<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[DriverPacks.net Forum - You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
	<link rel="self" href="http://forum.driverpacks.net/extern.php?action=feed&amp;tid=6227&amp;type=atom"/>
	<updated>2013-01-17T06:05:51Z</updated>
	<generator>PunBB</generator>
	<id>http://forum.driverpacks.net/viewtopic.php?id=6227</id>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=50525#p50525"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>Neil McAllister of TheReg wrote:</cite><blockquote><p><strong>&quot;Surprised? Old Java exploit helped spread Red October spyware</strong><br /><em>New Java exploit can be yours for $5,000</em><strong>&quot;</strong></p><p>...</p><p>&quot;Metasploit founder HD Moore claims it will likely take Oracle two years to get its Java security house in order, given its past track record.&quot;</p><p>&nbsp; &nbsp;<em><span class="bbu">Quoted from:</span>&nbsp; <a href="http://www.theregister.co.uk/2013/01/16/red_october_java_connection/">http://www.theregister.co.uk/2013/01/16 … onnection/</a></em></p></blockquote></div>]]></content>
			<author>
				<name><![CDATA[TechDud]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=14671</uri>
			</author>
			<updated>2013-01-17T06:05:51Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=50525#p50525</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=50504#p50504"/>
			<content type="html"><![CDATA[<p>Respectfully, Oracle is not the only organization where one might demand progress.</p><p>&nbsp; <a href="http://markey.house.gov/sites/markey.house.gov/files/documents/2013-01-11_DOE_RadioActive_ScrapMetal.pdf">http://markey.house.gov/sites/markey.ho … pMetal.pdf</a></p><p><em>from <a href="http://enenews.com/gundersen-u-s-govt-to-allow-highly-radioactive-material-from-nuclear-plants-into-silverware-other-items-audio">http://enenews.com/gundersen-u-s-govt-t … tems-audio</a></em></p>]]></content>
			<author>
				<name><![CDATA[TechDud]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=14671</uri>
			</author>
			<updated>2013-01-15T06:43:39Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=50504#p50504</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=50498#p50498"/>
			<content type="html"><![CDATA[<p>Comments I&#039;ve read today say update 11 is not a good &#039;fix&#039; but merely a patch pending a better solution by Oracle</p>]]></content>
			<author>
				<name><![CDATA[ChiefZeke]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=3134</uri>
			</author>
			<updated>2013-01-14T21:45:31Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=50498#p50498</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=50481#p50481"/>
			<content type="html"><![CDATA[<p>1) <strong><em>&quot;Calling all java-enabled &#039;mobe users:&quot;,</em></strong><br /> ... maybe all at once on a special 900 number from a Caymen Island, nowhere near YOU for 5 quid a minute?<br /><em>At least the black hats are not pushing the &quot;reset code #&quot;, yet afik.</em><br /></p><div class="quotebox"><cite>John Leyden from The Register wrote:</cite><blockquote><p>&quot;A new Java zero-day security vulnerability is already being actively exploited to compromise PCs. The best way to defend against the attacks is to disable any Java browser plugins on your systems.&quot;<br /><a href="http://www.theregister.co.uk/2013/01/10/java_0day/">http://www.theregister.co.uk/2013/01/10/java_0day/</a></p></blockquote></div><p>see also <a href="http://phys.org/news/2013-01-java-software-peril.html">http://phys.org/news/2013-01-java-software-peril.html</a><br />This may be a sign of how bad the situation truly is.<br />&nbsp; It made for a headline in Phys.org, a Physics news site!</p><p>&nbsp; &nbsp; That article originates from SecureList; quoted below.<br /><a href="https://www.securelist.com/en/blog/208194070/Java_0day_Mass_Exploit_Distribution">https://www.securelist.com/en/blog/2081 … stribution</a><br /></p><div class="quotebox"><cite>Kurt Baumgartner, a Kaspersky Lab Expert wrote:</cite><blockquote><p><strong>&quot;</strong>One of the best statements that I have seen in regards to the fairly impractical &quot;just uninstall it&quot; approach was presented by one of the handlers at the ISC Storm Center in today&#039;s issue of SANS NewsBites: It seems each time a zero day exploit is found in software, be that Java or otherwise, the industry pundits recommend that people stop using that software. New vulnerabilities will always be discovered in the software we use. If our best defence to a threat is to cause a denial-of-service on ourselves then this in the long term is a no-win strategy for us as an industry. We need to be looking at better ways to defend our systems and data, one good place to start is the 20 Critical Security Controls <a href="http://www.sans.org/critical-security-controls/">http://www.sans.org/critical-security-controls/</a><strong>&quot;</strong></p></blockquote></div><p>2) Tangentially, Firefox20 development builds render Flash content with the built-in HTML5 engine.&nbsp; That will allow many to say goodbye to the official product with it&#039;s questionable oft-communicating auto-updater that doesn&#039;t auto-update, nor has it had to for some time now (until today that is).<br /> For now, if you absolutely have to render these documents in a browser, they can be rendered via HTML5 &amp; JavaScript (sadly not controllable with NoScript, afik) on Firefox with <a href="http://mozilla.github.com/pdf.js/">this mozilla plugin</a>, which is reviewed <a href="http://www.theregister.co.uk/2013/01/11/firefox_beta_shows_pdfs_without_plugin/">here</a>.</p><p>Krzysztof Kowalczyk&#039;s <a href="http://blog.kowalczyk.info/software/sumatrapdf/free-pdf-reader.html">SumatraPDF</a> offers a free standalone application.</p><div class="quotebox"><cite>John Leyden wrote:</cite><blockquote><p>&quot;&#039;Better than Adobe&#039; Foxit PDF plugin hit by worse-than-Adobe 0-day<br /><em>New security hole: How an evil URL will ruin your day</em>&quot;<br /><a href="http://www.theregister.co.uk/2013/01/11/foxit_pdf_plugin_vuln/">http://www.theregister.co.uk/2013/01/11 … ugin_vuln/</a></p></blockquote></div><br /><p>3) Also, here is a thought-provoking article by Alexander Gostev, via SecureList, &amp; Kaspersky Labs.&nbsp; Every DriverPack member should become aware of what the issues are.&nbsp; I reason that it is one based upon &quot;collisions&quot; with existing Security Catalogs and other Certificates, though i have no examples.&nbsp; Correct me if i am wrong.<br /><a href="https://www.securelist.com/en/analysis/204792257/Kaspersky_Security_Bulletin_2012_Cyber_Weapons">https://www.securelist.com/en/analysis/ … er_Weapons</a></p><br /><p>4) Even Canonical&#039;s Ubuntu (&amp; therefore distro&#039;s built upon Ubuntu - incl. linuxMint) is now reportedly spying upon users:<br /><a href="http://www.neowin.net/news/richard-stallman-accuses-ubuntu-of-spying-on-users">http://www.neowin.net/news/richard-stal … g-on-users</a><br />I&#039;ve got my eye on <a href="http://www.linuxmint.com/download_lmde.php">LinuxMint Debian Xfce</a>, so-to-speak, not literally that is.</p><br /><p>5) In the ilk of <strong><em>&quot;only Nixon could go to China&quot;</em></strong>,<br /> <span class="bbu">only Google Chairman Eric Schmidt could go to North Korea!</span><br />&nbsp; &nbsp; &nbsp; &nbsp;<em>&quot;Stone-Cold State Dept. said so&quot;</em><br /><a href="http://allthingsd.com/20130112/north-korea-to-google-chairman-rock-on-dude/">http://allthingsd.com/20130112/north-ko … k-on-dude/</a></p><br /><p>6) It all reminds me, in a abstract sense, of the 300+ tonne <a href="http://enenews.com/reactor-vessel-slips-railroad-track-nuclear-plant-photo">&quot;slipped&quot; vessel</a>, the <a href="http://enenews.com/bizarre-disappearance-nuclear-plant-operator-carjacking-private-jet-100000-gold-bars-audio">alleged outlaw carjacking, gold bar transmuting, fleet-footed Senior Nuclear Operator</a> currently allegedly on the lam, or the tanker&#039;s meeting with San Francisco&#039;s <a href="http://enenews.com/coast-guard-briefing-oil-tanker-directed-4000-feet-boom-scene-sf-bridge-monitoring-signs-product-entering-water-video">Bay Bridge</a>!</p><br /><p>7) Alright, break&#039;s over; we know what we&#039;re up against.&nbsp; Let&#039;s get <a href="http://phys.org/news/2013-01-giant-squid-pacific-depths-japan.html#ajTabs">Krakken</a>!<br />After all, it&#039;s far better to be proactive, than reactive.<br />&nbsp; Like with electricity (no pun intended or harmed)<br />&nbsp; &nbsp; &nbsp; &nbsp;<a href="http://www.theregister.co.uk/2013/01/09/electricity_starvation_rations/">http://www.theregister.co.uk/2013/01/09 … n_rations/</a>.<br />&nbsp; &nbsp;1.5 kiloWatts?&nbsp; What would Doc. Emmet Brown think?</p><p>Slow news week?&nbsp; I think not!</p><br /><p><em><span class="bbu">Edit:</span>&nbsp; Now that&#039;s how i celebrate a thousandth post!</em>&nbsp; &nbsp;<img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></content>
			<author>
				<name><![CDATA[TechDud]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=14671</uri>
			</author>
			<updated>2013-01-12T20:48:57Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=50481#p50481</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=49666#p49666"/>
			<content type="html"><![CDATA[<p>Indeed.<br /></p><div class="quotebox"><cite>Michael Mimoso wrote:</cite><blockquote><p><span class="bbu">&quot;Oracle Leaves Fix for Java SE Zero Day Until February Patch Update&quot;</span><br /><a href="http://threatpost.com/en_us/blogs/oracle-leaves-fix-java-se-zero-day-until-february-patch-update-101712">http://threatpost.com/en_us/blogs/oracl … ate-101712</a></p><p><span class="bbu">&quot;Researcher Develops Patch for Java Zero-Day, Puts Pressure on Oracle to Deliver its Fix&quot;</span><br /><em>&quot;A security researcher has submitted to Oracle a patch he said took him 30 minutes to produce that would repair a zero-day vulnerability currently exposed in Java SE. He hopes his actions will spur Oracle to issue an out-of-band patch for the sandbox-escape vulnerability, rather than wait for the February 2013 Critical Patch Update as Oracle earlier said it would.&quot;</em><br /><a href="http://threatpost.com/en_us/blogs/researcher-develops-patch-java-zero-day-puts-pressure-oracle-deliver-its-fix-102212">http://threatpost.com/en_us/blogs/resea … fix-102212</a>&nbsp; <img src="http://forum.driverpacks.net/img/smilies/sad.png" width="15" height="15" alt="sad" /></p></blockquote></div>]]></content>
			<author>
				<name><![CDATA[TechDud]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=14671</uri>
			</author>
			<updated>2012-11-01T05:36:53Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=49666#p49666</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=49099#p49099"/>
			<content type="html"><![CDATA[<p>Oops.</p>]]></content>
			<author>
				<name><![CDATA[mr_smartepants]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=1602</uri>
			</author>
			<updated>2012-09-01T06:11:03Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=49099#p49099</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=49090#p49090"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>Neil McAllister in San Francisco for The Register wrote:</cite><blockquote><p>&quot;<strong><span class="bbu">Oracle rushes out patch for critical 0-day Java exploit</span></strong><br />&#039;Everything&#039;s fine now, please don&#039;t delete us&#039;&nbsp; <img src="http://forum.driverpacks.net/img/smilies/lol.png" width="15" height="15" alt="lol" /></p><p><em>By Neil McAllister in San Francisco&quot;</em></p><p>&quot;Maurice said that the vulnerabilities patched only affect Java running in browsers, and not standalone desktop Java applications or Java running on servers. According to Oracle&#039;s official advisory on the flaws:</p><p>&nbsp; &nbsp; <strong>These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password. To be successfully exploited, an unsuspecting user running an affected release in a browser will need to visit a malicious web page that leverages this vulnerability. Successful exploits can impact the availability, integrity, and confidentiality of the user&#039;s system.</strong></p><p>That certainly matches the description of the vulnerabilities first spotted on a rogue website by security firm FireEye on Sunday. Exploits for the flaws have since been incorporated into the notorious Blackhole malware toolkit and the Metasploit penetration testing tool.</p><p>On Wednesday, Adam Gowdiak of Polish startup Security Explorations revealed that his company had disclosed details of the vulnerabilities in question – along with 29 others – to Oracle in April of this year, but that the database giant still had not fixed the flaws as of its June Critical Patch Update (CPU).</p><p>Oracle told Security Explorations that it had developed fixes for most of the other vulnerabilities it had submitted and that they would be ready for the next Java CPU. Unfortunately, <span class="bbu"><span style="color: red">however, that patch kit wasn&#039;t scheduled to be released until October 16</span></span>.&quot;</p><p>from <a href="http://www.theregister.co.uk/2012/08/30/oracle_issues_java_0day_patch/">http://www.theregister.co.uk/2012/08/30 … day_patch/</a></p></blockquote></div><p><span class="bbu">additional reading</span>:<br />&quot;<strong>Oracle knew about critical Java flaws since April</strong>&nbsp; Could have issued patches, but didn&#039;t&nbsp; <br /><em>By Neil McAllister in San Francisco</em>&quot;<br /><a href="http://www.theregister.co.uk/2012/08/30/oracle_knew_about_flaws/">http://www.theregister.co.uk/2012/08/30 … out_flaws/</a>&nbsp; <img src="http://forum.driverpacks.net/img/smilies/sad.png" width="15" height="15" alt="sad" /></p><p>&quot;<strong>Super-critical Java zero-day exploits TWO bugs</strong>&nbsp; Write Once, Exploit Everywhere&nbsp; <br /><em>By John Leyden</em>&quot;<br /><a href="http://www.theregister.co.uk/2012/08/30/java_zero_day_latest/">http://www.theregister.co.uk/2012/08/30 … ay_latest/</a><br /><strong><span class="bbu">Quote</span>:</strong> <br /></p><div class="quotebox"><blockquote><p>&quot;Sean Sullivan, a security adviser at F-Secure, commented: &quot;The perpetual vulnerability machine that is Oracle&#039;s Java Runtime Environment (JRE) has yet another highly exploitable vulnerability (CVE-2012-4681). And it&#039;s being commoditised at this very moment. There being no latest patch against this, the only solution is to totally disable Java.&quot;&quot;</p></blockquote></div><p>&quot;<strong>Why Java would still stink even if it weren&#039;t security swiss cheese</strong>&nbsp; Nuke it from orbit - it&#039;s the only way to be sure&nbsp; <br /><em>By Trevor Pott</em>&quot;<br /><a href="http://www.theregister.co.uk/2012/08/30/i_hate_java/">http://www.theregister.co.uk/2012/08/30/i_hate_java/</a></p><br /><p>Personally, i like Java; albeit in a non-internet-enabled environment.<br /> <strong> Would Java be better suited to Virtualized Systems for an Internet-enabled environment?</strong></p>]]></content>
			<author>
				<name><![CDATA[TechDud]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=14671</uri>
			</author>
			<updated>2012-08-31T05:12:50Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=49090#p49090</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=49088#p49088"/>
			<content type="html"><![CDATA[<p>JRE7u7 is now released which addresses the bugs.</p>]]></content>
			<author>
				<name><![CDATA[mr_smartepants]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=1602</uri>
			</author>
			<updated>2012-08-31T04:53:38Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=49088#p49088</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=49083#p49083"/>
			<content type="html"><![CDATA[<p>You&#039;re welcome.</p>]]></content>
			<author>
				<name><![CDATA[TechDud]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=14671</uri>
			</author>
			<updated>2012-08-31T02:15:07Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=49083#p49083</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=49066#p49066"/>
			<content type="html"><![CDATA[<p>Thanks very much!!!</p>]]></content>
			<author>
				<name><![CDATA[compstuff]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=4947</uri>
			</author>
			<updated>2012-08-28T11:49:18Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=49066#p49066</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[You were once again urged to disable Java to avoid 0day xploit(sss)]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=49062#p49062"/>
			<content type="html"><![CDATA[<div class="quotebox"><blockquote><p><em><span class="bbu">Quote</span>:</em><br />&quot;<strong>Users urged to disable Java as new exploit emerges</strong><br /><em>All operating systems, browsers vulnerable</em></p><p><em>By Neil McAllister in San Francisco</em></p><p>A new browser-based exploit for a Java vulnerability that allows attackers to execute arbitrary code on client systems has been spotted in the wild – and because of Oracle&#039;s Java patch schedule, it may be some time before a fix becomes widely available.&quot;</p><p><a href="http://www.theregister.co.uk/2012/08/27/disable_java_to_block_exploit/">http://www.theregister.co.uk/2012/08/27 … k_exploit/</a></p></blockquote></div>]]></content>
			<author>
				<name><![CDATA[TechDud]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=14671</uri>
			</author>
			<updated>2012-08-28T07:08:29Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=49062#p49062</id>
		</entry>
</feed>
