Showing posts with label Java Vulnerability. Show all posts
Showing posts with label Java Vulnerability. Show all posts

Thursday, July 18, 2013

0

Critical JAVA Sandbox Bypass Vulnerability in Java 7 Update 25

  • Thursday, July 18, 2013
  • Nauman Ashraf
  • Security Explorations – A polish company has found a critical Java vulnerability that bypass Java sandbox. Vulnerable versions are Java 7 and its previous ones.


    What’s interesting about the attack is that it’s not new. Experts say the attack method has been known for over 10 years and it should have been mitigated with the Reflection API introduced in Java SE 7. It's one of those risks one should protect against in the first place when new features are added to Java at the core VM level. According to Softpedia.

    The vulnerability, dubbed “issue 69,” can be exploited via a “very classic attack” for a complete Java sandbox bypass.  According to Adam Gowdiak, the CEO of Security Explorations.

    The details and Proof of Concept of the vulnerability have been submitted to Oracle and Oracle fixed it in the June 2013 Java SE CPU, and POCs for nine IBM Java vulnerabilities addressed in early July 2013.

    Previously, Security Explorations found and submitted flaws to Oracle and IBM, which have been fixed now.

    Read More..

    Friday, January 18, 2013

    0

    Java Zero Day sells on Black market for $5000

  • Friday, January 18, 2013
  • Nauman Ashraf


  • It is recommended that users should disable the Java program in their Web browsers, because it remains vulnerable to attacks that could result in identity theft and other cyber crimes. Some browsers by default have disabled the JAVA Program. On Sunday, Oracle released a security update that addresses two critical zero-day vulnerabilities in Java that are being actively exploited by attackers, an online vulnerability seller began offering a brand-new Java bug for sale.

    According to a report, a Java exploits was being advertised for $5,000 a piece in an underground Internet forum and the new zero-day vulnerability was apparently already in at least one attacker's hands.

    The thread has since been deleted from the forum indicating a sale has been made, something sure to bring more concern to Oracle.Oracle can’t predict the future, and its engineers obviously can’t predict what exploits are going to be found in its software.

    The most recent hold Java fixed to allow hackers to enter a computer by using compromised websites as the entry-point into Java. Once in the system, they could steal any information, or hook up the computer to a botnet or a string of infected computers that can be used to launch attacks against other computers.

    The exploit is valuable because not only is it usable on the most up-to-date version of Java, which could remain vulnerable for weeks, if not months.
    Read More..

    Subscribe