Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - It's like sports for geeks.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Mozilla Firefox
4. Smart Defrag
5. MusicBee
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Sergei Strelec's WinPE
8. Visual C++ Redistributable Runtimes AIO Repack
9. Dolby AC-3/AC-4 Installer
10. McAfee Removal Tool (MCPR)
More >>

top reads

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff

Star Gmail Using Your Emails and Attachments for AI Training: Here's How To Opt Out


MajorGeeks.Com » News » February 2013 » Facebook engineers compromised by Java zero-day

Facebook engineers compromised by Java zero-day


Contributed by: Email on 02/18/2013 03:11 PM [ comments Comments ]


Facebook has confirmed that systems used by its employees were compromised in an attack which used a Java plugin zero-day exploit. The company explained that it found a suspicious domain in its DNS logs in January and traced it an employee laptop internally and a compromised web site which acted as the source. According to a report in Ars Technica the employee was one of the company's engineers.

Internal investigations discovered malware on that system and company-wide searches found "several other compromised employee laptops". All the laptops were "fully-patched and running up-to-date anti-virus software" the company says. Examining the compromised web site showed it was using a previously unseen Java vulnerability which bypassed the sandbox to allow it to install malware.

Facebook says it reported the exploit to Oracle and they received a patch on 1 February to address the issue. That is also the date on which Oracle released an emergency patch set for all Java users to fix fifty flaws, saying it had come across some of the fixed flaws being exploited in the wild and had brought the release forward from this coming Tuesday 19 February to 1 February because of that. It now seems very likely that the Facebook attack was at least one of the reports Oracle was acting upon. Facebook said it knew of other companies compromised by the same zero-day attack. Oracle has more fixes for Java in an updated version of the patches, due on Tuesday.

Further details of the attack were not given; however, Facebook did say that there was no evidence that any Facebook user data was compromised, though the attackers did gain "some limited visibility" into production systems and they were trying to "move laterally into our production environment". The attackers did harvest information from the laptops such as company emails, data and some code. The company says it is working with law enforcement and has collaborated through an informal working group with other affected companies.






« Lockheed Martin "almost missed" hacker intrusion · Facebook engineers compromised by Java zero-day · Man arrested for DUII released, re-arrested for bank robbery (LOL Mugshot) »




Comments
comments powered by Disqus

MajorGeeks.Com » News » February 2013 » Facebook engineers compromised by Java zero-day

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition