Feeds

back to article Latest Java patch is not enough, warns US gov: Axe plugins NOW

Security experts advise users to not run Java in their web browsers despite a patch from Oracle that mitigates a widely exploited security vulnerability. The database giant issued an emergency out-of-band patch on Sunday, but despite this the US Department of Homeland Security continues to warn citizens to disable Java plugins …

COMMENTS

This topic is closed for new posts.

Page:

Silver badge
Pint

JavaScript has nothing to do with anything (though it had, and still does, have problems).

Additionally, why not use NoScript? No autostarting Applets anymore.

2
0
Silver badge
Trollface

I dare say Javascript flaws are still responsible for more malware dumping than Java would be my guess but Java is catching up these days.

0
0
Silver badge
Big Brother

The next governmental announcement

"Uninstall TSA! Groping, probing, stealing and fondling (plus possibly cancer-installing) by uniformed nontrustworthies perfoming security theater will take years to fix. Additionally, the effectiveness of TSA is marginal. We recommend that every tax-paying citizen no longer deal with this product."

Bet it won't come.

2
0
Silver badge
Big Brother

Re: The next governmental announcement

I know I am going to get the crap down voted for this comment but most of the sympathy I had for survivors who lost loved ones in 9/11 flew out the window when they pushed for the creation of the Ministry of Love (Department of Homeland Security who oversee TSA). Surprised they didn't push to bring back the Un-American Activities Committee in the House as well.

6
0
Bronze badge

Re: The next governmental announcement

...Surprised they didn't push to bring back the Un-American Activities Committee in the House as well...

Actually, they did, only under a bunch of different names.

1
0
Anonymous Coward

Re: The next governmental announcement

"who lost loved ones in 9/11 flew out the window"

Unfortunate use of that phrase, there, asdf,

1
0
Silver badge

My new invention

My bank has Windows PCs running IE displaying an internal app with lots of text boxes that the user tabs between to enter the numbers.

I suggest replacing the virus prone PC and the malware prone browser with some sort of custom hardware which sends tab characters directly down a wire to the big computer and receives the text to print in the box directly from the same wire. The custom box wouldn't have an OS or be able to access facebook

Can anyone suggest a name for this technology?

0
0

Re: My new invention

You could call it a smart terminal as it's smart enough not to be a security problem.

0
0
Anonymous Coward

Re: My new invention

vt100 ?

0
0
Silver badge

Re: My new invention

Wyse 50?

0
0

"If you can't avoid...

...using a handful of websites that demand your browser supports Java", why not apply a small piece of selotape to a corn cob.

0
1
Holmes

"This will help mitigate other Java vulnerabilities that MAY be discovered in the future."

As the title reads... Just as never turning the machine on will eliminate all except for WAKE ON technologies.

Its true that... if you have no plan to use it, or need it, why is it installed... However lets be realistic... Its not half as bad as Adobe's issues given most users probably werent aware that 11.5.502.146 was released recently since code for prior versions went public... and could easily be blocked by decent AV heuristics... because it mainly targets JMX classes in java.

Now lets focus upon more pressing matters such as... nginx, IIS 8 and Apache 2.4.3 ... IE 7,8,9 and 10 connection handling overruns which result in a DoS... and can be performed remotely!

3
0
Anonymous Coward

It's said to work on more browsers than just IE 7,8,9,10

I am still to see one which isnt currently vulnerable to it? Suggestions anyone?

0
0

disable everything

And while we're at it. Why not just disable everything?

Without the bloody javascript the web is faster.

MAKE webdesigners... pardon... web-programmers.. . do proper websites again.

Instead of a horrible piece of ECMA-code use a simple bloody HTML-tag like this one

(A HREF="http://www.site.com/pic.jpg" target="_blank">Link</A) to open an image in another window!

Yes, GSMArena I'm pointing AT YOU (amongst others)!!!

For the record I removed the first < and last > to get the code displayed itself.

In fact disabling javascript on your smartphone not only decreases data-volume coming through it also makes the bloody thing much faster. Which is important for the mortals amongst us whom don't have quad-core-GHz-gigabyte-RAM-sucking-LTE-monsters.

5
0
Anonymous Coward

Firefox, Chrome, Chromium, Lynx, Epiphany, W3m, Opera, IE <- This is the most affected

I'm thinking the TCP stack might need re-writing! Or some network engineers get forensics training?

JBoss App Server versions 4.0.2, 4.2.2 , 4.2.1 , 4.0.*,4.2.* is RCE'd too since:

web-console/Invoker allows you to invoke jboss.admin:service=DeploymentFileRepository without permissions

0
0
Bronze badge
Trollface

OMG - you mean I could get hacked playing Minecraft!

Fix Java NOW!

0
0
Bronze badge

OMG - you mean I could get hacked playing Minecraft!

No

0
0
Anonymous Coward

If you're still unlucky enough to be a java programmer...

...now would be a good time to learn Python. Right now.

0
1
Linux

Re: If you're still unlucky enough to be a java programmer...

Moved to Android (Google's version of Java) development two years ago. It has been a real interesting learning curve. If you think you know Java, try Android development.

Java is a beautiful programming language and not a superset of anything like C++.

Oracle JVM can be substituted with OpenJDK. It works fine for development. Netbeans has no trouble with it and OpenJDK does not suffer from said security problem.

0
0
Bronze badge

Re: If you're still unlucky enough to be a java programmer...

Such a ridiculous comment you couldn't even add your name to it.

Why should this have any consequence on the use of java where it is most commonly used? Applets probably cover less than 1% of java deployments (no data, just a guess based on my experience). They were great years ago but have been superseded by browser improvements, were they solved "real" problems webstart is by far the better solution.

Java desktop and server applications are not affected by this issue at all, it's irrelevant. I know python well and it just can't scale up to the demands that most software have placed on it, especially in an enterprise, you know the software that the many businesses and governments rely on.

1
1
Anonymous Coward

Re: If you're still unlucky enough to be a java programmer...

So your real name is 'vic 4' is it?

0
0

FINALY

Will we see then end of one of the most inefficient and bloated software ever?

FLASH: YOUR NEXT!

1
2
Anonymous Coward

Re: FINALY

I haven't got a next.

And I wouldn't show it to you, if I did.

7
0
Silver badge

Re: FINALY

Flash? Maybe. But why bother attacking Flash? The numerous opportunities offered by HTML 5 and Javascript must surely be very tempting.

Every time anyone does a new execution environment it takes years and years before all the bugs get ironed out. OSes aren't bad now, but they're still finding problems 22 years in. JAVA is riddled with problems seemingly, and that's been around for a long time now. Javascript has been terrible too, until browser people started implementing half decent sand boxes. Flash has had its problems too... Even .NET has had to be patched many times, though because hardly anyone used Silverlight no one noticed the vast security holes it probably blew in your browsing experience.

So remember that HTML 5 is just another environment, is brand new, and does not require an attack to break out of whatever sandbox the browser has wrapped around it. That's because HTML5 is now the OS as far as Web apps are concerned; there's already proof of concept attacks on it. It's bound to be riddled with flaws, and one day the anti virus vendors will be selling AV for your browser...

The HTML 5 proponents are being highly overconfident in my view, and the more it gets extended and the more OS-like it becomes the more dangerous it is. If Web apps really take off as replacements for JAVA, OSes, native apps, Flash, etc it won't take long before attackers start finding the holes in it and using them. Except their attacks may well be successful across a wider range of machines, because the browser author has probably made the same mistakes in the Windows, Mac and Linux versions.

Quick question. If JAVA and Flash are bloatware, why isn't Javascript and HTML 5? HTML 5 in particular is the thickest of layers imaginable to lie between executable code and the CPU. It's a crazy way of running code.

2
0
Silver badge
WTF?

What I want to know is

Who at Oracle pissed in the US government's cornflakes? From the way the DHS has been carrying on about Java lately, you'd think they were the fourth arm of the Axis of Evil!

3
0
Thumb Up

Re: What I want to know is

+1

Exactly what I was thinking.

1
0
Linux

Re: What I want to know is

Same here. It's bizarre.

I bet if you wander the US Gov's halls, you'll find PC after PC running Microsoft Windows and IE !! The most insecure operating system and browser in existence,

A quick Google search for: security hole .net

returns a few results too.

1
0
Anonymous Coward

Could someone please tell the network support team at my work the difference between Java and Javascript? I keep overhearing them telling clients who have heard about this vuln and have phoned up worried about it that they do still need Java in their browser as most websites in the world use it.

I've tried butting in and explaining it to the support technicians myself, but when I do their eyes just glaze over because SIMILAR WORDS BE CONFUSING

Anon for obvious reasons.

2
0
Facepalm

Why turn off?

The only solution the 'security experts' seem to be able to come up with is : "turn it off".

Of course that is a valid solution if you know you will never need Java in the browser.

However Java is still widely used in the browser, perhaps not so much on public internet (except perhaps netbanks), put is - in my experience - pretty much omnipresent on corporate intranets.

Any plugin (being it Java, Flash, .NET) that allows you to download code on-the-fly and then execute it is vulnerable, sandbox or not. Bugs will always exist. The only way forward is to educate users not to say 'yes' to execute something that they don't know what is. The real problem is that too many users have had their browsers configured in such a way so that code would be executed without any prompt or active accept from the user.

There are multiple ways to force your browser (or the plugin) to give you that prompt. The new increased default security level in Java 7 Update 11 does just that. Chrome has always had this functionality. Firefox users can use NoScript extension, etc.

Personally I'm perfectly happy with the solution resulting from the new default security level in Java 7 Update 11. I believe that will provide me all the protection I need ... also against vulnerabilities that have not yet been discovered. But as far as I understand this solution has indeed always been available to me: I could have increased the default security level myself. I could have done that last week when the reports about the vulnerability first came out. But all the 'security experts' could muster was the recommendation to 'turn it all off'.

0
0
Linux

Does the exploit work on Linux?

Does it give you root access to the underlying Operating System?

0
0

Re: Does the exploit work on Linux?

One does not need root access to do bad things with a Linux system - "the standard user" is so powerful that most interesting things on a Linux system is run on crippled accounts deliberately.

Malware-injectors, all kinds of bots, spam-mailers, DDOS-applications, kiddie-porn distribution, whatever - will be perfectly functional as a normal user. Easier to install too.

0
4
Silver badge
Happy

People should listen up to the US Government ...

they are the experts in leaky systems - they leak all over the place.

Maybe Manning had a virus on his machine?

0
0

Page:

This topic is closed for new posts.