Disable Java: Your Computer Is Under Threat

By Shailesh Shrivastava email: s.shrivastava@mobilenapps.com | Jan 12, 2013 05:28 AM EST

Share This Story

  • Print
  • Email

Java is once again under security threat because of a recent zero-day exploit, and people out there, including the Department of Homeland Security are shouting "Disable Java."

According to an advisory issued by the Department of Homeland Security, "a vulnerability in Java's Security Manager allows a Java applet to grant itself permission to execute arbitrary code. An attacker could use social engineering techniques to entice a user to visit a link to a website hosting a malicious Java applet. An attacker could also compromise a legitimate web site and upload a malicious Java applet (a 'drive-by download' attack)."

Follow us

Any system using Oracle Java 7 (1.7, 1.7.0) including, Java Platform Standard Edition 7, Java SE Development Kit, Java SE Runtime Environment have become vulnerable because of the bug.

Any Web browser using the Java 7 plug-in is affected. The Java Deployment Toolkit plug-in and Java Web Start can also be used as attack vectors. Reports indicate this vulnerability is being actively exploited, and exploit code is publicly available, the department added in the advisory.

Talking about the zero-day exploit Kurt Baumgartner, a Kaspersky Lab expert posted on his blog: "There appears to be multiple ad networks redirecting to Blackhole sites, amplifying the mass exploitation problem. We have seen ads from legitimate sites, especially in the UK, Brazil, and Russia, redirecting to domains hosting the current Blackhole implementation delivering the Java 0day. These sites include weather sites, news sites, and of course, adult sites."

Baumgartner also listed down some of the files being directed to vulnerable systems.

Stretch.jar, Edit.jar, UTTER-OFFEND.JAR are among so many files which are being delivered to victim systems by the hackers.

According to a report from Mercury News, Oracle will release a fix on Jan 15 which will contain 86 new security vulnerability fixes. Oracle, which manages Java software, also asked the users of Java to update the software as soon as the fix is released.

For now, as a precautionary measure, the Department of Homeland Security and other experts have recommended users to disable Java from their Web browsers.

In case you are finding it difficult to disable Java from your browser you can refer to this guide.

Apple has already, in a swift move, disabled the Java 7 plug-in on its computers.

 Apple has achieved this by updating its "Xprotect.plist" blacklist to require a minimum of an as-yet unreleased 1.7.0_10-b19 version of Java 7. With the current publicly-available version of Java 7 being 1.7.0_10-b18, all systems running Java 7 are failing to pass the check initiated through the anti-malware system built into OS X, Mac Rumors reported.

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
Nokia Lumia 928Verizon Exclusive Nokia Lumia 928 Now $49.99 At Online Retailers
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Leaked
Samsung Galaxy S4 App Contest Boasts $800,000 Total Prizes For Talented Devs
Photo Taken With Samsung Galaxy Note 3 'Leaked' Online
Tablet / Laptop / PC
Samsung Galaxy Tab 3 8.0 Leaked ImageSamsung Galaxy Tab 3 8-Inch Specs, Photo Leak Online
Asus 1015E Ubuntu Notebook To Launch Soon With $215 Price Tag
New MacBook Air To Debut In June With Intel's New Haswell Processor?
Nexus 7 Refresh Teased In Google+ Hangouts Video, Sports Glowing Notification Light
Gadgets
Ouya Android-Powered $99 Game ConsoleOuya Will Be At E3 2013, But Not Where You Think
Next Microsoft Xbox To Sport Dashboard UI Update And Tile Changes
Google Media Streamer Hits FCC To Replace Nexus Q
Google Glass Raises Lawmakers' Concerns: Congress Demands Answers About Privacy
OS / Software
Galaxy S3 Mini Jelly Bean UpdateAndroid 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Leaked
Samsung Galaxy S4 Mega Confirmed By Samsung In WatchOn Change Log?
Android 4.2.2 Jelly Bean Coming Soon For HTC One; Google Edition of HTC One On The Way
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
Internet / Social Media
The Demonstrator Set Up Between Two Skyscrapers In Karlsruhe, West Germany Download 40 GB In A Second: Researchers Set Up World's Fastest Wi-Fi Network In Germany
YouTube Shoppable Videos - Will Google Hit A New Jackpot?
Apple iRadio Reportedly Delayed Over Song Skipping Issue
Yahoo Is Eyeing Tumblr
What's App
Galaxy S4 White FrostSamsung Galaxy S4 App Contest Boasts $800,000 Total Prizes For Talented Devs
Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Itsdagram Available Now For Windows Phone: Best Instagram Client Around

DON'T MISS

A photo allegedly taken with the Samsung Galaxy Note 3
Photo Taken With Samsung Galaxy Note 3 'Leaked' Online
The photo is posted by SamMobile and the screenshot of the EXIF data of the image shows that the
Nokia Lumia 928
Verizon Exclusive Nokia Lumia 928 Now $49.99 At Online Retailers
Want a Lumia 928 on Verizon Wireless? Pick it up from RadioShack or Wirefly for $49.99.
Asus 1015E Notebook
Asus 1015E Ubuntu Notebook To Launch Soon With $215 Price Tag
Asus is offering an alternative to the Windows 8 1015E notebook model: an 1015E-DS03 notebook
YouTube App
YouTube Shoppable Videos - Will Google Hit A New Jackpot?
YouTube is no longer a simple video-sharing site, it now offers consumers the chance to shop
Galaxy S3 Mini Jelly Bean Update
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Leaked
The new firmware comes with some Galaxy S4 features but it is not known whether the camera features
Samsung Galaxy Tab 3 8.0 Leaked Image
Samsung Galaxy Tab 3 8-Inch Specs, Photo Leak Online
Samsung recently announced the Galaxy Tab 3 7.0, but a new report with leaked specs and photo now

Ouya Android-Powered $99 Game Console
Ouya Will Be At E3 2013, But Not Where You Think
The Ouya team might not be on the E3 2013 show floors, but you can still give the console a test
Galaxy S3 Sapphire Black
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
The update comes with some features like Group CastApp and Page Buddy.
MacBook Air
New MacBook Air To Debut In June With Intel's New Haswell Processor?
Apple is expected to update its hardware lineup as soon as June with a new MacBook Air likely
Google Nexus 4 White Version
White Nexus 4 To Launch On June 10 Rocking Latest Android 4.3
The white Nexus 4 that created a lot of buzz among rumor mills recently, finally has a launch date:
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics