16 ms·
Facebook computers compromised by zero-day Java exploit
- jff 14y agoAaaand that's why I don't have the Java plugin installed. Anywhere. I'd like to think that we're almost to the point of viewing Java in the same light as Bonzi Buddy or Comet Cursor; IT discovers you got Java on your computer again, they just sigh and re-image it, with some stern warnings to please not download such sketchy software.
- onedev 14y agoBonzi Buddy was my childhood computer hero.... Ahh to be 11yrs old again...
- jacquesm 14y agoThere is a data room by a very large M&A group that requires you to install Java. I hate them with a passion because you can't really avoid them in my line of work so I end up having a VM just for them. Java as a requirement to access a document store for which you've already signed a pretty solid NDA is a real nuisance. Especially since it then ends up giving you download access through their applet anyway...
- bilbo0s 14y agoJava and Flash... I mean really ... how many zero day flaws does it take before people turn this stuff off?
- jlgaddis 14y agoI wish that were the case. Large companies tend to have important enterprise applications that require Java to run and, even worse, in some cases upgrading the version of Java on the user's desktop will break the application. You then end up with hundreds or thousands or users with vulnerable versions of Java on the PC that you can't upgrade until the software vendor fixes whatever is wrong with their application. I've seen it countless times at my previous job (.edu with 1000s of staff and faculty) where we were basically helpless to do anything because absolutely critical applications would break if we upgraded Java on the desktop. Solution: closely monitor traffic to/from user's PC's, hope for the best, and re-image when they inevitably got pwned. Before someone chimes in with the obvious "switch to a different application", it's not that easy when you have millions invested and training the user base sometimes takes months. Yeah, I hate Java.
- yuhong 14y agoOracle BTW offers paid support for old Java versions long after they no longer release public updates. The Feb 2013 end of support date for 6.0 is for free support.
- pjmlp 14y ago> Yeah, I hate Java. What about C and C++ induced security holes?
- canttestthis 14y agoIndeed. Compare the number of Java vulnerabilities (plugin vulnerabilities included) with the number caused due buffer overflows and such in C/C++.
- hshshzjaj 14y agoDon't forget rails. Is also crap.
- pjmlp 14y agoDo you have C and C++ dynamic libraries installed instead?
- lucian1900 14y agoIt is an excellent idea to always use click to play for all plugins.
- error54 14y ago"The attack was injected into the site's HTML, so any engineer who visited the site and had Java enabled in their browser would have been affected," Sullivan told Ars, "regardless of how patched their machine was." It's criminal how Oracle can release production code with so many security holes. It seems like every week there is a new new Java based exploit.
- yuhong 14y agoSome of these vulns are extremely old. I read the Oracle security bulletin which says some of them dates back to 1.4.2. (Oracle is still willing to support such old versions if you pay for it)
- mtgx 14y agoIsn't the Skype plugin for Facebook video-chats made in Java, too? Sounds to me like Facebook should be one of the very first companies to want to adopt WebRTC. Not only will they become independent of Skype for video-calls, but they can offer it for everyone inside the browser, too, instead of getting them to install plugins. Hopefully they intend to make it federated though, rather than keeping it Facebook-only.
- niggler 14y agoThey also have the crucial directory ability that WebRTC doesn't describe. "Hopefully they intend to make it federated though, rather than keeping it Facebook-only." What part of Facebook's history suggests that they wouldn't make it tied to a Facebook account?
- rmc 14y agoThat's presuming Web browsers won't have any bugs in how they do webrtc that could allow someone to take over the browser. Web browsers sometimes have bugs like this. I believe iPhone 1.1 had a bug in TIFF images that people used to jail break the phone
- ubercow13 14y agoPresumably it could be sandboxed for security, being a feature of the browser itself, which Java can't be.
- rmc 14y agoSure, but what if there's a bug with your sandboxing and code can escape the sandbox? There is no magic bullet.
- badgar 14y ago> I believe iPhone 1.1 had a bug in TIFF images that people used to jail break the phone Yep, there was a buffer overflow in the libtiff. http://theiphonewiki.com/wiki/LibTiff_Exploit http://theiphonewiki.com/wiki/LibTiff_Exploit
- speeder 14y agoJava is that prevalent to make it a good target, or it is full of holes making it a easy target? Also this must be (more) very negative pr to Oracle
- druiid 14y agoIt's a combination of both. Java is on nearly every platform out there at this point in one form or another... and the 'Oracle' version of it is full of enough holes to drive the asteroid that just passed by earth... through.
- chubot 14y agoMicrosoft really stepped up their game in the last 5-10 years, particularly with being aggressive about pushing security updates. So basically attackers are moving to other ubiquitous software with holes, e.g. Java. That's apparently also why you saw an increase of using Adobe Reader as a vector.
- martinced 14y agoIt's complicated. First, yes, Java is that prevalent. There's no a single corporate company out there were there's not Java devs. As simple as that. Then Java is also on so many systems even outside the corporate world: both Windows on OS X. It's typically not there by default but on Windows it depends on who ships the machine. On OS X now at least they don't ship it by default but it's trivial to install. But really the problem ain't Java but Java applets. Java as in "The JVM" is actually not bad at all on the server side: on the contrary, it's very robust. There are have been two very lame exploits in 2011 allowing Denial of Services on Java webservers, but no remote exploit working on Java servers. The problem is Java on the client-side: i.e. on people's computers. In other word: the issue is pathetically lame Java applets. Java applets have to be the most stupid, silly and insecure lame technology ever invented by Sun. You should have been there in comp.lang.java.programmer back in the nineties when people were saying how stupid, silly and insecure a lame tech Java applets were... Only to be laughed at by the like of Jon Skeet (the most upvoted user today on StackOverflow). To most Java early adopters Java applets were "the nuts". Supposedly the one tech going to solve all our problems. It "only" took close to 15 years to prove wrong all the retards who thought Java applets were a good thing. And now we're in this big mess. For end-users it's easy: remove Java or disable Java applets. But for the corporate world it's not so simple: many devs are, well, Java devs. Because Java is pretty much what powers the corporate world (hint: no, it's not Excel). Then even if most apps tend to be webapps now, there are still a lot of in-house apps which are Java apps and corporate drones do need to use these apps. Then there are all the Android / dalvik devs: world is moving to mobile and Android is huge. Hence Java is huge. Hence you can count on many, many, many more Java exploits being used to infiltrate companies. Companies whose users / devs are using very poor security practices anyway.
- 0x0 14y agoAny ideas on which "waterhole" website was compromised?
- ianhawes 14y agoI would suspect that it would be related to Android development given that (1) Android SDK requires Java, (2) Facebook develops a native Android app, (3) Facebook does NOT develop a native Blackberry app (other mobile SDK using Java), and (4) the identified engineer(s) were on the mobile team.
- dsl 14y agoHaving the Java plugin installed does not mean they were doing Java development. It could have been iOS engineers and they had the plugin enabled so they could access some internal application.
- lawnchair_larry 14y agoI can't believe this hasn't been mentioned. It's kind of important for other people to know if they've hit the site as well.
- uptown 14y agoThe only reason I still have Java installed on my OSX machine is to use a SQL Server management tool. If I were to run that in a virtualized environment by installing Parallels and running a separate instance of OSX in that virtual environment, would that completely isolate Java to that one "box" and protect the rest of my environment?
- 0x0 14y agoIt would help tremendously, but I believe there have been cases of exploits allowing attackers to jump from a guest VM to a host machine.
- glhaynes 14y agoPretty much, at least as long as you didn't share any folders between the host and the VM.
- dbloom 14y agoDoes the management tool run as Java web page plugin, or as a standalone Java application? If it's the latter, just disable the Java plugin in all of your browsers and you should be safe.
- uptown 14y agoIt's a Java application (www.dbvis.com) so I guess if I disable the plugins I should be good. Open to any alternative suggestions.
- xradionut 14y agoRun a copy of Windows in a VM and ditch Oracle's Java. That way you can run SSMS, etc... I run Windows 7 and Server 2012 along with various versions SQL Server in VMWare on a Ubuntu host with no issues.
- jakub_g 14y ago> Rather than using typical targeted approaches like "spear phishing" with e-mails to individuals, the attackers used a "watering hole" attack—compromising the server of a popular mobile developer Web forum and using it to spring the zero-day Java exploit on site visitors. > "The attack was injected into the site's HTML, so any engineer who visited the site and had Java enabled in their browser would have been affected," Sullivan told Ars, "regardless of how patched their machine was." It seems it's high time now to start working with two separate profiles in a browser if you're forced to use Java - one internal-only with Java enabled, and the second for browsing the internet, with Java disabled (of course this works as long as your internal apps do not get hacked...). Rather easy to achieve with Firefox (probably there are command line switches for Chrome as well): 1. Create two profiles, `external` and `internal`, using `firefox -p` 2. Open external profile and disable Java (will be kept in profile settings) Then, run first `firefox -p external`, then `firefox -no-remote -p internal`, that way links opened e.g. from email clients will go to the external instance. To differentiate the two instances, you can install some theme: http://www.getpersonas.com/en-US/ http://www.getpersonas.com/en-US/ Total paranoiacs could try to find/write some extension that will block all the pages other than approved internal ones in the internal profile (perhaps AdBlock Plus will do?).
- dfc 14y agoI think the separate profiles is the better looking tinfoil hat. For everyday browsing Adblock is nice, but I think it falls short. Throw NoScript and RequestPolicy into the mix and it gets a lot better. My friends always laugh when they watch me browse the web because I have to enable javascript for any new site and then use RP to allow that site to make requests to other domains.
- nikcub 14y agoIf your default browser still has the plugins enabled for Java, Acrobat and Flash you are asking for it. In Chrome: go to chrome://plugins and disable all Safari: Preferences, Security uncheck 'Enable Plugins' Firefox: Tools > Addons > Plugins Tab > disable all Don't use Flashblock or Javablock or similar extensions, they hide the applet, they don't stop execution. You should always use a browser with all plugins disabled as your default browser. Run a second browser for trusted sites where you enter the URL in yourself.
- signed0 14y agoFirefox started blocking Java plugins in January '13. I wonder how long before other browsers follow suit.
- nikcub 14y agoFirefox also has the feature that will block Flash and the other plugins if an update has been released, which is also good IMO all browsers should implement 'click to run' by default for all plugins on all sites
- jakub_g 14y agoThis works only for outdated Java versions that are known to be vulnerable (they're blacklisted by Mozilla version-by-version). If you happen to have the newest Java version which hasn't been publicly announced as exploitable, it will not be blocked unless you enable `plugins.click_to_play` in `about:config`. Anyway it's still a very good move from Mozilla side to minimize the risks.
- signed0 14y agoThat's too bad, I was hoping they had made all Java plugins "click to play" or whitelist only.
- deleted 14y ago[deleted]
- anonymouz 14y ago
- gdeglin 14y agoI wonder what the most practical but effective defense against these kinds of exploits would be? Company-wide install of NoScript? But that wouldn't save you if a trusted site got compromised. Maybe they should prohibit use of all commonly targeted software? (Flash, Acrobat Reader, Java..) This seems really serious. Surely someone must be working on a better way to protect against this kind of thing?
- jakub_g 14y agoRegarding the corporate users, I think actually most of them should not need any of those 3 plugins enabled: 1. Acrobat Reader plugin: use some less popular PDF reader which is not that commonly attacked 2. Flash: you shouldn't play Flash games in the office ;) For Youtube, you can enable HTML5 version in modern browsers 3. Java: IMO it's mostly needed in IE6-dating web apps but I might be very naive here... Regarding Acrobat: there's a built-in PDF reader coming in Firefox soon (pdfjs). Currently I do not use any plugin, just make the browser download a PDF and render it in SumatraPDF or PDF Xchange Viewer.
- ams6110 14y agoSometimes you really need Acrobat though. For fill-in PDF forms none of the other "readers" really do an adequate job.
- drucken 14y agoFor fill-in PDF forms none of the other "readers" really do an adequate job. That is not really relevant to a browser plugin. You can download and fill in PDFs with whatever application you like without browser plugins.
- jakub_g 14y agoExactly. BTW are the fill-in PDF forms that prevalent? I've only been using them once a year to fill my tax declaration which sadly requires installation of Adobe Reader plugin in Poland. I feel the corpo world prefers Excel for that kind of things :)
- jtheory 14y agoThis happened last month, so it was 0-day THEN, not NOW. The hole in question was patched in the February 1st Java release. This is news because it shows how Facebook was affected by the many unaddressed security holes that were present in Java (and how it could be run -- last month -- silently), but this is NOT news of new holes in Java. So far the latest (quite significant) fixes seem to have been effective.
- ihsw 14y agoHow long will we wait and shrug our shoulders until we start blaming Oracle and looking for assurances this doesn't happen again? 'Free' services continuously disappoint me, notwithstanding FLOSSware. Perhaps there is a mole at Oracle leaking security holes elsewhere.
- klausjensen 14y agoI have two banks, that require me to use Java. Please, banks, stop using java, so we can finally get rid of that POS.
- klapinat0r 14y agoWhile I don't have the reference, I'm fairly certain NemID has announced that they're looking towards a non-java interface.
- ams6110 14y agoOr, you know, you could change banks. Sort of a PITA but not really THAT big a deal....
- drucken 14y agoAgreed. But for anything that needs a browser plugin, you can run it in a VM, if it is your own hardware. VM software is often free and extremely useful anyway for developers or security.
- recoiledsnake 14y agoWonder if those laptops were running Windows, OS X or Linux. Hard to find details on that, anyone know?
- drucken 14y agoWhy would it matter? The initial attack vector is the same no matter the OS: Java in the web browser.
- blazingfrog2 14y ago"The attack was injected into the site's HTML, so any engineer who visited the site and had Java enabled in their browser would have been affected," Sullivan told Ars, "regardless of how patched their machine was." How can one find out if one has been infected?
- martinced 14y agoDefense in depth. People should really all consider doing what I do: install a throwaway VM on your system from which you surf the Web. For all the sites that I don't trust I do surf from a VM which can be erased / re-installed at will. For sites I trust, like my GMail / Google Docs, I surf from a separate user account. I'm using a firewall that can do "per user" rules and I'm only using whitelists. By default no packets can be emitted. Then the user account used to access GMail / Google Docs is configured so that it can emit HTTP/HTTPS trafic. No Java in the user accounts / VM that do surf the Web: and I'm a "Java" dev (Java + Clojure). Java can be installed only for one user account on Linux, without needing to be root. Wanna do online banking / MoneyBookers / etc.: boot a read-only Linux CD / DVD. Yes, it is slightly more inconvenient than using your main user account to surf the Web. But so far security and conveniency haven't exactly been good matches yet. The state of security today is really terribly bad. It is so bad that I'm going back to a "stupid" Nokia S40 phone until things settle down.
- Osmium 14y ago> Yes, it is slightly more inconvenient That's not just inconvenient, it's verging on paranoia. Most people haven't got the time or the processor cycles to spare to run a separate VM. What's wrong with just disabling plugins for all but trusted sites?
- xyzzy123 14y agoThere are lots of browser bugs which aren't plugin related at all. Lots of DOM/parser/JS stuff; the most popular bug class at the moment is use-after-free.
- ZoFreX 14y ago> Most people haven't got the time or the processor cycles to spare to run a separate VM Processor cycles? If I run Firefox inside a Windows VM on my MBP it's faster than the native version.
- lalc 14y agoI'd like to see a custom version of Chromium for this purpose. Google's sandboxing is great. Just reduce the attack surface by stripping out non-essentials like plugins, SVG, WebGL, NaCl, etc. etc. and you have a pretty darn secure browser. See the ridiculous complexity of those two exploits by Pinkie Pie for what attackers are up against. Seems like a good convenience/security tradeoff to me.
- logn 14y agoAre there any good malware scans for Mac? Obviously it's not going to prevent a novel attack, but I'd like to see if I'm infected with this or other known attacks.
- pjmlp 14y agoBrowser plugins are bad and should be eradicated. But that is only half of the way, because thanks to C and C++ runtimes, they are still open to security exploits triggered by buffer overflows, strings misuse, use after free, double deallocation, array access out of bounds, stack overflow, pointer misuse... The only safe way is to use a separate VM for browsing, or failing that, run the browser under a different user account with limited user rights.