Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Computer Help and Support

Showing Original Post only (View all)

Earth Bound Misfit

(3,585 posts)
Fri Jan 11, 2013, 05:09 PM Jan 2013

Turn off your Java plug-ins RIGHT FUGGIN NOW!!!!! [View all]

Critical Java zero-day bug is being “massively exploited in the wild”
http://arstechnica.com/security/2013/01/critical-java-zero-day-bug-is-being-massively-exploited-in-the-wild/

Attack code that exploits vulnerability in Java's browser plugin has been added to the Blackhole, Cool, Nuclear Pack, and Redkit exploit kits, according to the Malware Don't Need Coffee blog, prompting its author to say that the bug is being "massively exploited in the wild." Miscreants use these products to turn compromised websites into platforms for silently installing keyloggers and other types of malicious software on the computers of unsuspecting visitors. KrebsOnSecurity reporter Brian Krebs said the curators of both Blackhole and Nuclear Pack have taken to the underweb to boast of the addition to their wares. It's not yet clear how many websites have been outfitted with the exploits.

snip

"There appears to be multiple ad networks redirecting to Blackhole sites, amplifying the mass exploitation problem," Kaspersky Lab expert Kurt Baumgartner wrote. "We have seen ads from legitimate sites, especially in the UK, Brazil, and Russia, redirecting to domains hosting the current Blackhole implementation delivering the Java 0day. These sites include weather sites, news sites, and of course, adult sites."


Java 7 Update 10 ships with a feature that makes it far simpler to unplug Java from the browser than in previous versions. Oracle’s instructions for using that feature are here: http://www.java.com/en/download/help/disable_browser.xml

Setting the Security Level of the Java Client: http://docs.oracle.com/javase/7/docs/technotes/guides/jweb/client-security.html
47 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
K&R!!!!!!!!!!! CountAllVotes Jan 2013 #1
Is it good enough to disable ohheckyeah Jan 2013 #2
If you go into your addons/plugins it's should have an "update now" at the end the java Lone_Star_Dem Jan 2013 #4
Thanks - ohheckyeah Jan 2013 #5
As of this morning Mozilla has made Java "Click-to-Play" on a per site/ per visit basis... Earth Bound Misfit Jan 2013 #41
I am now running SuperAntispyware ... will this help? CountAllVotes Jan 2013 #3
My ThinkPad is screwed CountAllVotes Jan 2013 #6
This message was self-deleted by its author CountAllVotes Jan 2013 #8
Have a friend that ohheckyeah Jan 2013 #7
fix hint CountAllVotes Jan 2013 #9
My Acrobat just updated, I hadn't read any of this. polly7 Jan 2013 #10
I gave up on that computer CountAllVotes Jan 2013 #11
damn. polly7 Jan 2013 #13
if you do system restore it will be gone CountAllVotes Jan 2013 #14
that was a rumor! CountAllVotes Jan 2013 #24
Thanks .. polly7 Jan 2013 #25
Better stay off those porn sites, folks! WhoIsNumberNone Jan 2013 #12
you could be next CountAllVotes Jan 2013 #15
Funny you should say that WhoIsNumberNone Jan 2013 #16
I came home and turned on my computer CountAllVotes Jan 2013 #18
I've been pretty slack when it comes to updating Java WhoIsNumberNone Jan 2013 #19
Fascinating technical analysis... Earth Bound Misfit Jan 2013 #17
'tis a nightmare CountAllVotes Jan 2013 #20
Have you tried restoring your computer to factory settings? UnrepentantLiberal Jan 2013 #31
All I can do is system restore CountAllVotes Jan 2013 #33
What kind of computer do you have? UnrepentantLiberal Jan 2013 #39
IBM ThinkPad; desktop is an ACER CountAllVotes Jan 2013 #40
You mean you're using a Vista operating system UnrepentantLiberal Jan 2013 #44
I know! CountAllVotes Jan 2013 #45
Thanks for the information. nick of time Jan 2013 #21
R#5 & K. For me/LowTech, please spell everything out UTUSN Jan 2013 #22
Do the following: CountAllVotes Jan 2013 #27
tnx.am on kindle fire hd. does it affect. there was java tab in laptop control panel didn't click. UTUSN Jan 2013 #29
O.K., here's more of my problem: I've got Java 6and the tech article said nothing earlier than Java7 UTUSN Jan 2013 #32
yes I saw that CountAllVotes Jan 2013 #36
Don't go messing w/the registry CountAllVotes Jan 2013 #34
Amazon kindle fire hd 8.9 UTUSN Jan 2013 #37
The Security tab > Untick enable Java content is a new feature in Ver 7 update 10... Earth Bound Misfit Jan 2013 #38
tnx back pecking. is this a temporary situation. should I just governorate off ie laptop nt UTUSN Jan 2013 #42
that is what I am doing CountAllVotes Jan 2013 #43
Just UNinstalled my Java 6 (didn't see any JavaSCRIPT) & so far haven't seen any differences UTUSN Jan 2013 #46
JavaSCRIPT does not pertain to this vulnerability, the concern is Java APPLETS... Earth Bound Misfit Jan 2013 #47
This is a particular vulnerability, a "route to infection" rather than an infection. Earth Bound Misfit Jan 2013 #28
I believe I know where it came from CountAllVotes Jan 2013 #35
Thanks for posting this, malwarebytes has detailed instructions and a way to remove the malware Sunlei Jan 2013 #23
thanks! CountAllVotes Jan 2013 #26
Do I need to disable Java and Flash on my Android phone? UnrepentantLiberal Jan 2013 #30
Latest Discussions»Help & Search»Computer Help and Support»Turn off your Java plug-i...»Reply #0