Have you disabled your Java?

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

PeeluckyDuckee

Diamond Member
Feb 21, 2001
4,464
0
0
My dlink web cam uses java and neither of the app under windows/osx work at the moment. My only access right now is through android app on my GNexus.

Safari runs like crap right now, not sure if it's related to Java at all, but I've never experienced such slow down prior to this week.
 
Last edited:

Cerb

Elite Member
Aug 26, 2000
17,484
33
86
Disabled in all browsers on all PCs, except Chrome variants (click to play, which, IMO, should be the default, for security reasons). The Java plugin serves no better purpose than as an attack vector.
 

clamum

Lifer
Feb 13, 2003
26,252
403
126
Already was disabled in Firefox (looks like I have version 6 there anyway). That's good, cause the Security tab in the Java Control Panel only has a "Certificates" button, lulz.
 

Wyndru

Diamond Member
Apr 9, 2009
7,318
4
76
So for this to actually be a risk, you have to have version 7 of Java installed and hit a website that has malicious code in it that will trigger java (not javascript), created by someone that has already started abusing this exploit discovered by a security firm on Friday?

Is this firm handing out the code to hackers or something?

Oh, nevermind, I read the metaslpoit post. I love how when this stuff hits the news, the exploit immediately becomes widely available, with screenshots and instructions on how to use it.
 
Last edited:

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
So for this to actually be a risk, you have to have version 7 of Java installed and hit a website that has malicious code in it that will trigger java (not javascript), created by someone that has already started abusing this exploit discovered by a security firm on Friday?

Is this firm handing out the code to hackers or something?

Oh, nevermind, I read the metaslpoit post. I love how when this stuff hits the news, the exploit immediately becomes widely available, with screenshots and instructions on how to use it.

Kaspersky Lab said it's been in the wild since mid-December: http://www.securelist.com/en/blog/208194070/Java_0day_Mass_Exploit_Distribution

There appears to be multiple ad networks redirecting to Blackhole sites, amplifying the mass exploitation problem. We have seen ads from legitimate sites, especially in the UK, Brazil, and Russia, redirecting to domains hosting the current Blackhole implementation delivering the Java 0day. These sites include weather sites, news sites, and of course, adult sites.

According to Immunity, version 6r10 and later are also affected, not just JRE 7: https://partners.immunityinc.com/idocs/Java MBeanInstantiator.findClass 0day Analysis.pdf (PDF).

My dlink web cam uses java

Thanks for mentioning this, I will make sure nevar to buy a D-Link webcam without first making sure it's free of the Java prerequisite.
 

John Connor

Lifer
Nov 30, 2012
22,757
617
121
I have an add-on for Firefox called Quickjava and it allows me to disable Java when I'm not using it. I never keep it on unless I need it and that need is only for pingtest.net. I also use Noscript which not only will block Javascript, but Java unless I approve of it.
 

WT

Diamond Member
Sep 21, 2000
4,816
59
91
We spent a lot of time at work this week fixing a broken Java 7.10 deployment on teacher's laptops - its what runs the gradebook app. As of Friday it worked, and then I get home only to read that Java is now disabled within the supported browser.

Monday will be no fun at all I am sure ... this could get messy.
 

Svnla

Lifer
Nov 10, 2003
17,986
1,388
126
Thanks to lxs and mech (especially the link to check if the programs are up to date or not). <thumb up>
 

GrumpyMan

Diamond Member
May 14, 2001
5,780
264
136
Haven't read the rest of this thread but I have not disabled my java, I like it with 2 sugars and 1 cream. I couldn't do without it in the morning.
 

FelixDeCat

Lifer
Aug 4, 2000
29,614
2,263
126
Scottrade requires JAVA for steaming quotes so its enabled for IE. All other sites are browsed with FF.

To be safe, its uninstalled for now until the update is available on Tuesday. I oversee several dollars and need access to Java so I can manipulate governments and people to serve my Machiavellian interests.

()
 

disappoint

Lifer
Dec 7, 2009
10,132
382
126
Scottrade requires JAVA for steaming quotes so its enabled for IE. All other sites are browsed with FF.

To be safe, its uninstalled for now until the update is available on Tuesday. I oversee several dollars and need access to Java so I can manipulate governments and people to serve my Machiavellian interests.

()

 

biostud

Lifer
Feb 27, 2003
18,670
5,397
136
I have an add-on for Firefox called Quickjava and it allows me to disable Java when I'm not using it. I never keep it on unless I need it and that need is only for pingtest.net. I also use Noscript which not only will block Javascript, but Java unless I approve of it.

Thanks for QuickJava
 

Dumac

Diamond Member
Dec 31, 2005
9,391
1
0
Disabled it in browser, yeah.

See no need to remove it from my computer, though.
 

paulney

Diamond Member
Sep 24, 2003
6,909
1
0
Can't run GoToMeeting without Java, and that's what I use daily, so kept it enabled.
 

hclarkjr

Lifer
Oct 9, 1999
11,375
0
0
http://news.softpedia.com/news/Java...-for-5-000-on-Underground-Market-321702.shtml

Less than a week has passed since Oracle patched the vulnerability in Java 7 Update 10 and another zero-day exploit &#8211; which is said to work on Java 7 Update 11 &#8211; is already being sold on the cybercriminal underground market.

Brian Krebs, who came across an ad for the exploit on a hacker forum on Monday, reveals that the author had offered to sell it to two people for the price of $5,000 (3,750 EUR). The buyers were promised an &#8220;encrypted&#8221; and &#8220;weaponized&#8221; version of the exploit.

In the ad he posted, the seller claimed that the exploit was not integrated into any known crime kits, not even in the expensive Cool Exploit Kit.

According to Krebs, the cybercriminal most likely found buyers since the post was removed from the forum.

This shows that the US Department of Homeland Security is right to advise users to uninstall Java if they don&#8217;t need it for their everyday tasks.

In its advisory, the DHS has warned that Oracle might have addressed one issue, but some old vulnerabilities are still unfixed and security holes are identified in Java all the time.
 

John Connor

Lifer
Nov 30, 2012
22,757
617
121
That looks goooood. I want some! My damn espresso machine quit working for me the other day too. Off to eBay to find a replacement.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |