c-commerce? WTF? #
Posted Thursday 12th July 2007 16:24 GMT
I know e-commerce, and m-commerce, but what is c-commerce?
Posted Thursday 12th July 2007 16:24 GMT
I know e-commerce, and m-commerce, but what is c-commerce?
Posted Friday 13th July 2007 18:12 GMT
Java runtime vulnerability see details at http://isc.sans.org I predict
a lot more of this sort of thing for JAVA as vulnerabilities go anything
that can infect every platform on any OS is kind of a biggie.
Posted Monday 16th July 2007 10:14 GMT
Hi Alan,
I think you were referring to http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-102934-1
This is a specific issue for certain SUN JRE's for PC's, and does not affect J2ME.
You are right that any mono-culture is vulnerable to one exploit sweeping through it, but MIDP/J2ME virtual machines on mobile phones are not a mono-culture as they are made by different vendors, running on different OS's and Processors (contrary to popular belief all JRE's are not made by SUN).
Windows is a far worse situation, found in very similar guises on only two major CPU families with similar op codes (the binary codes required to make things happen on the processor when a virus has overflowed data into instruction space).
I have posted more detail about mobile security, with an invitation for people to ask more questions on blog.masabi.com if you have other concerns.
Ben (Masabi)
p.s. I think C-Commerce was a typo, we've never heard of it either, and wondered if it was a US translation to "Cellular-Commerce" or something....
Sign up, sign up for The Register's weekly IT security newsletter - click here