Just two weeks after Oracle officially took over responsibility for Java on OS X with the launch of Java SE 7 Update 6, a new Java vulnerability has been discovered to pose a significant threat to systems running the software. Krebs on Security highlighted the issue yesterday, noting that it affects all versions of Java 7 on most browsers.News of the vulnerability (CVE-2012-4681) surfaced late last week in a somewhat sparse blog post by FireEye, which said the exploit seemed to work against the latest version of Java 7, which is version 1.7, Update 6. This morning, researchers Andre’ M. DiMino & Mila Parkour published additional details on the targeted attacks seen so far, confirming that the zero-day affects Java 7 Update 0 through 6, but does not appear to impact Java 6 and below.
Initial reports indicated that the exploit code worked against all versions of Internet Explorer, Firefox and Opera, but did not work against Google Chrome. But according to Rapid 7, there is a Metasploit module in development that successfully deploys this exploit against Chrome (on at least Windows XP).The report notes that Oracle is moving to a quarterly update cycle for Java, meaning that the next regularly-scheduled update to Java SE 7 is not planned until October, but it is unclear how quickly the company will move to address the issue. In the interim, some security experts are developing an unofficial patch while users are advised to simply disable Java if they do not need it active on their systems.
Computerworld reports that the issue does indeed affect fully-updated Macs running Java 7 on top of OS X Mountain Lion.David Maynor, CTO of Errata Security, confirmed that the Metasploit exploit -- which was published less than 24 hours after the bug was found -- is effective against Java 7 installed on OS X Mountain Lion.
"This exploit works on OS X if you are running the 1.7 JRE [Java Runtime Environment]," said Maynor in an update to an earlier blog post.
JRE 1.7 includes the most-current version of Java 7, dubbed "Update 6," that was released earlier this month.Both Safari 6 and Firefox 14 have been found to be vulnerable to the issue on OS X systems.
Apple has of course had its own issues with Java vulnerabilities, most recently with the Flashback malware that was able to infect over 600,000 Macs by taking advantage of an exploit in Java 6 that had already been patched by Oracle for most platforms but not by Apple for OS X. It is due to smaller, previous incidents similar to Flashback that Apple had already been moving to shift responsibility for Java updates to Oracle, a move that is taking place with Java 7. But while Mac users will now receive Java updates simultaneously with users on other platforms, Java remains one of the highest-profile targets for attackers seeking to compromise systems on a broad basis.
Update: CNET noted earlier today that most Mac users are not currently susceptible to the issue, as Java 7 is not installed by default on Macs. The current version of Java installed on Mac remains Java 6 for the time being, so users would have to have manually updated to Java 7 in order for their systems to be vulnerable. read more..
Wednesday, 29 August 2012
Java Runtime Environment-Latest Version Of Java-Security Vulnerability-Oracle
Sunday, 8 April 2012
Malicious Website-Trojan
According to Russian antivirus firm Dr. Web, over 600,000 Macs worldwide are infected with the Mac flashback trojan. The trojan can be installed if you visit a malicious website, and it will attempt to connect your Mac to a botnet. Fifty-seven percent of infected machines are located in the US and 20 percent are in Canada. There are even 24 infected machines supposedly connected to the botnet from Apple's Cupertino campus. This trojan targets a Java vulnerability in Mac OS X that was recently patched. It should be noted that in OS X 10.7 Lion, Java isn't included by default; only those who have deliberately installed it are potentially vulnerable to this exploit (or those running Snow Leopard or earlier OS X versions). If you installed it at some point but no longer have a reason to run Java, you should probably turn it off completely or at a minimum disable it in Safari. F-Secure has provided a set of diagnostics that'll let you know if you have been infected. If you have the malware on your machine, F-Secure's page can walk you through the steps to remove the infection. Thanks to everyone who sent this in. [Via The Loop]How to find/remove the Flashback trojan originally appeared on TUAW - The Unofficial Apple Weblog on Thu, 05 Apr 2012 10:15:00 EST. Please see our terms for use of feeds.Source | Source | Permalink | Email this | Comments read more..
Sunday, 25 March 2012
Address Bar Spoofing-Safari Address Bar-Security Alert-Security Issue-Device Ios
Users of iPhones, iPads, and iPod touch devices running Safari on iOS 5.1 should beware of a security issue that involves address bar spoofing. The issue was discovered by David Vieira-Kurz of MajorSecurity.net, and involves "an error within the handling of URLs when using javascript's window.open() method." What does this mean in plain English? It means that the error can be exploited to trick users into supplying personal information to a malicious website, since the Safari address bar can display a totally different address than the website that is actually being displayed. MajorSecurity.net has notified Apple of the issue, so it's just a matter of time before a patch is available to fix the problem. In the meantime, it's a good idea to not open untrusted links and to think twice about sending personal information to any website that asks for it through Safari on your iOS device. For those who would like a working example of the vulnerability in action, MajorSecurity.net has created a web page at http://majorsecurity.net/html5/ios51-demo.html. Just open that page in Safari on a device iOS 5.1, click the demo button at the top of the page, and prepare to see something that looks amazingly like the www.apple.com site but is actually hosted by MajorSecurity.net. We'll let you know when the update to fix this issue is available. [via The Next Web]Security Alert: Safari for iOS 5.1 reportedly vulnerable to address bar spoofing originally appeared on TUAW - The Unofficial Apple Weblog on Thu, 22 Mar 2012 16:17:00 EST. Please see our terms for use of feeds.Source | Permalink | Email this | Comments read more..