Welcome to DU!
The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards.
Join the community:
Create a free account
Support DU (and get rid of ads!):
Become a Star Member
Latest Breaking News
Editorials & Other Articles
General Discussion
The DU Lounge
All Forums
Issue Forums
Culture Forums
Alliance Forums
Region Forums
Support Forums
Help & Search
Computer Help and Support
Showing Original Post only (View all)Turn off your Java plug-ins RIGHT FUGGIN NOW!!!!! [View all]
Critical Java zero-day bug is being massively exploited in the wildhttp://arstechnica.com/security/2013/01/critical-java-zero-day-bug-is-being-massively-exploited-in-the-wild/
Attack code that exploits vulnerability in Java's browser plugin has been added to the Blackhole, Cool, Nuclear Pack, and Redkit exploit kits, according to the Malware Don't Need Coffee blog, prompting its author to say that the bug is being "massively exploited in the wild." Miscreants use these products to turn compromised websites into platforms for silently installing keyloggers and other types of malicious software on the computers of unsuspecting visitors. KrebsOnSecurity reporter Brian Krebs said the curators of both Blackhole and Nuclear Pack have taken to the underweb to boast of the addition to their wares. It's not yet clear how many websites have been outfitted with the exploits.
snip
"There appears to be multiple ad networks redirecting to Blackhole sites, amplifying the mass exploitation problem," Kaspersky Lab expert Kurt Baumgartner wrote. "We have seen ads from legitimate sites, especially in the UK, Brazil, and Russia, redirecting to domains hosting the current Blackhole implementation delivering the Java 0day. These sites include weather sites, news sites, and of course, adult sites."
Java 7 Update 10 ships with a feature that makes it far simpler to unplug Java from the browser than in previous versions. Oracles instructions for using that feature are here: http://www.java.com/en/download/help/disable_browser.xml
Setting the Security Level of the Java Client: http://docs.oracle.com/javase/7/docs/technotes/guides/jweb/client-security.html
47 replies
= new reply since forum marked as read
Highlight:
NoneDon't highlight anything
5 newestHighlight 5 most recent replies
If you go into your addons/plugins it's should have an "update now" at the end the java
Lone_Star_Dem
Jan 2013
#4
As of this morning Mozilla has made Java "Click-to-Play" on a per site/ per visit basis...
Earth Bound Misfit
Jan 2013
#41
tnx.am on kindle fire hd. does it affect. there was java tab in laptop control panel didn't click.
UTUSN
Jan 2013
#29
O.K., here's more of my problem: I've got Java 6and the tech article said nothing earlier than Java7
UTUSN
Jan 2013
#32
The Security tab > Untick enable Java content is a new feature in Ver 7 update 10...
Earth Bound Misfit
Jan 2013
#38
tnx back pecking. is this a temporary situation. should I just governorate off ie laptop nt
UTUSN
Jan 2013
#42
Just UNinstalled my Java 6 (didn't see any JavaSCRIPT) & so far haven't seen any differences
UTUSN
Jan 2013
#46
JavaSCRIPT does not pertain to this vulnerability, the concern is Java APPLETS...
Earth Bound Misfit
Jan 2013
#47
This is a particular vulnerability, a "route to infection" rather than an infection.
Earth Bound Misfit
Jan 2013
#28