5 ms·
The Java browser plugin runs unsigned applets in a sandbox. Sandboxed applications can only use a subset of Java that should make it impossible to cause serious
by jsaxton86 13y ago
The Java browser plugin runs unsigned applets in a sandbox. Sandboxed applications can only use a subset of Java that should make it impossible to cause serious damage to the host system. However, if an attacker can break out of the sandbox, they can do whatever they want, so this is a pretty common attack vector.
If you're interested, I spent some time figuring out how these attacks work and I blogged about it here: http://jsaxton.com/fun-with-wireshark-and-ie-java-exploits-part-2/ http://jsaxton.com/fun-with-wireshark-and-ie-java-exploits-p...
- jebblue 13y agoWhat's the difference between that and running JavaScript unfettered? If the confines of the Java Sandbox can be challenged by hackers, JavaScript's day is coming and it will be huge.
- craigching 13y ago> What's the difference between that and running JavaScript unfettered? Except that the article is specifically about the Java plugin for browsers. But, that said, the fact that there have been so many Java exploits reported compared to JavaScript exploits probably says a lot about the major browser developers (Mozilla, Google, Apple, Microsoft) compared to Oracle/Sun.
- meowface 13y agoThe difference is that Javascript generally has no API for accessing file system and OS resources, but Java applets by default give full access to the entire Java standard library; it simply restricts certain parts of it with the sandbox. If a Java applet can find a way to access things on the blacklist, then it can download and run any file with your OS user privileges. With Javascript there isn't actually a sandbox to break out of.
- kleiba 13y agoIs there an implementation of the JVM in Javascript? That should address some of the issues outlined.
- pjmlp 13y ago> API for accessing file system and OS resources You mean like FileReader and WebGL/CL?
- free652 13y agoAnd so it can be exploited: http://www.scip.ch/en/?vuldb.10561 http://www.scip.ch/en/?vuldb.10561
- meowface 13y agoThis is a buffer overflow exploit in the browser, not an exploit of the API mechanics. On the other hand, most critical Java vulnerabilities are simple sandbox bypasses, not memory corruption ones.
- pjmlp 13y ago> Java vulnerabilities are simple sandbox On Oracle's implementation. There are other JVMs to choose from. Plus, can you guarantee that the JavaScript sandbox from all VMs are safe if hackers turn their attention to them?
- meowface 13y agoIBM's JVM and OpenJDK's IcedTea have fallen victim to most (possibly all, not sure) of the exact same sandbox bypass flaws as the ones in Oracle's HotSpot, mostly because the codebase of all the other alternatives still contains a huge portion of Oracle's original code.
- leoc 13y agoNot necessarily: it seems that the poor quality of specifically the Java sandbox and its security maintenance are the main problem here.