• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

US-CERT Advises Enterprises to Disable Java

mixin

Well-known member
By: Dan Verton
08/29/2012 ( 8:59am)

The US-CERT warning came one day after researchers at FireEye Inc. in Milpitas, Calif., discovered an active exploit for the vulnerability in the wild. According to Atif Mushtaq, a malware researcher at FireEye, all versions of Java 7 are vulnerable to the new exploit, which is hosted on a domain that resolves to an Internet Protocol (IP) address based in China.
...
the attack is hosted on a malicious Website that installs a Java applet capable of escalating security privileges. Attackers can then use this access to execute arbitrary code on the vulnerable computer. The advisory states that there is currently no known ?practical solution to the problem?
...
?It's just a matter of time that a POC [proof of concept exploit] will be released and other bad guys will get hold of this exploit as well,? said Mushtaq in a blog posting. ?It will be interesting to see when Oracle plans for a patch, until then most of the Java users are at the mercy of this exploit.?
...

Read the full article here:
http://www.hstoday.us/industry-news...le-java/9bd1a1a78f95cf9fa3effde64bf2bb6d.html
 
Back
Top