PPRuNe Forums - View Single Post - Java infection
Thread: Java infection
View Single Post
Old 5th September 2012 | 10:30
  #1 (permalink)  
Milo Minderbinder
 
Joined: Jan 2012
Posts: 2,173
Likes: 0
From: .
Java infection

Just a heads up to say that I've come across several examples on forums recently of adverts being posioned by trojans using the recently found Java exploits. It looks like they've become very common in the last week - an explanation of the background is here
Oracle rushes out patch for critical 0-day Java exploit ? The Register

Most of the ones I've seen have been incorporated into infections created using the Blackhole build-your-own-virus kit.

You can block the exploit by downloading and installing the latest version of the Java VM from java.com: Java + You
The version you need is "Java Runtime Environment 7 Update 7" (or later)
If you already have that installed then thats OK. If you have any other version, uninstall it (if you have multiple versions remove them all) and then install the new version.
Some machines will auto-update, but a lot won't.

This is a real risk and I've seen it on a number of forum sites. I've told the admins on each one but theres not a lot that can be done - users need to make sure their machines are secure.

If you want to see an example of the havoc this vulnerability can create, read Thanks ever so much Java, for that biz-wide rootkit infection ? The Register


Among other things, this exploit is also being used in another industrial espionage attack aimed at Defence Contractors
Chemical biz 'Nitro' hackers use Java to coat PCs in poison ivy ? The Register

Last edited by Milo Minderbinder; 5th September 2012 at 10:43.
Milo Minderbinder is offline  
Reply