Slashdot Mirror


A Tidal Wave of Java Flaw Exploitation

tsu doh nimh writes "Microsoft warned today that it is witnessing a huge spike in the exploitation of Java vulnerabilities on the Windows platform, and that attacks on Java security holes now far outpace the exploitation of Adobe PDF bugs. The Microsoft announcement cites research by blogger Brian Krebs, who has been warning for several months that Java vulnerabilities are showing up as the top moneymakers for those peddling commercial crimeware exploitation kits, such as Eleonore, Crimepack and SEO Sploit Pack." Several days ago, Oracle released a patch that fixed 29 Java security flaws.

7 of 238 comments (clear)

  1. Nervous by Konster · · Score: 4, Funny

    Seeing Oracle and Java all in the same sentence gives me a nervous tick...the same nervous tick that I developed when I read MS was in talks to acquire Adobe.

    1. Re:Nervous by MrEricSir · · Score: 4, Funny

      Just wait until you hear the news that Larry Ellison is buying Linus Torvalds.

      --
      There's no -1 for "I don't get it."
  2. This article speaks the truth by gman003 · · Score: 5, Funny

    I'm still in the process of repairing my Windows system after a Java-transmitted virus. A hacked website was sending out malware to visitors via Java applet, and the only solution I found was a format/reinstall. Since then, I've disabled Java on all my machines; the only things I've seen it used for are crappy browser games and malware.

  3. Re:Patches have been available for a long time by Anonymous Coward · · Score: 5, Funny

    I've run out of space in my head for all the different tools I need to seperately manage updates for.

    Sounds like you need a computer.

  4. Re:JVM on Windows? by MrEricSir · · Score: 4, Funny

    Yeah, they should have used ActiveX, right?

    --
    There's no -1 for "I don't get it."
  5. Re:Patches have been available for a long time by Ant+P. · · Score: 5, Funny

    I guess Windows isn't ready for the desktop.

  6. Re:JRE's no mere ranger. by Haeleth · · Score: 2, Funny

    Here in the Enterprise(tm) world, we generally tend to, y'know, test shit thoroughly before launching/updating it.

    Indeed. Most of the Enterprise(tm) world is probably completely safe from these attacks. At least till 2027 when they upgrade to the vulnerable versions.