Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - We'e your CTRL+D site.. right?.. RIGHT?

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Sergei Strelec's WinPE
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Visual C++ Redistributable Runtimes AIO Repack
8. McAfee Removal Tool (MCPR)
9. K-Lite Mega Codec Pack
10. Visual C++ Runtime Installer (All-In-One)
More >>

top reads

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff


MajorGeeks.Com » News » August 2012 » Warning on critical Java hole

Warning on critical Java hole


Contributed by: Email on 08/27/2012 03:03 PM [ comments Comments ]


The current version of Java contains a serious security hole that allows computers to be infected with malicious code when a specially crafted web page is visited. The hole is already being exploited in the wild – although currently only for targeted attacks. But since an exploit is now in circulation, it shouldn't be long before criminals exploit the vulnerability for large-scale attack waves.

The H's associates at heise Security have managed to recreate the problem and have built a proof-of-concept page using information that is publicly available. When the page is accessed, the Java plugin executes a process, in this case calc.exe, without requesting any prior confirmation. Instead of launching the calculator, the web page could have downloaded and executed a malicious program.

Small effort with a large security gain: in Firefox, disable Java in the Add-ons menu under Plugins

All versions of the 7.x branch of Java are affected. In tests, the exploit worked under Windows with all popular browsers including Google Chrome. This conclusion disproves the findings of DeepEnd Research's security experts, who said that the vulnerability can't be exploited under Chrome. Those who have Java installed on their systems should disable the browser plugin – at least until Oracle has released a patch.

It is also worth considering whether to put the Java browser plugin out to pasture for good. After all, coming across a web page that uses Java for legitimate purposes is rather unlikely these days. A secondary browser can be installed for accessing web pages that can't avoid using Java. Local Java applications will still start normally when the plugin is disabled.

The targeted attacks that have been registered so far have exploited the hole to install the Poison Ivy trojan. The malware for these attacks is hosted on a server in Singapore. Oracle has not yet commented on the problem; at present, it is therefore unknown when the vulnerability will be fixed. The next regular Java update is scheduled to be released on 16 October.






« Is the mysterious 'Spike Wells’ really Prince Harry? · Warning on critical Java hole · New Java Zero Day Being Used in Targeted Attacks »




Comments
comments powered by Disqus

MajorGeeks.Com » News » August 2012 » Warning on critical Java hole

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition