS P6X58D-E Memory KINGSTON KHX2000C9, Hyper X,12 GIGS Graphics Card MSI/Nvidia/460GTX-Cyclone 1GD5/OC Monitor(s) Displays DYNEX 40 IN. Screen Resolution 1920-1080 or 1280-720 HDMI Keyboard M/S 3000 v 2.0 wireless Mouse M/S 5000 wireless PSU Corsair AX-850 Plus Gold Case Corsair 600T (Black) + side panel with 2 140 mm Noctua fans Cooling Corsair H50/2 Noctua NF-P12 (120 mm) Push/Pull- Hard Drives INTEL SSD 120GB-SER 510
Seagate 1TB SATA 600 7200 rpm Hard Drive Internet Speed 3.0 mb Antivirus Microsoft Security Eesentials Browser I.E. 10 default/Firefox Other Info LG BluRay-Read/Write
Sound system
KLipsch-THX
Asus Router RTN-12
2 Noctua 140 added on top of 600t case
Malwarebytes Anti Malware Professional
Windows 7 Firewall |
16 Jan 2013
|
#4 | | Windows 7 Ultimate SP1 (64 bit), Windows XP SP3, Linux Mint 14 MATE (64 bit) Adelaide |
The "Fun" Never Ends Java is a disaster (like Flash).
People "paid me out" (a couple of years ago) when I called Java, "a dirty, disease-carrying, piece of garbage." | My System Specs | | System Manufacturer/Model Number n/a OS Windows 7 Ultimate SP1 (64 bit), Windows XP SP3, Linux Mint 14 MATE (64 bit) CPU AMD Phenom II x6 1055T, 2.8 GHz Motherboard ASRock 880GMH-LE/USB3 Memory 8GB DDR3 1333 G-Skill Ares F3-1333C9D-8GAO (4GB x 2) Graphics Card ATI Radeon HD6450 Sound Card Realtek? Monitor(s) Displays Samsung S23B350 Screen Resolution 1920x1080 Mouse Wired Optical Case Tower Hard Drives Western Digital 1 TB (SATA), Western Digital 1.5 TB (SATA), Western Digital 2 TB (SATA) Internet Speed DSL Other Info Ubuntu 10.04 (64 bit) replaced with Linux Mint 14 MATE (64 bit) - 2013-01-14
RAM & Graphics Card Upgraded - 2013-01-13
Monitor Upgraded - 2012-04-20
System Upgraded - 2011-05-21, 2010-07-14
HDD Upgraded - 2010-08-11, 2011-08-24 |
17 Jan 2013
|
#5 | | Windows 7 Home Premium 64-bit Service Pack 1 Lost in disambiguation |

Quote: Originally Posted by Layback Bear Is it just me or does it seem like every sense Oracle bought Sun Micro Java it has been exploited with revenge. Same thought occurred to me. | My System Specs | | System Manufacturer/Model Number Gateway NV59C Notebook OS Windows 7 Home Premium 64-bit Service Pack 1 CPU Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz Motherboard Gateway V1.08 Memory 8GB Kingston DDR3 Graphics Card Intel HD Graphics Sound Card Realtek High Definition Audio Screen Resolution 1366x768 Hard Drives WDC WD2500BPVT-75JJ5T0 Other Info MSSE AV, FFox, Ex-PLODE-r 9 |
17 Jan 2013
|
#6 | | Windows 7 Home Premium 64 bit. SP-1 Northern Ohio |
| My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home made Desktop OS Windows 7 Home Premium 64 bit. SP-1 CPU Intel i7-960-3.2 @ 4.25 Motherboard ASUS P6X58D-E Memory KINGSTON KHX2000C9, Hyper X,12 GIGS Graphics Card MSI/Nvidia/460GTX-Cyclone 1GD5/OC Monitor(s) Displays DYNEX 40 IN. Screen Resolution 1920-1080 or 1280-720 HDMI Keyboard M/S 3000 v 2.0 wireless Mouse M/S 5000 wireless PSU Corsair AX-850 Plus Gold Case Corsair 600T (Black) + side panel with 2 140 mm Noctua fans Cooling Corsair H50/2 Noctua NF-P12 (120 mm) Push/Pull- Hard Drives INTEL SSD 120GB-SER 510
Seagate 1TB SATA 600 7200 rpm Hard Drive Internet Speed 3.0 mb Antivirus Microsoft Security Eesentials Browser I.E. 10 default/Firefox Other Info LG BluRay-Read/Write
Sound system
KLipsch-THX
Asus Router RTN-12
2 Noctua 140 added on top of 600t case
Malwarebytes Anti Malware Professional
Windows 7 Firewall |
18 Jan 2013
|
#7 | | Windows 7 Home Premium 64 bit. (On both machines) Lincolnshire, UK. |
The questions I would like to ask are these: -
Do we need Java?
What are the alternatives? | My System Specs | | System Manufacturer/Model Number (PC) Gigabyte EG41MFT-US2H Self build. (Laptop) HP Dv7. OS Windows 7 Home Premium 64 bit. (On both machines) CPU (PC) Intel Quad Core Q6600: (Laptop) Turion II M520 Motherboard PC: as above. Laptop (HP System Board) 3639 33.23 Memory PC: Corsair DDR3 4GB Corsair Laptop: DDR-2 Micron 800 4 GB. Graphics Card ATI Asus HD6770: Laptop: ATI Mobile Radeon 4500. Sound Card Onboard. Monitor(s) Displays PC: Lyama Prolite E2407HDS 24" Laptop 17" Screen Resolution PC: 1920x1080. Laptop:1600x900 Keyboard Logitech MK 250 wireless. Mouse PC: Logitech MK 250 wireless. Laptop: Logitech Wireless M235 PSU OCZ 550 GX. Laptop - ? Case Black Coolermaster Centurion 5 II. Cooling 2x120 mm. Coolermaster front & rear: 120mm. CM side fan. Hard Drives Pc: WD 5000AAKS (O/s, Photos, Files.)
Seagate ST3100520AS 1TB (Films, Video)
Laptop: WDC WD32000BEKT-605t1
External Backup: another WD 5000AAKS, in Trust E-SATA case. Internet Speed (Rural Lincolnshire!) From 2 to 2.8 Mb. Other Info Clean-installed laptop. PC, networked as Master to laptop.
TV Tuner card "WinTV Nova T-500 Dual Tuner fitted, in order to watch sport & own film/TV choice without marital discord! NOTE: works fine, excellent Freeview reception in a poor signal area.
Laptop Mouse: tiny USB thumb drive, works fine. |
19 Jan 2013
|
#8 | | Windows 7 Home Premium 64-bit Service Pack 1 Lost in disambiguation |
And the beat goes on... Researchers find critical vulnerabilities in Java 7 Update 11 | Security - InfoWorld Quote: Researchers from Security Explorations, a Poland-based vulnerability research firm, claim to have found two new vulnerabilities in Java 7 Update 11 that can be exploited to bypass the software's security sandbox and execute arbitrary code on computers.
Oracle released Java 7 Update 11 last Sunday as an emergency security update in order to block a zero-day exploit used by cybercriminals to infect computers with malware.
Security Explorations successfully confirmed that a complete Java security sandbox bypass can be still be achieved under Java 7 Update 11 (JRE version 1.7.0_11-b21) by exploiting two new vulnerabilities discovered by the company's researchers, Adam Gowdiak, the company's founder, said Friday in a message sent to the Full Disclosure mailing list. The vulnerabilities were reported to Oracle on Friday, together with working proof-of-concept exploit code, he said.
According to Security Explorations' disclosure policy, technical details about the vulnerabilities will not be publicly disclosed until the vendor issues a patch. | My System Specs | | System Manufacturer/Model Number Gateway NV59C Notebook OS Windows 7 Home Premium 64-bit Service Pack 1 CPU Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz Motherboard Gateway V1.08 Memory 8GB Kingston DDR3 Graphics Card Intel HD Graphics Sound Card Realtek High Definition Audio Screen Resolution 1366x768 Hard Drives WDC WD2500BPVT-75JJ5T0 Other Info MSSE AV, FFox, Ex-PLODE-r 9 |
21 Jan 2013
|
#9 | | W7 pro 64bit, ult 32bit, hp 32bit, XP pro 32bit, W8 pro 32bit |
From the continuing stream of java scares, history seems to point towards there may never come a time when it's completely safe (even for shorter periods!).
F.ex., banks + many government websites here does all their authenticating using java, so it's not an option to uninstall it completely.
Solution is to use several browsers, disable java in the day-to-day browser (mainly FF w. security add-ons here), + a dedicated java-enabled browser (IE here) used exclusively to access the sites where java is mandatory. | My System Specs | | System Manufacturer/Model Number HP 6570b, 6730b, 6735b, 311c OS W7 pro 64bit, ult 32bit, hp 32bit, XP pro 32bit, W8 pro 32bit New Java Exploit Fetches $5,000 Per Buyer; Krebs on Security problems? All times are GMT -5. The time now is 03:16 PM. | |