blufive: (Default)
[personal profile] blufive
I've had a fun time in the last 24 hours with a piece of malware that managed to install itself via Firefox and a Java applet. Breezed straight in, installed a nasty IE toolbar and hijacked IE.

Having poked and prodded extensively, the security hole was in Java, and was fixed between Java 1.4.1_01 (which I was using yesterday) and Java 1.4.2_05 (which I'm using now).

Moral: If you have Java enabled in Mozilla/Firefox on Windows, update to the latest Java Runtime right now unless you like the idea of websites being able to execute arbitrary code on your machine.

Date: 2004-08-30 03:58 (UTC)
From: [identity profile] stsquad.livejournal.com
Was it a hole just on Windows Java? Who's Java Runtime (Sun, IBM, Microsoft, other)?

Date: 2004-08-30 04:33 (UTC)
From: [identity profile] blufive.livejournal.com
The Sun JRE.

Having pinned it down and dissected it thoroughly, the security hole may well exist in non-windows versions of Java, but this particular exploit was windows-specific, and would likely just fail miserably on non-Win32 systems.

Profile

blufive: (Default)
blufive

April 2024

S M T W T F S
 123456
78910111213
14151617181920
21222324252627
282930    

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated 2026-03-24 03:54
Powered by Dreamwidth Studios