Security question - or - curiousity

Cliff789

New member
Member
Local time
3:27 PM
Messages
86
Running Win 7 makes it easier to keep administrator permissions separate as compared to XP which was a bit of a PITA. So I just don't run as administrator.

And as a result I get a popup about once a day from Oracle asking if they can modify my HD with a JAVA update. This is of a piece with the Windows updates that have been part of MS's service for so very long. Microsoft doesn't even stop to ask if it's OK to futz with your computer - they just up and do it.

Now here is the thing that bugs me:
How is it that hackers have not figured out how to impersonate these services? Seems to me that this would be the holy grail.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home built
OS
ASUS X79 DELUXE LGA 2011 Intel X79 SATA 6Gb/s USB 3.0 ATX
CPU
Intel Core i7-4930K Ivy Bridge-E 3.4GHz LGA 2011 130W 6-Core
Motherboard
ASUS X79 DELUXE LGA 2011 Intel X79 SATA 6Gb/s USB 3.0 ATX
Memory
CORSAIR Dominator Platinum 16GB (4 x 4GB) 240-Pin DDR3 SDRAM
Graphics Card(s)
ASUS EAH6450 Silent/DI/1GD3(LP) Radeon HD 6450 1GB 64-bit DD
Sound Card
onboard
Monitor(s) Displays
Dell lcd 32"
Hard Drives
1tb SATA, 2tb SATA, 500 gig SATA, 500 Gig SATA, 500 Gig IDE
PSU
CORSAIR HX Series HX750 750W ATX12V 2.3 / EPS12V 2.91 SLI Re
Case
something colored black
Cooling
Cooler Master Seidon 120XL
Keyboard
this thing with buttons on it
Mouse
a tailed devil
Internet Speed
whizzing along
Antivirus
KASPERSKY
Browser
Firefox. Opra, Explorer.
Other Info
I am naked and outside your window shouting Non Sequiturs in a loony high pitched voice.
Windows Update can be set to NOT automatically install updates.
It can notify you of updates before installing.
Check your Windows Update settings.

I don't have JAVA, but I'd be surprised if there is an update about once a day.
Are you sure the update is successful, and it's not the same update being offered again?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
I don't have Java installed either and have not had any issues surfing the internet so if you don't know what Java is or does (like I don't) Please Uninstall it.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
You can try this

Click the Windows "Start" button and select the "Control Panel" item found on the right side of the Start Menu.

Click within the search box located at the top-right corner of the resulting window and type "Java."

Click the "Java" item that appears in the list of search results. The Java Control Panel pops up on your screen within a few seconds.


Select the "Update" tab located near the top of the Java Control Panel window.


Uncheck the box labeled "Check for Updates Automatically."



Click the "Never Check" button when prompted.



Click "OK" to confirm your choice and close the Java Control Panel.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I'd be surprised if there is an update about once a day.
Are you sure the update is successful, and it's not the same update being offered again?

Google it, there's lots of people reporting it.
It may be a buggy install that keeps trying over and over again. I'll unistal the whole bloody thing and reinstall fresh But still the original question goes on addressed. What keeps hackers from mimicking those things? Massive individualized code on each operating system that only the mother ship knows? If the NSA gets hacked how come they don't?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home built
OS
ASUS X79 DELUXE LGA 2011 Intel X79 SATA 6Gb/s USB 3.0 ATX
CPU
Intel Core i7-4930K Ivy Bridge-E 3.4GHz LGA 2011 130W 6-Core
Motherboard
ASUS X79 DELUXE LGA 2011 Intel X79 SATA 6Gb/s USB 3.0 ATX
Memory
CORSAIR Dominator Platinum 16GB (4 x 4GB) 240-Pin DDR3 SDRAM
Graphics Card(s)
ASUS EAH6450 Silent/DI/1GD3(LP) Radeon HD 6450 1GB 64-bit DD
Sound Card
onboard
Monitor(s) Displays
Dell lcd 32"
Hard Drives
1tb SATA, 2tb SATA, 500 gig SATA, 500 Gig SATA, 500 Gig IDE
PSU
CORSAIR HX Series HX750 750W ATX12V 2.3 / EPS12V 2.91 SLI Re
Case
something colored black
Cooling
Cooler Master Seidon 120XL
Keyboard
this thing with buttons on it
Mouse
a tailed devil
Internet Speed
whizzing along
Antivirus
KASPERSKY
Browser
Firefox. Opra, Explorer.
Other Info
I am naked and outside your window shouting Non Sequiturs in a loony high pitched voice.
I can't answer why things like the MS Update process/service is not hacked - I'm not a hacker...
I wouldn't be surprised if hackers do try...
If that ever happens, things will be MUCH worse imho, if we can't trust getting Windows updates securely/reliably.
I would guess MS has put a lot of effort into making sure their update process is secure...

Are you sure you need JAVA?
I removed it and have found no website I must use that requires it...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
There is cryptography involved. So it is not easily hacked.
 

My Computer

OS
Windows
How is it that hackers have not figured out how to impersonate these services? Seems to me that this would be the holy grail.
"Automatic software updates" just mean that the software installs a component in your PC that periodically initates a secure connection to its own download server.
This goes on without you knowing, but it's all stuff inside your PC that connects to its download server and asks "is this the last version?"

Goes without saying that you can disable this madness by either the program's own options (java has its own entry in Control Panel, icon view, the same for flash, and windows update can be set to not download automatically updates) or by removing manually entries of the update-checking components from startup, step 2 of this tutorial.

Being internet what it is, hacking something like this could theoretically happen in three broad ways:

-something (read: malware) modifies the address that the update-checking component uses to ask its questions and download stuff and redirects it to a malware server.

-someone intercepts the connection while en-route and swaps its stuff instead of the updates

-someone hacks the update server

Now, the first possibility is kinda stupid, as any malware that can do that would be perfectly capable of downloading whatever it wants on its own without screwing up other programs in the first place.
Quite a few advanced ones do have such "features", and update themselves from other infected PCs if their malware's "version" was newer.

Second is possible but horribly complex to pull off as the would-be hacker would have to exploit less-secure areas of the network between you and the download server. Which usually means hacking the wifi network you are connected to, or physically tampering with network infrastructure. Either is doable but risky, and does not allow a big-enough spread of the malware to make it worthwhile.

The last is possible but again complex to pull off. Any serious server admin are expecting this kind of tampering, and usually the download server is impregnable to such attacks. After all it just does have to answer a couple questions and upload stuff, it's not that hard to lock it down.
Yes, you can force it to crash or do the usual denial-of-service attacks, but there is no way of stealing its IP address to make a shadow server in the meantime.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom built
OS
Win 7 Pro 64-bit 7601
CPU
AMD Phenom 9650 QuadCore, revision DR-B3
Motherboard
ASUS M4A78
Memory
5 GB yes I run 2x 2GB and 1x 1GB, different brand, spank me.
Graphics Card(s)
NVIDIA GeForce 9800 GT 512 Mb, unknown manufacturer.
Sound Card
Crappy Realtek Integrated Audio
Monitor(s) Displays
Fujitsu Siemens P19-3P
Screen Resolution
1280 x 1024 x 32 bits @ 60 Hz Oh yeah, 4:3 rocks!
Hard Drives
(1) MAXTOR S TM3320613AS SATA Disk Device (2) STM35004 18AS SATA Disk Device (3) TOSHIBA USB 2.5"-HDD
PSU
whatever, around 450w
Case
Scavenged from old company PC, 10+ years old
Cooling
CPU fan, GPU fan, case fan, nothing fancy
Keyboard
Microsoft, PS/2, white.
Mouse
Optical, logitec.
Internet Speed
effective max speeds: 70-ish kB/s down 30-ish kB/s up
Antivirus
Avira, free edition.
Browser
Firefox with FXChrome to make it look like Google Chrome :P
Other Info
Was discarded by previous owner due to "horrible performance".
Was running Win Xp from a IDE drive. Yeah. Was a pain.
SATA II drive and Win7 and it zips away! Yay!
Back
Top