Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Bosonic

(3,746 posts)
Thu Jan 10, 2013, 07:06 PM Jan 2013

Kill that Java plugin now! New 0-day exploit running wild online

Source: The Register

A new Java zero-day security vulnerability is already being actively exploited to compromise PCs. The best way to defend against the attacks is to disable any Java browser plugins on your systems.

The offending bug is present in fully patched and up-to-date installations of the Java platform, now overseen by database giant Oracle, according to Jaime Blasco, head of labs at security tools firm AlienVault.

"The exploit is the same as the zero-day vulnerabilities we have been seeing in the past year in IE, Java and Flash," Blasco warned.

"The hacker can virtually own your computer if you visit a malicious link thanks to this new vulnerability. At the moment, there is no patch for this vulnerability, so the only way to protect yourself is by disabling Java."

Read more: http://www.theregister.co.uk/2013/01/10/java_0day/



I suspect as java is largely OS agnostic, so is the exploit...

67 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Kill that Java plugin now! New 0-day exploit running wild online (Original Post) Bosonic Jan 2013 OP
This says "PCs". Does that include Macs too, or not? ~nt 99th_Monkey Jan 2013 #1
very probably Bosonic Jan 2013 #2
how do you disable java Voice for Peace Jan 2013 #4
There's a link at the bottom of the article Bosonic Jan 2013 #6
ok thanks - it doesn't mention Macs -- but under my Firefox preferences for content Voice for Peace Jan 2013 #24
Apple Blocks Java 7 Plug-in on OS X to Address Widespread Security Threat KareBear Jan 2013 #47
ooh goody, thanks Voice for Peace Jan 2013 #64
Um, aren't there ALWAYS zero day viruses out there? FreeBC Jan 2013 #3
Yes William Seger Jan 2013 #23
All the links on the Register article enlightenment Jan 2013 #5
It's a new version of an old problem muriel_volestrangler Jan 2013 #8
Ah. Thanks. enlightenment Jan 2013 #16
'Preciate the heads up. nt cbrer Jan 2013 #7
What can this actually DO to my PC? pscot Jan 2013 #9
Right now it's being used to distribute the Reveton malware. Xithras Jan 2013 #48
I don't browse random free porno sites etc. CountAllVotes Jan 2013 #54
Thanks for responding pscot Jan 2013 #59
Great post, ty! Earth Bound Misfit Jan 2013 #67
Thank you! MynameisBlarney Jan 2013 #10
Like most articles of this ilk.. sendero Jan 2013 #11
Good point. What ARE the implications of turning off Java? Jim Lane Jan 2013 #13
There are a lot of game you need Java for. RebelOne Jan 2013 #19
But that would apply only to games you access through a browser, right? Jim Lane Jan 2013 #20
If I turn off Java on my phone some of the tabs on DU don't work Turborama Jan 2013 #21
Many sites run java applications and plugins. defacto7 Jan 2013 #26
Thank you for this. Squinch Jan 2013 #12
One more reason we geezers have a love hate think with these internet machines. I keep .... marble falls Jan 2013 #14
I'd go with getting the noscripts plug-in for firefox and not clicking on any unknown links. pam4water Jan 2013 #15
that's what I do, but it's too complicated for normals. FreeBC Jan 2013 #17
Why do I even NEED Java on my computer?? What does it actually do for me?? kestrel91316 Jan 2013 #18
Almost certainly nothing Ratty Jan 2013 #22
I did. And because I can't remember even a day later how I did it, I can't turn it back on. kestrel91316 Jan 2013 #55
I'm all for turning it off but, defacto7 Jan 2013 #27
If you play games on different sites, you need Java. n/t RebelOne Jan 2013 #53
I don't. I only play the mahjongg that came with Windows 7. kestrel91316 Jan 2013 #56
I play at only one game site and some of the games cannot be played without Java. n/t RebelOne Jan 2013 #65
There is nothing in this post SCVDem Jan 2013 #25
Except for the one above. defacto7 Jan 2013 #28
I just had to reinstall Windows the other day freeplessinseattle Jan 2013 #29
Information help, Please left on green only Jan 2013 #30
No relation at all ... 66 dmhlt Jan 2013 #31
Many thanks for your turning me on to something that is better left on green only Jan 2013 #36
FWIW...the free Calibre program has a great reader in it, too. dixiegrrrrl Jan 2013 #40
There is a malware posing as an Adobe reader update. Coyotl Jan 2013 #33
Many thanks for your thoughtful information left on green only Jan 2013 #35
Major reason I disable pop up windows in my browsers. dixiegrrrrl Jan 2013 #41
Experts advice disabling of Java browser plugin steve2470 Jan 2013 #32
On DU, disabling Java will stop MineralMan Jan 2013 #34
I disabled it in FoxFire, and wasn't able to respond to a DU jury service request without it. DeschutesRiver Jan 2013 #50
Are you guys disabling Java or JavaScript? bananas Jan 2013 #62
Turns out I'd disabled javascript, not Java. DeschutesRiver Jan 2013 #63
U.S. warns on Java software as security concerns escalate Bosonic Jan 2013 #37
crap! i need it for work. govt websites critical to my job run on java. ellenfl Jan 2013 #38
yes Bosonic Jan 2013 #39
In Fire fox, go to dixiegrrrrl Jan 2013 #42
javascript != java Bosonic Jan 2013 #43
eerrkk....u r right.... dixiegrrrrl Jan 2013 #49
Firefox 17/18 blocked Java meow2u3 Jan 2013 #45
Java is disabled on my browser(s) RainDog Jan 2013 #44
Everyone make sure you're blocking JAVA, and not JAVASCRIPT Xithras Jan 2013 #46
thanks CountAllVotes Jan 2013 #52
Thanks, I didn't understand before that there was a difference. nt DeschutesRiver Jan 2013 #57
That was helpful, thanks! and-justice-for-all Jan 2013 #60
ugh CountAllVotes Jan 2013 #51
Thanks for the heads up....... nc4bo Jan 2013 #58
What about Ubuntu? n/t AverageJoe90 Jan 2013 #61
Oracle Corp to fix Java security flaw "shortly" Eugene Jan 2013 #66

Bosonic

(3,746 posts)
2. very probably
Thu Jan 10, 2013, 07:12 PM
Jan 2013

from Experts urge PC users to disable Java, cite security flaw

...
"Moore said machines running on Mac OS X, Linux or Windows all appear to be vulnerable to attack."
...

http://www.reuters.com/article/2013/01/10/us-java-security-idUSBRE90919X20130110

 

Voice for Peace

(13,141 posts)
24. ok thanks - it doesn't mention Macs -- but under my Firefox preferences for content
Thu Jan 10, 2013, 10:05 PM
Jan 2013

there's an option to enable Java or not.. we'll see

enlightenment

(8,830 posts)
5. All the links on the Register article
Thu Jan 10, 2013, 07:15 PM
Jan 2013

go to articles posted in August of 2012.

Is this new? If so, why are all the links going to old information?

enlightenment

(8,830 posts)
16. Ah. Thanks.
Thu Jan 10, 2013, 08:28 PM
Jan 2013

B*gger. Our LMS (online course provider) requires Java to operate and the semester starts in a week and a half (and of course my classes are far from ready to launch).

Guess I need to actually start using NoScript in a serious way.

I have the flu. I do not want to deal with this right now.
*whinge, moan, complain*

Xithras

(16,191 posts)
48. Right now it's being used to distribute the Reveton malware.
Fri Jan 11, 2013, 06:18 PM
Jan 2013

Reveton has been around a while, and it's more of a pain in the ass than a real danger. Basically, it locks your computer up tight, prevents you from accessing your files, and pastes a nasty message on screen that prevents you from clicking or opening anything. The message usually carries some variant of a message claiming that your PC has child pornography, pirated files, or something like that on it. It tells you that you've been fined a small amount (usually a few hundred dollars), and that if you wire your "fine" to the FBI, they'll send you an unlock code to give you access to your computer again. Luckily, most newbie techs can remove it in about 30 minutes anyway.

It goes without saying that the money doesn't go to the FBI, and you'll never get that unlock code.

Reveton itself doesn't pull your data or invade your privacy, but simply tries to scam you out of money. Thing is, Reveton COULD easily do anything it wanted, as it ends up controlling your system. It doesn't do so simply because that's not the scam they're running. If they change the scam, or if another outfit uses the exploit for something else, the your personal privacy can go out the window in a heartbeat. That's why it's a danger.

By the way, what this article DOESN'T mention is that Reveton is primarily distributed through shady eastern European porn sites. They'll put up a "free gallery" site, link it into a western Gallery Post site (basically, sites where other porn sites advertise themselves to get traffic) and lure unsuspecting clickers in (a browser can't tell the difference between an American and Russian .com site). Someone comes in, looks at an image or two, and the virus installs itself and locks the computer down.

If you don't browse random free porn sites and don't click anonymous links in emails, the odds of you getting this virus are actually very low.

CountAllVotes

(20,868 posts)
54. I don't browse random free porno sites etc.
Fri Jan 11, 2013, 07:19 PM
Jan 2013

But damn, my ThinkPad has this on it.

I'm on my desktop now and it is ok however.

BUT, I'm screwed as I use the ThinkPad 99% of the time.

Ran SuperAntiSpyware, now got a virus check going, have cleared caches, etc.

ThinkPad is major messed up. Why? I don't know.

sendero

(28,552 posts)
11. Like most articles of this ilk..
Thu Jan 10, 2013, 08:00 PM
Jan 2013

.... it does not discuss the implications of turning off Java, it acts like it is like turning off a toaster.

 

Jim Lane

(11,175 posts)
13. Good point. What ARE the implications of turning off Java?
Thu Jan 10, 2013, 08:12 PM
Jan 2013

Does it mean that some of my programs will fail to run? which ones? Can I still use a browser to read email and surf DU?

RebelOne

(30,947 posts)
19. There are a lot of game you need Java for.
Thu Jan 10, 2013, 08:40 PM
Jan 2013

I am reluctant to turn off my Java because I play many games on Pogo.com that require Java.

 

Jim Lane

(11,175 posts)
20. But that would apply only to games you access through a browser, right?
Thu Jan 10, 2013, 08:48 PM
Jan 2013

If you download and install the game's own software, and play the game by clicking on the resulting icon on your desktop, then I'm guessing you're safe (unless the game's developers are crooked or incompetent). I ask because I play such a game.

Alas, I'm only guessing here. I'd welcome clarification from someone who actually knows this area.

Turborama

(22,109 posts)
21. If I turn off Java on my phone some of the tabs on DU don't work
Thu Jan 10, 2013, 08:53 PM
Jan 2013

So DU does lose some of it's functionality.

defacto7

(13,485 posts)
26. Many sites run java applications and plugins.
Thu Jan 10, 2013, 10:25 PM
Jan 2013

You may not be able to see some videos, some sites will be skewed a bit, others will not allow you to make comments or use buttons. It just depends on the site. A lot of comment, news and blogging sites are full of java.

marble falls

(57,077 posts)
14. One more reason we geezers have a love hate think with these internet machines. I keep ....
Thu Jan 10, 2013, 08:16 PM
Jan 2013

my virus/malware protections upgraded. I also know that I need Java. I am a computer truck driver. I know what a super charger is and does but I cannot tear one down. Compound that with dyslexia. I would rather contact Oracle and download a patch. Is this possible yet?

I wondered why I got an extra jelping of phishing junk mail today. Thanks and help.......

pam4water

(2,916 posts)
15. I'd go with getting the noscripts plug-in for firefox and not clicking on any unknown links.
Thu Jan 10, 2013, 08:23 PM
Jan 2013

Until the security hole gets patched. It looks like you have to click on a malicious link before you can get affected.

Ratty

(2,100 posts)
22. Almost certainly nothing
Thu Jan 10, 2013, 09:16 PM
Jan 2013

I'm a java programmer and I've had java turned off in my browsers for years. I have never missed it. Couple that with the fact that nowdays when you try and update Java, Oracle tries to cram new toolbars and crapware onto your machine. No thank you.

It started with the fact that Java was annoying. A lot of web sites started using it for distracting animated ads (the same reason I use flashblock nowdays). I turned it off as an experiment and was delighted to discover I never missed it.

Seriously. Turn it off, don't worry about it. You won't miss it.

 

kestrel91316

(51,666 posts)
55. I did. And because I can't remember even a day later how I did it, I can't turn it back on.
Fri Jan 11, 2013, 08:31 PM
Jan 2013

That's a WIN for declining short-term memory.

defacto7

(13,485 posts)
27. I'm all for turning it off but,
Thu Jan 10, 2013, 10:30 PM
Jan 2013

there a lot of stuff on sites that don't work without it. One good thing is that turning it off stops the hated quantserve hangs. Ad software use java applets and most info seeking pests.

I turn it on and off all the time... (Firefox)

 

SCVDem

(5,103 posts)
25. There is nothing in this post
Thu Jan 10, 2013, 10:06 PM
Jan 2013

which has a shred of credibility.

No links or attribution.

Sounds like Fox and a fear campaign!

freeplessinseattle

(3,508 posts)
29. I just had to reinstall Windows the other day
Thu Jan 10, 2013, 11:14 PM
Jan 2013

My pc had been acting funny and even just shutting off with some pics and animation, and I tried all kinds of diagnostics but no answer. Reinstalling adobe didn't help, either, now I know why, and when I reinstalled windows it took 5 frickin' tries-kept shutting off right when it went from "preparing installion" to "installing".

Fortunately I can read DU from my phone, or I would have really been tearing my hair out.

left on green only

(1,484 posts)
30. Information help, Please
Thu Jan 10, 2013, 11:51 PM
Jan 2013

Today I received an Adobe Reader Update notification prompting me to click on and install update 10.1.4. Does anyone know if this update in any way relates to the Java issue? Many thanks in advance for enlightening me.

dixiegrrrrl

(60,010 posts)
40. FWIW...the free Calibre program has a great reader in it, too.
Fri Jan 11, 2013, 03:45 PM
Jan 2013

And my Linux default opens pdf via Document reader.
So I am able to by pass Adobe most of the time.

 

Coyotl

(15,262 posts)
33. There is a malware posing as an Adobe reader update.
Fri Jan 11, 2013, 01:54 PM
Jan 2013

I'm in the habit of not using pop-up windows to update anything. My preference require a prompt for some updates, but I go to the domains directly when I do it manually.

left on green only

(1,484 posts)
35. Many thanks for your thoughtful information
Fri Jan 11, 2013, 02:29 PM
Jan 2013

As it turned out, your exact thought had occurred to me on my own, almost immediately after I clicked on the "Adobe" pop-up window. So very soon afterwards, I went and used the "revert computer back to an earlier time" function and back tracked by one day. Immediately after I did that, the Adobe update icon appeared again in my bottom tray. So I am guessing that my reversal was a success.

You'd think I would have learned by now. All of a sudden I remembered back to a while ago when I began receiving a ton of pop up windows from Yahoo (whose mail service I use) telling me to click on their pop-up to download the latest "update" from Firefox. At that time, it occurred to me to ask myself, "Why is Yahoo repeatedly sending me pop-ups to download an improvement for the software of someone else?" So I went right to the Firefox site and verified that I was already running the latest version of their software.

My conclusion was that Yahoo was trying to fool me into downloading something that would permit them to cram more of their frigging advertising down my throat.

From now on, I will never download a software update again, unless it comes directly from the internet site of the owner of that software.

dixiegrrrrl

(60,010 posts)
41. Major reason I disable pop up windows in my browsers.
Fri Jan 11, 2013, 03:58 PM
Jan 2013

I can choose to enable the pop up if I really need it, rarely have to tho.

MineralMan

(146,286 posts)
34. On DU, disabling Java will stop
Fri Jan 11, 2013, 02:05 PM
Jan 2013

the display of the reply post title list when you click the "Replies to me" numbers in My Posts. I haven't found anything else that doesn't work, yet, after disabling it in Chrome.

DeschutesRiver

(2,354 posts)
50. I disabled it in FoxFire, and wasn't able to respond to a DU jury service request without it.
Fri Jan 11, 2013, 06:20 PM
Jan 2013

Took me a minute to understand what was happening, as I have dialup and there are lots of times I try to respond to things, but can't because it has slowed everything online to a crawl.

This time I remembered, turned the java back on and immediately could accept the jury summons.

bananas

(27,509 posts)
62. Are you guys disabling Java or JavaScript?
Sat Jan 12, 2013, 01:38 AM
Jan 2013

They're different.
DU uses javascript, but I don't think it uses Java at all.

DeschutesRiver

(2,354 posts)
63. Turns out I'd disabled javascript, not Java.
Sat Jan 12, 2013, 01:49 AM
Jan 2013

After reading another post, I enabled my javascript again.

Then I checked at Java.com and there was no Java found. I am computer illiterate, fact. But now I sort of know a little bit of something that I didn't know before, so it's all good

Bosonic

(3,746 posts)
37. U.S. warns on Java software as security concerns escalate
Fri Jan 11, 2013, 02:33 PM
Jan 2013

(Reuters) - The U.S. Department of Homeland Security urged computer users to disable Oracle Corp's Java software, amplifying security experts' prior warnings to hundreds of millions of consumers and businesses that use it to surf the Web.

Hackers have figured out how to exploit Java to install malicious software enabling them to commit crimes ranging from identity theft to making an infected computer part of an ad-hoc network of computers that can be used to attack websites.

"We are currently unaware of a practical solution to this problem," the Department of Homeland Security's Computer Emergency Readiness Team said in a posting on its website late on Thursday.

"This and previous Java vulnerabilities have been widely targeted by attackers, and new Java vulnerabilities are likely to be discovered," the agency said. "To defend against this and future Java vulnerabilities, disable Java in Web browsers."

http://www.reuters.com/article/2013/01/11/us-java-security-idUSBRE90A0S320130111

ellenfl

(8,660 posts)
38. crap! i need it for work. govt websites critical to my job run on java.
Fri Jan 11, 2013, 03:13 PM
Jan 2013

i use forefox. can i just enable/disable when needed?

dixiegrrrrl

(60,010 posts)
42. In Fire fox, go to
Fri Jan 11, 2013, 04:11 PM
Jan 2013

"Edit" > "preferences"> " content" where you will find an "enable Java Script" box to uncheck.
fast and easy to re-check it for things you really need.

I have it off almost all the time.

meow2u3

(24,761 posts)
45. Firefox 17/18 blocked Java
Fri Jan 11, 2013, 05:18 PM
Jan 2013

I run Firefox and checked my add-ons tab. When I clicked on plug-ins, I found out that Firefox blocked Java until a fix is available because it's vulnerable. I have to play Pogo on IE9--the only time I'm using IE.

RainDog

(28,784 posts)
44. Java is disabled on my browser(s)
Fri Jan 11, 2013, 04:37 PM
Jan 2013

For the last month, whenever I click on (most) pages to read something while using Firefox, I get a drop down box that says "Java script error" and something about syntax, with an "ok" button to click.

I have to click this button, sometimes six times in a row, to unfreeze Firefox. I can't make this stop happening.

As a result, I'm using Chrome more and more.

Does this happen to anyone else?

Xithras

(16,191 posts)
46. Everyone make sure you're blocking JAVA, and not JAVASCRIPT
Fri Jan 11, 2013, 06:03 PM
Jan 2013

I'm seeing a lot of comments about lost functionality here that sounds like people are disabling Javascript. In spite of the similar names, they two are NOT the same technology. More importantly, if you turn off Javascript, or simply disable scripting, it will NOT disable Java, which means that your computer will still be vulnerable to the virus.

Also, everyone should be aware that many modern antivirus applications are ALREADY blocking this exploit. I'm running the latest TrendMicro patch, which already has protections in place for this virus. If you have antivirus software in place, I would suggest that you check their site and update it FIRST. You may only need to get a definitions update to protect yourself.

If not, here's how you block the virus on Windows....

IE9: Gear Icon > Internet Options > Programs > Mange AddOns. Click on the Java Helper from Sun Microsystems, and click the Disable button.

Chrome: No need to disable anything. Chrome disables Java by default. Whenever a page wants to use it, Chrome will ask you whether you want to permit it. Just say NO until this problem is patched.

Firefox: Firefox > Add Ons. Click the Plugins tab. Find the Java Platform plugin, and click the Disable button.

Mac Users: Yes, you're vulnerable. The exploit is currently only being used to distribute the Reveton virus to PC's, but they could potentially release a virus for the Mac at any time. Unless you need Java for something, there's no reason to leave your computer exposed. Firefox and Chrome instructions are the same as the PC.

To disable Java on Safari, click Safari > Preferences. Click the Security button, and uncheck the Enable Java checkbox.

CountAllVotes

(20,868 posts)
51. ugh
Fri Jan 11, 2013, 06:48 PM
Jan 2013

I think I got "it".

Have disabled Java running SuperAntispyware.

Laptop was trying to run a wireless connection but I have a DSL connection.

OH WHAT A MESS!!!!!

Updated Firefox ... Fu ... KKKKKKK!!!!

nc4bo

(17,651 posts)
58. Thanks for the heads up.......
Fri Jan 11, 2013, 08:39 PM
Jan 2013

I disabled my Java crap a long time ago but will certainly pass the word!

Eugene

(61,872 posts)
66. Oracle Corp to fix Java security flaw "shortly"
Sat Jan 12, 2013, 03:58 PM
Jan 2013

Source: Reuters

Oracle Corp to fix Java security flaw "shortly"

By Jim Finkle
BOSTON | Sat Jan 12, 2013 1:15pm EST

(Reuters) - Oracle Corp said it is preparing an update to address a flaw in its widely used Java software after the U.S. Department of Homeland Security urged computer users to disable the program in web browsers because criminal hackers are exploiting a security bug to attack PCs.

"A fix will be available shortly," the company said in a statement released late on Friday.

Company officials could not be reached on Saturday to say how quickly the update would be available for the hundreds of millions of PCs that have Java installed.

The Department of Homeland Security and computer security experts said on Thursday that hackers figured out how to exploit the bug in a version of Java used with Internet browsers to install malicious software on PCs. That has enabled them to commit crimes from identity theft to making an infected computer part of an ad-hoc computer network that can be used to attack websites.

[font size=1]-snip-[/font]


Read more: http://www.reuters.com/article/2013/01/12/us-usa-java-security-idUSBRE90B0EX20130112
Latest Discussions»Latest Breaking News»Kill that Java plugin now...