Slashdot Mirror


Oracle Rushes Emergency Java Update To Patch McRAT Vulnerabilities

msm1267 writes "Oracle has once again released an emergency Java update to patch zero-day vulnerabilities in the browser plug-in, the fifth time it has updated the platform this year. Today's update patches CVE-2013-1493 and CVE-2013-0809, the former was discovered last week being exploited in the wild for Java 6 update 41 through Java 7 update 15. The vulnerability allows for arbitrary memory execution in the Java virtual machine process; attackers exploiting the flaw were able to download the McRAT remote access Trojan."

117 of 165 comments (clear)

  1. Uninstall by Dan+East · · Score: 5, Funny

    I uninstalled everything starting with "java" on my computers, and the only thing now missing is the every-other-day notification that Java needs to be updated.

    --
    Better known as 318230.
    1. Re:Uninstall by Pino+Grigio · · Score: 1

      Yup. Me too. Can't stand it.

    2. Re:Uninstall by DigitAl56K · · Score: 4, Insightful

      I mean it's no different than me going around, running executables from random websites and then blaming Microsoft for not doing more to secure their OS.

      It's entirely different, the plugin is supposed to be sandboxed.

    3. Re:Uninstall by holostarr · · Score: 2

      Just because it's supposed to doesn't mean you should run untrusted code.

    4. Re:Uninstall by Deekin_Scalesinger · · Score: 4, Insightful

      Look me in the eye and tell me you compile everything from source, after verifying each line of code. Do you trust Mozilla? Canonical? Berkeley? What an asinine statement.

      --
      "As the intrepid kobold companion continues his journey, he begins to wonder... if priests raises dead, why anybody die?
    5. Re:Uninstall by holostarr · · Score: 5, Insightful

      Obviously sometimes you have no choice but to trust someone else's code, but there is a difference between blindly trusting all code versus evaluating the source of the code and deciding whether or not there is enough good faith for the source to be trusted.

    6. Re:Uninstall by Deekin_Scalesinger · · Score: 1

      Indeed and well said Sire. My faith in tech humanity and common sense is somewhat restored (at least for tonight).

      --
      "As the intrepid kobold companion continues his journey, he begins to wonder... if priests raises dead, why anybody die?
    7. Re:Uninstall by Anonymous Coward · · Score: 1

      But the whole point of the Java security model is so that one isn't supposed to have to worry about whether they are running trusted or untrusted code. If it's untrusted code it's not supposed to be running at all.

    8. Re:Uninstall by Decker-Mage · · Score: 2, Interesting

      Sadly, more than a few "security" tools here require Java or .NET.

      --
      "[I]t is a wise man who admits the limits of his knowledge or skill, and that pretending either causes harm." --Terry Go
    9. Re:Uninstall by Technomancer · · Score: 4, Funny

      Thats easy, just click on this llittle Java app.

    10. Re:Uninstall by MemoryDragon · · Score: 2

      Disabling the browser plugin also would have helped.

    11. Re:Uninstall by qaz123 · · Score: 2

      Windows Control Panel -> Java -> Security Uncheck the "Enable Java content in the browser" checkbox That would be enough

    12. Re:Uninstall by smash · · Score: 1

      And the problem here lies in the fact that the source could be compromised. Hence, code signing - the software can be uploaded to the net, after being signed by the private key which is kept off-line. Trusting the server sending you stuff these days is no real security at all.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    13. Re:Uninstall by denis-The-menace · · Score: 1

      The don't use Open Office.
      Use LibreOffice instead. (https://www.libreoffice.org/)

      You don't need Java to install or to run it UNLESS you use BASE.

      --
      Obama's legacy: (N)othing (S)ecure (A)nywhere and (T)error (S)imulation (A)dministration
    14. Re:Uninstall by Macgrrl · · Score: 1

      Citrix for remote access to work. :(

      --
      Sara
      Designer, Gamer, Macgrrl in an XP World
    15. Re:Uninstall by netsentry · · Score: 1

      Citrix for remote access to work. :(

      Junos web access for the same reason ... sigh.

  2. Only one program I miss by AG+the+other · · Score: 1, Insightful

    Open office won't work without Java. Maybe some day I'll be convinced that they have their stuff together again and I'll reinstall it.

    --
    Non bene pro toto libertas venditur auro
    1. Re:Only one program I miss by mcl630 · · Score: 5, Informative

      Most of the Java vulnerabilities are in the browser plugin. You can always install Java and just disable the browser plugin.

    2. Re:Only one program I miss by TsuruchiBrian · · Score: 3, Interesting

      You can have the java virtual machine installed without using the java applet plugin for your browser. The recent security problems are only for the java applet browser plugin, which is now disabled by default by firefox and probably other browsers as well.

    3. Re:Only one program I miss by Desler · · Score: 5, Insightful

      Open office won't work without Java.

      Sure it does. The only parts that really required Java were a couple of wizards and the RDBMS.

    4. Re:Only one program I miss by Anonymous Coward · · Score: 3, Interesting

      I use Libre Office just fine without Java installed. Maybe some plugins still need it, but I've never had it complain that I was missing it.

    5. Re:Only one program I miss by smash · · Score: 3, Interesting

      .... and Base is pretty damn broken anyhow. I tested it a couple of months back - create new database. create a single table with 2 fields, a primary key and a name. It crashed when I tried to save the table design. Doesn't exactly inspire confidence as far as holding my data goes, which is somewhat crucial for a DATABASE.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    6. Re:Only one program I miss by antdude · · Score: 1

      OpenOffice doesn't require Java for everything. What do you use for its Java?

      --
      Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
    7. Re:Only one program I miss by etrusco · · Score: 1

      I would agree, if only the installer had the option not to install the plugin and the option was kept when updating.

    8. Re:Only one program I miss by AG+the+other · · Score: 1

      It says you can't install it unless you have Java installed or did the last time I tried to install it.
      My wife has a multi PC copy of MS Office and I use that, most of the time anyway, for what little word processing I do that Google Docs won't do.

      --
      Non bene pro toto libertas venditur auro
    9. Re:Only one program I miss by dissy · · Score: 4, Informative

      Just install 64 bit java JRE only. There are no browser plugins in the 64 bit JRE, only the 32 bit JRE, so none of the vulnerabilities released in the past 3 or 4 years will affect you.

      As a bonus, since there are no browser addons in 64 bit JRE, you won't ever see that annoying ask toolbar garbage from them again.

    10. Re:Only one program I miss by dissy · · Score: 1

      I think you're mistaken. Open Office never ever has run in the browser plugin.
      Or did you even bother to look at the conversation before spouting off?

    11. Re:Only one program I miss by rwyoder · · Score: 1

      I use Libre Office just fine without Java installed. Maybe some plugins still need it, but I've never had it complain that I was missing it.

      +1
      I switched to Libre Office long ago, and can't find any reason anyone would still use OpenOffice.

    12. Re:Only one program I miss by Numtek · · Score: 1

      It does here.

    13. Re:Only one program I miss by Nivag064 · · Score: 1

      You can use LibreOffice instead of OpenOffice, it does no depend on Java!

      http://www.libreoffice.org/

    14. Re:Only one program I miss by smash · · Score: 1

      This was on a 15 minute old install of debian stable, by the way. Not some bleeding edge or ricer-cflags distribution.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    15. Re:Only one program I miss by Anonymous Coward · · Score: 1

      This was on a 15 minute old install of debian stable, by the way.

      So the bug has been fixed decades ago. Debian stable only guarantees that the program version is old enough that most critical bugs should have been found by now.

    16. Re:Only one program I miss by futhermocker · · Score: 1

      There are WAY MORE java web apps you might think
      Where I work we have at least 3 applications that only can be used through an applet.
      Plus all our KVMs are java applets, thanks to HP...

      --
      KERNEL PANIC -SIGFAULT AT ADDRESS #51A54D07
    17. Re:Only one program I miss by kthreadd · · Score: 1

      Some users may find the license more appropriate.

    18. Re:Only one program I miss by AG+the+other · · Score: 1

      The last time I tried to install Libre Office on a relative's computer the installation failed and I haven't had another chance to try it again.

      --
      Non bene pro toto libertas venditur auro
    19. Re:Only one program I miss by Nivag064 · · Score: 1

      Usually when I try to install software and it fails, I've made one or more mistakes myself! To makes matters worse, I'm not always aware of what I did wrong.

      If installing LIbreOffice, or any other open source software, fails and you have not made any mistakes that you are aware of - then I advise you to file a bug report.

      I am a software developer, and I know from my own experience, that any moderately complicated piece of software always has bugs - no matter how thoroughly you think you have tested it!

    20. Re:Only one program I miss by LordLimecat · · Score: 1

      Equallogic SANs use java iirc, as does HP's iLO remote management. A number of bank sites also use java applets.

    21. Re:Only one program I miss by HaZardman27 · · Score: 1

      You see, once you disable the browser plugin, that's 99% of the raison d'etre of Java gone for most end users

      That last time I needed to use the Java browser plugin was nearly a year ago for a WebEx meeting. My last job involved server-side Java code, and I use OpenOffice at home, and that pretty much sums up my need for Java, other than the occasional program I write with it(very rare since I typically find that another language would be more suited to what I'm doing, and even when I chose Java it's never for applets). I understand my use probably does not represent the average computer user, but I can't even begin to imagine what all of those people you mention would be doing with Java applets.

      --
      Apparently wizard is not a legitimate career path, so I chose programmer instead.
    22. Re:Only one program I miss by HaZardman27 · · Score: 1

      There are almost no legimimate java web apps anymore

      Depends on how you define a Java web app. Applets are dead, sure, I won't disagree with that, but in my definition a web app that uses Javascript and AJAX calls to a server-side program running on a JVM and written in Java is still a Java web app.

      --
      Apparently wizard is not a legitimate career path, so I chose programmer instead.
    23. Re:Only one program I miss by AG+the+other · · Score: 1

      Unfortunately I was helping a relative set up a new computer, I had already spent several hours working on the computer and was exhausted so when the install failed I just changed to Open Office when the install failed.

      --
      Non bene pro toto libertas venditur auro
    24. Re:Only one program I miss by jandrese · · Score: 1

      Firefox (and I'm pretty sure all of the other major browsers) will remember that a plugin is disabled even when it is updated. Just let it install and then go and disable it in your browser(s).

      --

      I read the internet for the articles.
    25. Re:Only one program I miss by Nivag064 · · Score: 1

      So my first paragraph applies - especially when one is very tired.

      Initially, I was only going to comment along the lines of my second paragraph - but I felt that would come across as too harsh & likely to provoke irritation/anger!

      All the best for your next attempt.

    26. Re:Only one program I miss by Macgrrl · · Score: 1

      A number of bank sites also use java applets

      This.

      Also utilities, ISPs and similar organisations for web forms that probably don't really need java to do what they do (probably, it's possible they actually do).

      I can't pay my credit card from Safari on my desktop Mac at home because it can't get past the balance calculation applet, but I can on my iPad iOS app.

      I tried logging a ticket with my ISP the other day and their website said they don't support Safari, Firefox or Chrome - use IE, which isn't available for Mac OS and hasn't been for years (Note I used to be able to log faults through their website). I'm trying to log a fault at the exchange that causes random dropouts.

      --
      Sara
      Designer, Gamer, Macgrrl in an XP World
    27. Re:Only one program I miss by davydagger · · Score: 1

      all three of them too.

    28. Re:Only one program I miss by davydagger · · Score: 1

      javascript != java.

      and ajax has nothing to do with it. The point is there are better ways to do AJAX than java in 2013. In fact, Java is not the go to for ajax anymore. For most interactive web apps, I think flash has taken over from java

      perl, python, php, and javascript, and now HTML5.

    29. Re:Only one program I miss by Trogre · · Score: 1

      Interesting. OpenOffice.org or Libreoffice?

      --
      "Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife
    30. Re:Only one program I miss by OdinOdin_ · · Score: 1

      A "webapp" is a server side application, think like what PHP is mainly used for. There are a huge number Java Servlet Containers running Java webapp's in the world. Note the use of the term "webapp" was coined by Java back 12+ years ago to mean use of Servlets. From my view of the world only MS .NET with ASP.NET comes close to the capabilities possible with Java webapps. Sure today some other technologies have hijacked the term for their own use.

      No one does Java Applets anymore, except as noted for corporate equipment vendors and this is usually because those large corporations (IBM, HP, Equalogic, VMware, Oracle, etc...) use the Java language for everything so they can reuse in-house knowledge. But no general public facing business uses Java Applets anymore, only closed portals or contracted for services.

      Now the issue with JavaScript and AJAX this is talking about the HTTP client side of things, so the JavaScript != Java is not relevant to the original comments (since they were talking about "webapps" and therefore server side Java, but you confuse it with client side; that no one does). Currently NodeJS is about the only technology that can be said to have an edge on Java for server side processing of AJAX/WebSockets. But there are at least 2 major projects for Java making use of the NIO/Event processing model that should be able to scale better than NodeJS. The Servlet specification has an update to ratify WebSockets as at least 4 Java webserver implementations have already supported WebSockets to some degree already but in slightly different ways, so now we have a new standard.

      My current choices are: Ruby for the offline development tools for content processing and generation (css/sprites/etc...), AngularJS for MVVM in HTML5, Java Servlets on Servlet container for service side programming model.

  3. Seems like /. is stuck on repeat... by Anonymous Coward · · Score: 1

    I have Java on my computer, but it is warm, tasty, and resides in a mug, but most importantly is exploit proof!

    1. Re:Seems like /. is stuck on repeat... by davydagger · · Score: 2

      the worst part about this is the statement is inherently untrue.

      If an attacker where to gain physical access to your machine, I could easily picture a nice denial of service attack one could perform with a hot cup of java on your computer.

      here is a hint its the type that destroys the hardware.

      I don't know your setup, but I'd also question the stability of your java platform(and the cup too). If you get a user panic error, you could easily destroy your machine.

    2. Re:Seems like /. is stuck on repeat... by Nimey · · Score: 1

      It'd be more effective if the attacker would use hot grits instead.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    3. Re:Seems like /. is stuck on repeat... by Macgrrl · · Score: 1

      Or a petrified Natalie Portman.

      --
      Sara
      Designer, Gamer, Macgrrl in an XP World
    4. Re:Seems like /. is stuck on repeat... by davydagger · · Score: 1

      hosnap, you both are bringing back my 1996

  4. even worse than the vulns by csumpi · · Score: 5, Insightful

    Even worse than the vulnerabilities are the _constant_ nagging for updates. Then on top of it, the way java updates is stupid. With every update a new version is installed, and the old ones are left uninstalled. So it got uninstalled. All of it.

    The language is ok, but everything else about java just plain sucks.

    1. Re:even worse than the vulns by GodfatherofSoul · · Score: 1

      Compared to Adobe?

      --
      I swear to God...I swear to God! That is NOT how you treat your human!
    2. Re:even worse than the vulns by Anonymous Coward · · Score: 1

      I think java 7 installs updates in place - no more need to uninstall old versions.
      It says it does this somewhere on the oracle updater site, & it seems
      to be working for me on a number of platforms.

    3. Re:even worse than the vulns by Nimey · · Score: 2

      What do you mean "the old ones are left uninstalled"? Are you griping about it getting rid of old vulnerable versions, or do you have really ancient copies of Java prior to 6.0 update 10 still installed? Java 6u10 was the first version to be automatically removable by subsequent versions, so 6u7 and earlier must be manually uninstalled.

      The updater still sucks in that it requires manual intervention instead of updating in the background, yes.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    4. Re:even worse than the vulns by Anonymous Coward · · Score: 1

      http://docs.oracle.com/javase/7/docs/webnotes/install/windows/patch-in-place-and-static-jre-installation.html
      Haven't the faintest why this isn't documented more clearly
      in their other pages related to installation & patching.

    5. Re:even worse than the vulns by gstoddart · · Score: 4, Informative

      Even worse than the vulnerabilities are the _constant_ nagging for updates.

      And proclivity for trying to install the Ask.com toolbar.

      Currently that is my biggest beef with Java -- after the fact that it seems to be glaringly insecure, and I can't figure out if they broke it, or it was always broken. :-P

      --
      Lost at C:>. Found at C.
    6. Re:even worse than the vulns by Nimey · · Score: 2

      Because Java 7 ignores previous Java 6 installs. New Java 7 updates will remove previous Java 7 instances.

      It probably makes sense in some use cases.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    7. Re:even worse than the vulns by smash · · Score: 1

      Even worse - a recent Java update decided to upgrade me from Java 6 to Java 7 (I know this is the case, because I don't install Java 7 myself). It left Java 1.6u38 installed, and no update to Java 6. I have applications that do not run on Java 7. So i'll be running Java 6. Which is still insecure on my machine.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    8. Re:even worse than the vulns by smash · · Score: 1

      Confirmed on a second machine.

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    9. Re:even worse than the vulns by dinfinity · · Score: 1

      Even worse than the vulnerabilities are the _constant_ nagging for updates.

      1. Remove the scheduled updater task.
      2. Install Secunia PSI
      3. Profit.

      Also, the JRE is updated nowadays. Only old JDKs are not removed, but that makes sense (to a developer).

    10. Re:even worse than the vulns by jandrese · · Score: 1

      And frankly, I suspect that Ask.com bar is full of security holes too.

      --

      I read the internet for the articles.
    11. Re:even worse than the vulns by gstoddart · · Score: 1

      I certainly assume it is ... every thing you install these days wants to install some form of search bar or browser plugin.

      The answer is always "no".

      --
      Lost at C:>. Found at C.
  5. Last Java 6 public update by yuhong · · Score: 1

    http://www.oracle.com/technetwork/java/javase/6u43-relnotes-1915290.html
    After this one you will need to pay for a support contract or upgrade to Java 7.

    1. Re:Last Java 6 public update by viperidaenz · · Score: 1

      I was checking java 6 builds the other day and I'm almost positive that "This is the last release" message was in the update 41 release notes before 43 was released.

    2. Re:Last Java 6 public update by yuhong · · Score: 1

      Not this one:
      http://www.oracle.com/technetwork/java/javase/6u41-relnotes-1907743.html
      Keep in mind this update is out of band.

    3. Re:Last Java 6 public update by Nimey · · Score: 1

      Marvelous. We just bought a package that requires 6 to work and doesn't with 7, /and/ it needs the browser plugin.

      Eat a bag of dicks, Ellison.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    4. Re:Last Java 6 public update by yuhong · · Score: 1

      Just bought? The support lifecycle for Java is public: http://www.oracle.com/technetwork/java/eol-135779.html

    5. Re:Last Java 6 public update by Nimey · · Score: 1

      I wasn't involved in the purchase, but the program requires JavaFX and does not appear to work with any Java 7 REs I've tried.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    6. Re:Last Java 6 public update by willie150 · · Score: 1

      We're lucky to get that one. Oracle have publicly stated that there wont be any updates to Java 6 post February 2012. http://java.com/en/download/faq/java_6.xml

      --
      Better to stay silent, and let people think you're an idiot than to open your mouth and remove all doubt
    7. Re:Last Java 6 public update by yuhong · · Score: 1

      Yep, this update is out of band which is probably why.

    8. Re:Last Java 6 public update by wmac1 · · Score: 2

      How about expecting the new software's company to support their newly sold software (and update it to support 7) instead of asking Oracle to support its many years old free software?

    9. Re:Last Java 6 public update by viperidaenz · · Score: 1

      They changed the release notes for 41.
      That's my story and I'm sticking to it. Even though the google cache of that page on the 25th says otherwise. Wikipedia hasn't been updated yet and says 41 is the last.

    10. Re:Last Java 6 public update by Nimey · · Score: 2

      It's a lot easier to bitch about Oracle, especially given how shoddily written their software is.

      I mean, fuck. They've managed to take the crappy security award away from Adobe.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    11. Re:Last Java 6 public update by Kenshin · · Score: 1

      Brilliant. That's like buying new software that requires Windows XP.

      --

      Does it make you happy you're so strange?

    12. Re:Last Java 6 public update by Nimey · · Score: 3, Informative

      Ever dealt with "enterprise" vendors? With that attitude I bet you haven't.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    13. Re:Last Java 6 public update by cbhacking · · Score: 1

      Who, previously, had taken it from MS. Guys, *stop* chasing that award. It's not actually a good thing! I think MS was pretty happy to give it up (after all the security work that went into NT6.x, the IE sandbox, etc.), and Adobe is showing signs of acting that way too (the Reader sandbox was a huge improvement, though Flash is still iffy), but Oracle seems dead-set on holding onto it.

      --
      There's no place I could be, since I've found Serenity...
    14. Re:Last Java 6 public update by pedestrian+crossing · · Score: 2

      Cisco ASDM (configuration/management software for ASA firewalls) doesn't work on Java 7...

      --
      A house divided against itself cannot stand.
    15. Re:Last Java 6 public update by DeDmeTe · · Score: 1

      It's running fine for me on 7.17 (ASDM 6.4)

      --
      -Guns kill people like spoons made Rosie O'Donnell fat-
    16. Re:Last Java 6 public update by Rich0 · · Score: 1

      How about expecting the new software's company to support their newly sold software (and update it to support 7) instead of asking Oracle to support its many years old free software?

      Uh, their latest version is only guaranteed support until July 2014 according to their website. Sure, I guess nobody is paying for it, but I'm not sure I'd base my software off of a platform that is not guaranteed to get security updates for more than a year.

      The seven years Java 6 got isn't too bad, assuming it was announced that way back in the beginning. However, it still pales compared to the stability of win32/etc.

    17. Re:Last Java 6 public update by Rich0 · · Score: 1

      I wouldn't complain too much about XP.

      XP was introduced in Dec 2001 and is supported until April 2014.

      Java 7 (SEVEN - not six - ie the latest version) was introduced in July 2011, and is supported until July 2014 (it might or might not go later, but no promises).

      If you used something more sane like Windows 7 then you're supported until 2020.

      If you deployed a new piece of software that requires XP you'd only be three months worse off than deploying a new piece of software that requires Java 7.

  6. Warning: Oracle installs ask.com toolbar by icknay · · Score: 5, Informative

    Warning: the Java installer will install the ask.com toolbar if you click the "yes, please just install my security update" button, even for the original install you declined the toolbar -- really an obnoxious abuse of updates. Here is a very interesting analysis of the whole back and forth between the ask.com installer and the browsers trying to keep junk out. Interesting tidbit: apparently the ask.com installer sleeps for 10 minutes, so if you try to "remove" right afterwards, it's not there yet. This is on Windows, not sure across all platforms. Oracle taking this little tiny income stream from ask.com in exchange for screwing over tons of users and admins seems like a big mistake by Oracle, and would just sort of bug me if I were an engineer at Oracle spending all this time trying to make Java better.

    1. Re:Warning: Oracle installs ask.com toolbar by Qwavel · · Score: 1

      But that's just Oracle - and always has been Oracle. Being aggressive and obnoxious hasn't hurt them before (check their stock price).

    2. Re:Warning: Oracle installs ask.com toolbar by Anonymous Coward · · Score: 1

      If running Windows use ninite (ninite.com) to install java and other stuff w/o getting any of the toolbars. Added bonus you only have to download the installer once, it will still update everything to latest version. It does install both 32 and 64 bit java if you're running 64 bit windows.

    3. Re:Warning: Oracle installs ask.com toolbar by Anonymous Coward · · Score: 1
    4. Re:Warning: Oracle installs ask.com toolbar by smash · · Score: 2

      Also - watch out, it may also re-enable the Java plugin in your browser if you had previously turned it off, on at least one box I've updated on (previous update).

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    5. Re:Warning: Oracle installs ask.com toolbar by bloodhawk · · Score: 3, Insightful

      It's a damn slap in the face. You install updates to protect yourself and you get the fucking ask.com malware as your reward.

  7. OpenJDK .. by dgharmon · · Score: 3, Interesting

    Does this exploit work under the OpenJDK Runtime Environment?

    --
    AccountKiller
    1. Re:OpenJDK .. by sourcerror · · Score: 1

      As far as I know, OpenJDK is not really a fork, just a stripped down version of the Oracle JDK.

    2. Re:OpenJDK .. by ChunderDownunder · · Score: 3, Informative

      So yes, probably.

      The security flaw isn't necessarily in the browser plugin per se. Rather it's in the class libraries that are 'sandboxed' when running in a security manager.

      Were one to substitute, say, the IcedTea browser plugin, one would still be accessing the same underlying libraries and security manager implementations. i.e. following each security patch to Java, a Red Hat employee is quick to roll out a new IcedTea release with those patches.

  8. Java and Flash remind me of this song.. by DigitAl56K · · Score: 1
  9. So, Oracle managed to mess this one up as well... by SpaceCracker · · Score: 1

    All these security holes are loosing credibility for Java.
    That's good news for .Net.
    What about the rest of us?

    It seems like the right time for a new alternative to show up. Any takers?

    --
    sigo ergo sum
  10. I'll stick with the Java that I can drink. by Darth+Twon · · Score: 1

    And Barry Allen.

    --
    Take this sig and smoke it.
  11. Re:So, Oracle managed to mess this one up as well. by TheSunborn · · Score: 1

    Sorry, but I will keep using java server side. I just hope I don't end up with that "Ask toolbar" on our server :}

    And the fact that the Java Security Manager is as safe as an open door, does not really matter because 99% of all server side java code, is running without the security manager. (Or at least without relaying on the Security manager to provide security).

     

  12. Re:LOL by ls671 · · Score: 2

    Ok, I am sick of this. Java is a fine language and platform and it doesn't deserve all the bad press it got lately just because it is poorly managed at the moment in one specific area: browser plugins. Banks and other corporate customers that feed Oracle couldn't care less about the flaws because they use Java server-side.

    Here is my theory, I could be wrong...

    Sun and Oracle philosophy were pretty different. Since Sun's was acquired by Oracle, Oracle is spilt in 2 camps and stuck with a problem:

    1) Sun's former employees. The ones that haven't left yet but that are kind of resisting still from the inside.
    2) Legacy Oracle employees.

    Sun's employees are much closer to the real old school geeky Linux user style than Oracle employees that are closer to a Microsoft representative in their style. Sun's employees know this, they have also a strong ego.

    So making Java look stupid would sure get a stab at those former Sun's employees that think they know everything and possibly make them easier to merge into the company mentality or cause them to resign.

    When you bitch about Java, you may just be playing Oracle's game... But then again, could this theory possibly make sense to anybody else?

    --
    Everything I write is lies, read between the lines.
  13. It's Upload, Not Download by StormReaver · · Score: 3, Informative

    When someone is transferring something to your computer, they are uploading. They managed to upload the McRAT trojan. They did not manage to download the McRAT trojan; They already had it, and weren't trying to get it from the victims' computers.

    Please don't try learning your computer terminology from Hollywood, as they get it wrong 99% of the time. I think in all seven years of STTNG, they got it right only once.

    1. Re:It's Upload, Not Download by ChaseTec · · Score: 1

      Why? You downloaded an applet from a website which then downloaded the McRAT trojan. The article was misleading about who or what was doing the download but not the initiator of the transfer.

      --
      My Hello World is 512 bytes. But it's also a valid Fat12 boot sector, Fat12 file reader, and Pmode routine.
    2. Re:It's Upload, Not Download by slimjim8094 · · Score: 1

      It's completely correct. The user's computer downloaded the applet, which then proceeded to download the trojan from some Internet location and install it through this vulnerability. Uploading implies that the attackers were the "active" party; that would generally be a worm.

      --
      I have developed a truly marvelous proof of this comment, which this signature is too narrow to contain.
    3. Re:It's Upload, Not Download by Phrogman · · Score: 1

      Technically they got the user's system to download the McRAT Trojan surreptitiously by exploiting the vulnerability in Java :)

      Client to Server: Upload
      Server to Client: Download

      So its correct but not very grammatically clear

      --
      "The first time I got drunk, I got married. The second time I bought a chimpanzee, after that I stayed sober" Arian Seid
    4. Re:It's Upload, Not Download by StormReaver · · Score: 1

      Consider the context of the sentence: "[A]ttackers exploiting the flaw were able to..."

      They were able to...what? Uploading and downloading are terms used within the context of who is doing what. When a file is being transferred, uploading and downloading are occurring simultaneously. One side of the transmission is downloading, and the other side of the transmission is uploading. The side of the transmission that is receiving the data is downloading, and the side of the transmission that is sending the data is uploading. It doesn't matter if it's client/server, peer to peer, or Morse code through flashlights; the rule is the same: the sender is uploading, and the receiver is downloading. It similarly doesn't matter who initiated the transfer.

      The article was not in any way misleading about who was doing what. The victims were downloading, and the attackers were uploading.

  14. Troolbar by snsh · · Score: 1

    Will this update install the Google toobar, Yahoo toolbar, Bing toolbar, or Ask.com toolbar?

  15. Evil Masterminds by bill_mcgonigle · · Score: 1

    I get the impression that a group of hackers is working on a collection of Java vulnerabilities with the goal of releasing a new 0-day for the Java plugin a day after every Oracle update.

    I can think of a half-dozen ways Oracle could respond to such a tactic and each is a bit more chuckle-inducing than the last.

    --
    My God, it's Full of Source!
    OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
    1. Re:Evil Masterminds by MadKeithV · · Score: 1

      Who would benefit?

      Everyone who doesn't have Java installed gets a good laugh out of it, for starters.

    2. Re:Evil Masterminds by Nimey · · Score: 1

      Anybody who doesn't like Larry Ellison, i.e. everyone who's dealt with him personally.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
  16. How to stop applets from running by TrueSpeed · · Score: 3, Insightful

    The Java Control Panel (in the Windows control panel) contains a checkbox under the Security Panel called "Enable Java content in the Browser". Uncheck this if you do not want applets to run. This selection stays persisted each time you update the JRE.

    Once again,

    Windows Control Panel->Java Control Panel->Security Panel. Make sure the "Enable Java content in the Browser" checkbox is unchecked.

  17. How do I disable Java in my browser by TrueSpeed · · Score: 3, Informative
  18. This one is different by Anonymous Coward · · Score: 1

    Sounds like they have run out of pure sandbox vulnerabilities. Most of the previous ones were exploiting a properly running client sandbox and hence were pretty straightforward and reliable.

      This one is apparently related to JPG image handling. It just tries to corrupt JVM memory and often crashes it.

    My guess is, the rate at which vulnerabilities are discovered now is going to be a lot slower. The language sandbox is now probably fairly decent. Exploit writers are going to have to resort to finding bugs in native libraries used by JVM. I would not expect any new ones soon.

  19. Re:"3 Billion Devices Run Java by MemoryDragon · · Score: 1

    They also dont use the Java Plugin which is the problem there :-)

  20. Re:LOL by TheRaven64 · · Score: 5, Interesting
    This has nothing to do with Oracle. The browser plugin has a long history of security holes going back well over a decade and the bitching has been going on since 1995. The problem is that writing a language implementation that is both fast and 100% correct is really hard. The safety properties of Java (and any other managed language) rely on the implementation being 100% correct. This is relatively easy for something like the Squeak Smalltalk VM, which is a single-threaded bytecode interpreter with a stop-the-world garbage collector, but people insist on the JVM doing all sorts of optimisations, supporting multiple threads and so on. The early complaints about Java were that it was slow. The more recent complaints are that it's not correct. Well, you have three choices:
    • Have a slow VM.
    • Have a fast, but incorrect, VM, and be aware that every error is a potential security hole.
    • Formally verify your VM. Be aware that this will cost at least 30 times as much[1] as the non-verified version.

    Relying on software enforcement for security is just asking for trouble.

    [1] The factor of 30 comes from seL4 which, to mu knowledge, is the formally verified project that managed the smallest overhead. Other estimates from other projects are 100 or more times the cost.

    --
    I am TheRaven on Soylent News
  21. Re:LOL by JDG1980 · · Score: 1

    Ok, I am sick of this. Java is a fine language and platform and it doesn't deserve all the bad press it got lately just because it is poorly managed at the moment in one specific area: browser plugins. Banks and other corporate customers that feed Oracle couldn't care less about the flaws because they use Java server-side.

    The problem is that, until very recently, the Java installer went out of its way to shove the browser plugin down your throat. Even if you removed it manually, it would come back the next time Java was updated. They changed it recently so you can disable the plugin in the control panel, but that's not really good enough – it ought to be turned off by default. In fact, it should probably be a separate download, with a warning that it's for legacy support only. Also, they really need to stop using the update process as an opportunity to try to make an extra buck with Ask Toolbar.

  22. delta patches please by X0563511 · · Score: 1

    I'm getting very tired of installing a new JRE and JDK over and over again, including the JCE.

    Can we please get an in-place delta patch, Oracle? It's 2013, we have these things you know.

    --
    For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
  23. Pretty simple solution by boorack · · Score: 1

    Don't force users to install browser plugin crapola. One simple checkbox in setup program (unchecked by default) would make lives better for many, many people (mainly developers). Unfortunately, Oracle chose to use JDK to force lots of crap down our throats (JavaFX, browser plugin plus some other browser crapola), so virtually everyone using Java for any purose is affected by Java security holes. Unfortunate situation that boils down to by stubborn Oracle managos... is there anything in the world that Larry won't be able to turn into crap just by touching it ?

  24. Re:LOL by hraponssi · · Score: 1

    Just to go completely offtopic and straight for the woods, if you do that 30-100xcost of formal verification (which goes on forever as you evolve your software), then what did you verify?

    I had a look at that seL4 project as it sounds interesting. They claim to have used a theorem prover to "construct the proof". Does a threorem prover now read your specs, consult your experts, and construct the proof for you? Or does it just take what you write and your "constructing the proof" is writing all the specs yourself and running some prover to tell you how great your formal logics and nasty looking complex statements are? Like in "the logic of bugs"?

    Who verifies the spec for what is to be proven in the first place? That is hard even in testing, which deals mostly with more human processable stuff.

    Of course the project lists low-level details as being proven such as lack of buffer overflows, which don't really require much of a spec, so I suppose for those it can be nice with the 100 times overhead. Then you can address the rest of the security issues, which nicely would be much smaller though.

    Anyway, that stuff would be nice if you could feed it a million LOC and press a button. Still waiting for the day..

  25. Re:LOL by TheRaven64 · · Score: 1

    In the seL4 case, they first write a formal specification. Then they (oversimplifying slightly) prove an equivalence of their implementation (in a restricted subset of C) and their specification. Then they prove properties (e.g. isolation) of their specification. You can't just take some C code and say 'is this correct' without a spec, and you typically can't take arbitrary C code and say 'do these properties hold for this code'. Even in the seL4 case, there are some issues, for example they correct functioning of the MMU is taken as axiomatic.

    --
    I am TheRaven on Soylent News
  26. Re:Love Java, but dislike Javascript by Cito · · Score: 1

    Firefox states that the browser javascript plugin is vulnerable and automatically turns it off.

    http://www.h-online.com/security/news/item/New-holes-discovered-in-latest-Java-versions-1810990.html

    firefox now default turns off javascript in the browser unless you specifically tell it to accept, similar to noscript.

    which is the same bug as the original article fixes. But firefox is still refusing to allow javascript by default and until further notice all javascript plugins will be disabled by default in firefox.

    I was pointing out some people are confusing Java and Javascript, I explained they are 2 totally different creatures.

  27. Re:And Open Office still runs by Macgrrl · · Score: 1

    Does anyone else periodically feel like throwing their computer out the window with the constant nag screens to update Adobe Flash or Acrobat Reader that seem to appear every week or so.

    --
    Sara
    Designer, Gamer, Macgrrl in an XP World