Web malware exploitation kits updated with new Java exploit

lehnerus2000

New member
Guru
Gold Member
VIP
Local time
4:20 AM
Messages
4,058
Location
Adelaide

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
n/a
OS
W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, W10 Pro 1703 VM, #All 64 bit
CPU
AMD Phenom II x6 1100T, 3.3 GHz
Motherboard
ASUS M4A88T-M/USB3 (AM3)
Memory
12GB DDR3 1333 G-Skill (4GB x 2), G-Skill (2GB x 2)
Graphics Card(s)
NVIDIA GeForce GTX 660
Sound Card
Realtek?
Monitor(s) Displays
Samsung S23B350
Screen Resolution
1920x1080
Hard Drives
WD Green 2TB (SATA), WD Green 3TB (SATA), WD Blue 4TB (SATA), WD Blue 6TB (SATA)
PSU
Cooler Master
Case
Antec GX300 Tower
Cooling
3x Antec TRICOOL 120mm Fans
Mouse
Wired Optical
Internet Speed
DSL
Antivirus
Avast
Browser
Pale Moon (64 bit)
Other Info
2018-12-27 Upgraded HDDs
2015-12-10 Upgraded case, graphics card, storage
2015-08-15 Upgraded motherboard & RAM
2015-07-15 Upgraded LM17.1 to LM17.2
That does it - uninstalling Java. I only ever saw it used for the F1 live timing, and that's off until March, anyway.
 

My Computer

Computer Manufacturer/Model Number
CreepinJesus Mk. IV
OS
Windows 7 Ultimate x64
CPU
Intel Core i5-2500 3.3GHz
Motherboard
Asus P8H67-M PRO
Memory
8GB DDR3 1333MHz
Graphics Card(s)
On-board
Sound Card
On-board
Monitor(s) Displays
Samsung SyncMaster BX2250 22.5" LED-backlit LCD
Screen Resolution
1920 * 1080
Hard Drives
OCZ Agility 3 120GB, SATA-III
PSU
Thermaltake Toughpower Grand TPG-650M
Case
Lian-Li PC-A04
Cooling
Standard fans. They blow.
Keyboard
Logitech K360
Mouse
Generic Logitech from the bargain-bin by the checkout
Internet Speed
Over 9000! ...Mbps.
Other Info
Chocolate digestives are my favourite biscuit.
I don't have it installed on my actual PC.

I need it for my networking course (Cisco Packet Tracer) so I've created a VM and installed Java in that.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
n/a
OS
W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, W10 Pro 1703 VM, #All 64 bit
CPU
AMD Phenom II x6 1100T, 3.3 GHz
Motherboard
ASUS M4A88T-M/USB3 (AM3)
Memory
12GB DDR3 1333 G-Skill (4GB x 2), G-Skill (2GB x 2)
Graphics Card(s)
NVIDIA GeForce GTX 660
Sound Card
Realtek?
Monitor(s) Displays
Samsung S23B350
Screen Resolution
1920x1080
Hard Drives
WD Green 2TB (SATA), WD Green 3TB (SATA), WD Blue 4TB (SATA), WD Blue 6TB (SATA)
PSU
Cooler Master
Case
Antec GX300 Tower
Cooling
3x Antec TRICOOL 120mm Fans
Mouse
Wired Optical
Internet Speed
DSL
Antivirus
Avast
Browser
Pale Moon (64 bit)
Other Info
2018-12-27 Upgraded HDDs
2015-12-10 Upgraded case, graphics card, storage
2015-08-15 Upgraded motherboard & RAM
2015-07-15 Upgraded LM17.1 to LM17.2
I can understand the frustration. And I hate to be too simplistic, but a lot of falling prey to malware can be avoided by only visiting trusted sites. Of course, I understand "trusted" is a relative term and some crappy sites might be "trusted" by some. But still. Keep things simple.
 

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 1520 (Laptop)/ Home (Desktop)
OS
Windows 7 x64 / Same
CPU
Intel Core 2 Duo T7250 / Intel Core i7 930
Motherboard
Intel 945 / Asus P6X58D-E
Memory
4GB / 6GB
Graphics Card(s)
NVIDIA GeForce 8400M GS / ASUS 1GB
Sound Card
Whatever Dell gave me :-( / Onboard
Monitor(s) Displays
15.4" LCD / Crappy CRT
Hard Drives
Seagate 500GB SATA; 7200 RPM / Seagate 1TB SATA; 7200 RPM
PSU
N/A / OCZ Fatal1ty 550W Modular
Case
N/A / Antec 900
Cooling
Air
Mouse
Microsoft Presenter (Bluetooth)
I'm afraid that "Trusted Sites" are a myth

"Trusted Sites" can be compromised. :(

Linux repository
Linux repository hit by malware attack | TechRepublic

Google
Google busts itself for distributing malware | ZDNet

Your only real defence is regular patching/updating and frequent external backups.
Trojans, viruses, worms: How does malware get on PCs and Macs? | ZDNet

The only "Trusted Site" that is a possible exception, is a site that you:

  • Coded/created.
  • Are intimately familiar with every object in it.
  • Regularly check for unauthorised modifications.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
n/a
OS
W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, W10 Pro 1703 VM, #All 64 bit
CPU
AMD Phenom II x6 1100T, 3.3 GHz
Motherboard
ASUS M4A88T-M/USB3 (AM3)
Memory
12GB DDR3 1333 G-Skill (4GB x 2), G-Skill (2GB x 2)
Graphics Card(s)
NVIDIA GeForce GTX 660
Sound Card
Realtek?
Monitor(s) Displays
Samsung S23B350
Screen Resolution
1920x1080
Hard Drives
WD Green 2TB (SATA), WD Green 3TB (SATA), WD Blue 4TB (SATA), WD Blue 6TB (SATA)
PSU
Cooler Master
Case
Antec GX300 Tower
Cooling
3x Antec TRICOOL 120mm Fans
Mouse
Wired Optical
Internet Speed
DSL
Antivirus
Avast
Browser
Pale Moon (64 bit)
Other Info
2018-12-27 Upgraded HDDs
2015-12-10 Upgraded case, graphics card, storage
2015-08-15 Upgraded motherboard & RAM
2015-07-15 Upgraded LM17.1 to LM17.2
If a person uninstalled everything that an exploitation was found in, it wouldn't take long before that person wouldn't have anything on their machine, including an OS. I would look for another solution.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)

True, not EVERY site can be protected ALL the time. But c'mon. How often/likely is that?

Your only real defence is regular patching/updating and frequent external backups.
Trojans, viruses, worms: How does malware get on PCs and Macs? | ZDNet

Not totally true. Having good AV and firewall software helps defend against attack.

The only "Trusted Site" that is a possible exception, is a site that you:

  • Coded/created.
  • Are intimately familiar with every object in it.
  • Regularly check for unauthorised modifications.

Umm...didn't you explain in your first point that any trusted site can be exploited? It doesn't matter if you coded it or not. Even your code is never bulletproof.
 

My Computer

Computer Manufacturer/Model Number
Dell Inspiron 1520 (Laptop)/ Home (Desktop)
OS
Windows 7 x64 / Same
CPU
Intel Core 2 Duo T7250 / Intel Core i7 930
Motherboard
Intel 945 / Asus P6X58D-E
Memory
4GB / 6GB
Graphics Card(s)
NVIDIA GeForce 8400M GS / ASUS 1GB
Sound Card
Whatever Dell gave me :-( / Onboard
Monitor(s) Displays
15.4" LCD / Crappy CRT
Hard Drives
Seagate 500GB SATA; 7200 RPM / Seagate 1TB SATA; 7200 RPM
PSU
N/A / OCZ Fatal1ty 550W Modular
Case
N/A / Antec 900
Cooling
Air
Mouse
Microsoft Presenter (Bluetooth)
I did say "... possible exception ..."


True, not EVERY site can be protected ALL the time. But c'mon. How often/likely is that?

Not much comfort if you happen to be the poor sap, who goes to a site during the few hours that it is compromised. :cry:

Did I say hours?
IIRC, the Linux repository was compromised for "at least 17 days".

Google codeplex had malware on it for over a month!
Malware hosted on Google Code project site | ZDNet
More nasties found on Google Code repository | ZDNet

SourceForge also had dodgy links.
SourceForge is still harboring pornography and malware | ExtremeTech

If you can compromise Google for a few hours; you can potentially ensnare thousands (if not millions) of users.
This is the problem with the "Cloud", it is a "single point of failure".
Every criminal knows "where it is" and they will be attacking it.

They only have to get lucky once, whereas the provider has to be 100% successful at stopping thousands (if not millions) of attacks per day.

Your only real defence is regular patching/updating and frequent external backups.
Trojans, viruses, worms: How does malware get on PCs and Macs? | ZDNet

Not totally true. Having good AV and firewall software helps defend against attack.

D'oh! :o

A firewall is important in Windows (and on a server).
The Ubuntu firewall (iptables) doesn't have any rules in it by default (i.e. all actions/connections are allowed).
The CentOS (server) firewall (iptables) has rules blocking most external actions/connections by default.

AV software is reactive and limited by the speed of signature updates.
Apparently some malware has the ability to "mutate" itself, so that signature scanners are less likely to detect it! :shock:

I should have included this link.
http://www.sevenforums.com/security-news/190482-if-your-pc-picks-up-virus-whose-fault.html

If you read the article that is linked from that link, patching and a running firewall kept most of the PCs malware free, without an AV program (or other human intervention).

The only "Trusted Site" that is a possible exception, is a site that you:

  • Coded/created.
  • Are intimately familiar with every object in it.
  • Regularly check for unauthorised modifications.

Umm...didn't you explain in your first point that any trusted site can be exploited? It doesn't matter if you coded it or not. Even your code is never bulletproof.

I did say "... possible exception ...".

It depends on how much code you have and how often it is monitored (assuming you host it on a machine that you control).
A "Hello World" web page would only be a few lines of html, so it should be no problem to check it for alterations (every few minutes if necessary).
Of course it wouldn't be very useful web page. :)

If the page is hosted on someone else's machine or it has thousands of lines of code (e.g. databases, js, Flash, embedded media players, etc.) the chances of the page getting hijacked increase dramatically.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
n/a
OS
W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, W10 Pro 1703 VM, #All 64 bit
CPU
AMD Phenom II x6 1100T, 3.3 GHz
Motherboard
ASUS M4A88T-M/USB3 (AM3)
Memory
12GB DDR3 1333 G-Skill (4GB x 2), G-Skill (2GB x 2)
Graphics Card(s)
NVIDIA GeForce GTX 660
Sound Card
Realtek?
Monitor(s) Displays
Samsung S23B350
Screen Resolution
1920x1080
Hard Drives
WD Green 2TB (SATA), WD Green 3TB (SATA), WD Blue 4TB (SATA), WD Blue 6TB (SATA)
PSU
Cooler Master
Case
Antec GX300 Tower
Cooling
3x Antec TRICOOL 120mm Fans
Mouse
Wired Optical
Internet Speed
DSL
Antivirus
Avast
Browser
Pale Moon (64 bit)
Other Info
2018-12-27 Upgraded HDDs
2015-12-10 Upgraded case, graphics card, storage
2015-08-15 Upgraded motherboard & RAM
2015-07-15 Upgraded LM17.1 to LM17.2
I like to keep Java and Adobe Flash disabled on my Firefox for this very reason. Too many security issues. I don't really need Java or Adobe Flash. YouTube has added HTML5 to the experimental lab - so I have that enabled instead of using Flash.
 

My Computer

Computer Manufacturer/Model Number
xxxxxxx
OS
xxxxxxxxxxxxxxxxxxxxxxx
CPU
xxxxxxxxxxxxxxxxxx
Motherboard
xxxxxxxxxxx
Memory
xxxxxxxxxxx

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
n/a
OS
W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, W10 Pro 1703 VM, #All 64 bit
CPU
AMD Phenom II x6 1100T, 3.3 GHz
Motherboard
ASUS M4A88T-M/USB3 (AM3)
Memory
12GB DDR3 1333 G-Skill (4GB x 2), G-Skill (2GB x 2)
Graphics Card(s)
NVIDIA GeForce GTX 660
Sound Card
Realtek?
Monitor(s) Displays
Samsung S23B350
Screen Resolution
1920x1080
Hard Drives
WD Green 2TB (SATA), WD Green 3TB (SATA), WD Blue 4TB (SATA), WD Blue 6TB (SATA)
PSU
Cooler Master
Case
Antec GX300 Tower
Cooling
3x Antec TRICOOL 120mm Fans
Mouse
Wired Optical
Internet Speed
DSL
Antivirus
Avast
Browser
Pale Moon (64 bit)
Other Info
2018-12-27 Upgraded HDDs
2015-12-10 Upgraded case, graphics card, storage
2015-08-15 Upgraded motherboard & RAM
2015-07-15 Upgraded LM17.1 to LM17.2
Use noscript and block java and flash until you actually need it on sites you trust. That is the best practice.
 

My Computer

Computer Manufacturer/Model Number
Samsung rv520
OS
Windows Seven, Ubuntu
CPU
Intel
Graphics Card(s)
Intel
NoScript in Chrome and FireFox. NotScript in Opera to disable! :)
 

My Computer

Computer Manufacturer/Model Number
ADVENT / Dell Inc.
OS
MS Windows 7 Home Premium 64-bit SP1
CPU
Intel Core i5-2320 @ 3 Ghz / Intel Core i5 @ 2.67GHz
Motherboard
ADVENT / Dell Inc. (CPU 1)
Memory
8.00 GB / 6.00 GB Dual-Channel DDR3 @ 532MHz
Graphics Card(s)
Sapphire HD 6670 AMD / ATI Mobility Radeon HD 5650
Sound Card
IDT High Definition Audio CODEC
Monitor(s) Displays
BenQ G2222HDL 21.5-inch Widescreen LED Back-Light Monitor
Screen Resolution
1980 x 1080
Hard Drives
1.5 TB / 640GB (SATA)
PSU
Dell AC/DC Power Adapter
Case
ADVENT / Dell Inspiron 15R
Cooling
Microsoft Cooling Base
Keyboard
Logitech MK260 Wireless Keyboard
Mouse
Logitech Wireless Mouse M310
Other Info
Sennheiser HD 202 / Koss Porta Pro Stereo Headphones
wait wouldn't disabling java give problems when visiting some websites :|
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 10 64bit
CPU
AMD Phenom II X4 925 (Deneb)(2.8GHz) OC 3.4GHz
Motherboard
M5A78L-MLX Plus
Memory
Corsair Vengeance DDR3 4GBX2 (8192MB)
Graphics Card(s)
XFX HD 6870 1GB (OC)- 940MHz core, mem 1150MHz
Monitor(s) Displays
Vizio 26' 1920x1080 / Acer 1336x768
Screen Resolution
1920x1080 60Hz /1336x768
Hard Drives
Kingston Digital 60GB SSDNow V300/500gb HDD Western Digital 7200rpm (/WD 160GB HDD 7200rpm
PSU
CORSAIR CX600 600w
Case
AZZA Orion 202 EVO
Cooling
cooler master hyper TX3 cpu cooler
Keyboard
Razer DeathStalker
Mouse
Logitech Optical Gaming Mouse G400
Antivirus
Defualt on win 10
Browser
Firefox
Other Info
cpu is overclocked in bios
wait wouldn't disabling java give problems when visiting some websites :|

Very few I've found but YMMV - other issues sometimes cause problems though e.g some software requires Java.

;) :huh: :rolleyes:
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Compaq desktop
OS
Windows 7 x64 SP1
CPU
Athlon II x2 215
Memory
4.0 GB
Graphics Card(s)
Onboard
Sound Card
Creative SB X-Fi Titanium HD (nice)
Monitor(s) Displays
24" Dell LCD
Screen Resolution
1900 x 1200
Hard Drives
320 GB, 500 GB and 750 GB 7200 rpm
PSU
430w
Keyboard
USB
Mouse
USB
Internet Speed
approx 10 Mbps
Back
Top