Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

Just when you thought things couldn't get Geekier - MajorGeeks.Com.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » February 2013 » Facebook engineers compromised by Java zero-day

Facebook engineers compromised by Java zero-day


Contributed by: Email on 02/18/2013 03:11 PM [ comments Comments ]


Facebook has confirmed that systems used by its employees were compromised in an attack which used a Java plugin zero-day exploit. The company explained that it found a suspicious domain in its DNS logs in January and traced it an employee laptop internally and a compromised web site which acted as the source. According to a report in Ars Technica the employee was one of the company's engineers.

Internal investigations discovered malware on that system and company-wide searches found "several other compromised employee laptops". All the laptops were "fully-patched and running up-to-date anti-virus software" the company says. Examining the compromised web site showed it was using a previously unseen Java vulnerability which bypassed the sandbox to allow it to install malware.

Facebook says it reported the exploit to Oracle and they received a patch on 1 February to address the issue. That is also the date on which Oracle released an emergency patch set for all Java users to fix fifty flaws, saying it had come across some of the fixed flaws being exploited in the wild and had brought the release forward from this coming Tuesday 19 February to 1 February because of that. It now seems very likely that the Facebook attack was at least one of the reports Oracle was acting upon. Facebook said it knew of other companies compromised by the same zero-day attack. Oracle has more fixes for Java in an updated version of the patches, due on Tuesday.

Further details of the attack were not given; however, Facebook did say that there was no evidence that any Facebook user data was compromised, though the attackers did gain "some limited visibility" into production systems and they were trying to "move laterally into our production environment". The attackers did harvest information from the laptops such as company emails, data and some code. The company says it is working with law enforcement and has collaborated through an informal working group with other affected companies.






« Lockheed Martin "almost missed" hacker intrusion · Facebook engineers compromised by Java zero-day · Man arrested for DUII released, re-arrested for bank robbery (LOL Mugshot) »




Comments
comments powered by Disqus

MajorGeeks.Com » News » February 2013 » Facebook engineers compromised by Java zero-day

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition