9 ms·
New Java 0-day exploit spotted in the wild.
- FixThisPOS 14y ago"O-day"?
- Qz 14y agoI've become rabidly anti-Java. My friend installed Java on my computer as part of the process of rooting my HP touchpad to install android, and within days my antivirus had detected multiple java-based attacks on my system. These were literally the first attacks since I'd wiped my HD after a previous Java related attack. I uninstalled Java immediately, and hope that I never have to install it again.
- stock_toaster 14y agoI am not a fan of the Java stack either, and for the most part am successful at keeping it away from my daily work. It is a shame too, as there are some really useful things out there that were build on Java (the ones I care about run on the server). That said, there is a jenkins box running at $dayjob that of course requires Java. However, if I had a choice between jenkins and jenkins-clone-built-with-something-else, all things being equal I would choose jenkins-clone-built-with-something-else.
- karlmdavis 14y ago> if I had a choice between jenkins and jenkins-clone-built-with-something-else, all things being equal I would choose jenkins-clone-built-with-something-else What on earth for? It's not as if the Java binaries on a (non-multi-user) server somehow make it less secure.
- tedunangst 14y agoEven if it is multiuser, they're not installed with any special privileges. You can install java in your home directory. I can't wait for the day when people get their wish, and 50% of the installed browser base will run random python scripts off the web.
- X-Istence 14y agoThere is a certain amount of Java stuff I have running at $work as well, and the one I really care the least about is Jenkins, at least it isn't executing random code from the web. The one that has me worried way more is all of the Android build tools. I've had random crashes happen in them and there is no good way to debug the issue. Java throws stack traces that if printed would cost you a ream or two of paper and sometimes you get crashes in something completely unrelated. Ugh, there are many things I wish for, but Java no longer existing is probably one of my biggest wishes.
- pserwylo 14y agoIs it the JVM throwing incomprehensible stack traces? Or is it the android SDK throwing slightly less but still uselss stack traces? I often see the later, which is just poor error/exception handling by the developers. I very rarely (sometimes, but not enough to get annoyed) see the JVM printing out stack traces.
- andrewvc 14y agoA stack trace is a stack trace in any language. It's the app developer's responsibility to provide a useful error messages after catching an exception. This is CS 101, GiGo
- kbolino 14y agoNot all exceptions are caught, and not all caught exceptions can have useful error messages. Try to figure out the cause of an SQLException in code and you will quickly realize it is an exercise in futility. To top it off, you are at the mercy of the implementer, who often seems to choose the most cryptic message possible. Sometimes, all you have is a stack trace.
- taligent 14y agoNo offence but if you don't understand how stack traces work and why it isn't a "Java" wide problem then no offence but you really are in no position to comment. It really isn't that hard to understand.
- jebblue 14y agoI and everyone I know runs Java apps and on the server and on smart phone along with hundreds of millions of other people in the world and we all get along fine.
- skymt 14y agoBoth Firefox and Chrome have features that disable plugins but still allow you to run individual applets on demand. Please turn these on; it's not much hassle and you'll be shutting down the most common targets for exploits. For Chrome, go to advanced settings -> Privacy -> Content settings -> Plug-ins and select "click to play". For Firefox, go to about:config and enable "plugins.click_to_play".
- stevencorona 14y agoAwesome, I had Click2Flash installed on Chrome, but no idea it basically already came built into the browser.
- im3w1l 14y agoIs clickjacking a solved problem or will this only raise the bar a little?
- arkitaip 14y agoI would go one step further and recommend that you uninstall Java thus removing one attack vector. I did so a couple of months ago and have yet to find a case where I really needed Java.
- shanemhansen 14y agoTo eliminate further attack vectors, uninstall both the browser and the OS ; ). I just want to point out that's there's a big difference between having an interpreter on your machine like python, ruby, or java, and having a browser plugin that executes remote code by default. There's nothing wrong with the former, there's everything wrong with the latter.
- jebblue 14y agoDo you mean Java in the browser? If so, what do you think is happening when your JavaScript code hits your server's REST code returning JSON?
- lanstein 14y agoI'll take this opportunity to recommend that anyone who is in security should think about going to work at FireEye. Ridiculously cool technology, and they routinely lead Botnet takedowns to boot, e.g. http://www.fireeye.com/news-events/press-releases/read/fireeye-takes-down-grum-botnet http://www.fireeye.com/news-events/press-releases/read/firee... Email me at the email in my profile if you would like a warm intro. Disclaimer: my brother is a long-time engineer.
- SCdF 14y agoIt's interesting that so many consumers (read: not java developers) have Java installed at all. I code in Java for work and so it's on those boxes, but I have never found a need for it at home. I've only rarely come across a website that requires it. (The only exception is ADOM2, but that doesn't require a browser plugin, you just download it like any other executable [that you trust]) Does anyone here write consumer-focused non-server Java software?
- MichaelGG 14y agoA lot of online meeting/sharing/video conf sites seem to require Java. That's the largest reason I'm aware of.
- Beldur 14y agoI'm using http://www.gokgs.com http://www.gokgs.com a lot. Its a Client for the boardgame GO.
- ThJ 14y agoThe 3-D Secure VISA system in Norway is based on BankID (https://www.bankid.no/Dette-er-BankID/BankID-in-English https://www.bankid.no/Dette-er-BankID/BankID-in-English) and uses Java. Everyone with a computer and a bank account has the Java plugin installed. Internationally, the majority of oekaki (online painting board) software has traditionally used Java because of its speed and versatility. My own real-time collaboration software, Sketcher, requires Java 1.5 at minimum. The software does bit-banging and custom pixel-level rendering and image compression in tight loops that can't be done fast or well enough in HTML5 or even Flash, and wasn't even possible back in 2004 when the software was originally developed. The Java code isn't as fast as native code, but it's pretty close, with Photoshop type pressure sensitive brushes rendered in real-time. I've been looking at WebGL, but the technology isn't really ready for a mass market yet, and is widely criticized for the security holes it potentially introduces by exposing the OpenGL API to the DOM. The whole web community seems to be ignoring rich content rendered on the client side. Without these capabilities, we'll never have real web app versions of programs like Photoshop. Right now, my focus is on getting Kickstarter funding and developing a more user friendly version of my app for iOS, where such facilities are available today.
- andor 14y agoIn case anybody at FireEye reads this: is Windows XP the only OS vulnerable to this attack?
- techinsidr 14y agoI'm not from FireEye, but XP is not the only OS vulnerable. Rapid7 has created an exploit for Metasploit and was able to successfully execute an attack against a fully patched Windows 7 SP1 with Java 7 Update 6. http://www.securityweek.com/new-java-exploit-spotted-wild http://www.securityweek.com/new-java-exploit-spotted-wild
- freehunter 14y agoIn addition to 7 which was already mentioned, Rapid7 says they've successfully tested it against Ubuntu 10.04 and OSX 10.7.4 as well. https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day https://community.rapid7.com/community/metasploit/blog/2012/... Errata Sec claims it's working on a fully-patched Ubuntu 12.04, provided you're using the official Java package instead of the default OpenJRE. OSX 10.8.1 has also been confirmed. http://erratasec.blogspot.com/2012/08/new-java-0day.html http://erratasec.blogspot.com/2012/08/new-java-0day.html
- cedmart 14y agoAll these Java exploits --both client and server-side-- are really bad. I'm (mostly) a Java dev and I'm really sad at all this (probably deserved) bad rep Java is getting. I run Java on Linux and my setup is simple: I install Java in my "dev" account from the .tar.gz. There's no way I'll ever ever login as "root" to install Java on a Linux machine and there's no way Java ever gets installed in something else than my "dev" user account. I surf the net from another account which, of course, has no Java installed. I also admin two Java webapp servers and closely follow all the security issues: had to patch them twice "recently". First the DoS SNAFU related to predictable hashmap hashes where anyone could remotely DoS any Java webapp server (quite bad) and then the "infinite looping" when parsing I don't remember which HTTP header triggering a bug in floating-point code. Both bugs where known since more than ten years and Sun/Oracle never acted. It's really a quite sad state of affair.
- verroq 14y agoFireeye needs to learn how the censor IPs. From the screen shot I could tell it was 59.120.154.62.
- freehunter 14y agoI wish they wouldn't censor it at all. Working in network/information security, when I see one of these posts the first thing I do is go into our SIM tool and look to see if any of our clients have been seen talking to this address. I then do a reverse-DNS lookup to find the domain name they have censored to see if our DNS has been talking there. Censoring it just makes my job harder, and defeats the point of the entire blog post.
- verroq 14y agoAh well. Somebody already has obtained the sample from the url for us. Most likely bruteforced the address. http://twitter.com/jduck1337/status/239875285913317376 http://twitter.com/jduck1337/status/239875285913317376
- freehunter 14y agoReverse-DNS'ing the IP address gave me the URL they mentioned and censored in the article. I didn't want to post it here on HN because this isn't the place for that. I would think FireEye's blog would be that place. I'll have to get with my FireEye sales engineer to see why they censor there.
- verroq 14y agoHow did you find the domain through reverse dns? None of the queries I ran gave any useful results.
- freehunter 14y agoI use robtex.com to reverse-DNS [1]. It tells you if the address is listed in any blacklists, what domains are registered there, who owns the network, and where the geographical region of the server is. Listed in the registered domains is something awfully similar to what FireEye has censored out. [1] http://www.robtex.com/ip/59.120.154.62.html#ip http://www.robtex.com/ip/59.120.154.62.html#ip
- moultano 14y agoAsking out of genuine curiosity about the semantics, not being a grammar troll. Is New 0-day exploit redundant? Are all 0-day exploits new?
- Jimmie 14y agoAFAIK a 0-day exploit is an exploit that was found in the wild. No one previously knew about it and there's a scramble to fix it. In a week this exploit will be an "old 0-day exploit" because the "0-day" bit describes developer preparedness at discovery, not how long the exploit has been known.
- lmm 14y ago"n-day" refers to the number of days since a fix was released. So a vulnerability can be "0-day" indefinitely if the software maker never patches it - and in those circumstances it would make sense to talk about an "old 0-day".
- conductor 14y agoThe exploit (applet.jar) contains two classes - Gondzz (dropper downloader) and Gondvv (the exploit). Here is the decompiled source code of Gondvv: http://pastie.org/4594319 http://pastie.org/4594319