New Java 0-day exploit spotted in the wild.
blog.fireeye.com
blog.fireeye.com
For Chrome, go to advanced settings -> Privacy -> Content settings -> Plug-ins and select "click to play". For Firefox, go to about:config and enable "plugins.click_to_play".
I just want to point out that's there's a big difference between having an interpreter on your machine like python, ruby, or java, and having a browser plugin that executes remote code by default.
There's nothing wrong with the former, there's everything wrong with the latter.
(Yes, non-executable data can still deliver a malicious payload, e.g. http://technet.microsoft.com/en-us/security/bulletin/ms04-02.... It's just much less common-- presumably because it's a much smaller attack surface.)
But mostly it is buffer overflow bugs that get you now.
I keep Java around for some other reasons, so when I update, I have to remember to go and disable the browser plugins once again.
I had to go back to enabling plug-ins with Chrome, though, as I couldn't load videos for some reason.
Also on OS X the Flash mouse capture is broken if you enable click to play in Firefox.
Your point is correct, though. There are a lot of sites that break if they don't detect Flash right at page load.
http://www.fireeye.com/news-events/press-releases/read/firee...
Email me at the email in my profile if you would like a warm intro.
Disclaimer: my brother is a long-time engineer.
I code in Java for work and so it's on those boxes, but I have never found a need for it at home. I've only rarely come across a website that requires it.
(The only exception is ADOM2, but that doesn't require a browser plugin, you just download it like any other executable [that you trust])
Does anyone here write consumer-focused non-server Java software?
I've been looking at WebGL, but the technology isn't really ready for a mass market yet, and is widely criticized for the security holes it potentially introduces by exposing the OpenGL API to the DOM.
The whole web community seems to be ignoring rich content rendered on the client side. Without these capabilities, we'll never have real web app versions of programs like Photoshop.
Right now, my focus is on getting Kickstarter funding and developing a more user friendly version of my app for iOS, where such facilities are available today.
Mars Space Simulator
I've been writing Java for a desktop accounting app [1] for the last 8 years and it is fast, cross-platform, and indistinguishable from native applications.
The trick is to use SWT for the UI rather than the built-in Swing UI. SWT is lightweight, has a simple API and provides an excellent user experience. Swing is bloated, has a frustratingly-complicated API and for the most part provides a woeful user experience.
I really believe that if Sun had chosen to base their UI framework on something like SWT then today Java would dominate the desktop as much as it dominates server development. If you're curious, here's a juicy story about how the politics between Sun and IBM caused them to make such a bad choice: http://www.mail-archive.com/jug-discussion@tucson-jug.org/ms...
It's sad too, because I'd still much prefer to push Java for certain classes of solutions, and still - to this day - find audio/video support (among other things) lagging.
I guess, once Java took off as a server side platform, Sun just didn't have the vision or courage to seriously push Java on the desktop. Sad. :-(
So somehow the small gang at Mojang pulled off the impossible with Minecraft? Or the excellent apps NASA used to make with Java before the past 3 years or so like WorldWind? Or FusionCharts? or IBM Symphony, or OpenOffice, or SameTime, or HP Virtual Rooms (the last few heavy, heavy media), Apache Directory Studio, Eclipse, NetBeans, soapUI, SQL Developer?
Looking through their forums, this is relatively common.
I said "lagging", not non-existent. And clearly individuals can add support for things that aren't part of the JDK, using various OSS libraries, JNI, custom code, whatever. The point is, the lack of up-to-date, high-quality support for audio and video formats is a major detriment to "java on the desktop" for a wide range of applications.
Apache Directory Studio, Eclipse, NetBeans, soapUI, SQL Developer?
What do any of these things have to do with needing audio/video support?
Of course, where I work we're replacing pretty nice swing apps with far-less-nice web stuff. Why? Because the CTO read some trade mag that said nobody is doing fat clients anymore. Glad to see he's earning his salary. Sigh.
Vuze (former Azureus) has quite large base install. There alose should be quite a lot of Swing in-house apps.
A lot of government service interaction is being forced online, to reduce spending. So you are forced to at least have one Java capable browser available.
I run Java on Linux and my setup is simple: I install Java in my "dev" account from the .tar.gz. There's no way I'll ever ever login as "root" to install Java on a Linux machine and there's no way Java ever gets installed in something else than my "dev" user account. I surf the net from another account which, of course, has no Java installed.
I also admin two Java webapp servers and closely follow all the security issues: had to patch them twice "recently". First the DoS SNAFU related to predictable hashmap hashes where anyone could remotely DoS any Java webapp server (quite bad) and then the "infinite looping" when parsing I don't remember which HTTP header triggering a bug in floating-point code. Both bugs where known since more than ten years and Sun/Oracle never acted.
It's really a quite sad state of affair.
That said, there is a jenkins box running at $dayjob that of course requires Java. However, if I had a choice between jenkins and jenkins-clone-built-with-something-else, all things being equal I would choose jenkins-clone-built-with-something-else.
What on earth for? It's not as if the Java binaries on a (non-multi-user) server somehow make it less secure.
I can't wait for the day when people get their wish, and 50% of the installed browser base will run random python scripts off the web.
The one that has me worried way more is all of the Android build tools. I've had random crashes happen in them and there is no good way to debug the issue. Java throws stack traces that if printed would cost you a ream or two of paper and sometimes you get crashes in something completely unrelated.
Ugh, there are many things I wish for, but Java no longer existing is probably one of my biggest wishes.
Or is it the android SDK throwing slightly less but still uselss stack traces?
I often see the later, which is just poor error/exception handling by the developers. I very rarely (sometimes, but not enough to get annoyed) see the JVM printing out stack traces.
This is CS 101, GiGo
Sometimes, all you have is a stack trace.
It really isn't that hard to understand.
In a week this exploit will be an "old 0-day exploit" because the "0-day" bit describes developer preparedness at discovery, not how long the exploit has been known.
https://community.rapid7.com/community/metasploit/blog/2012/...
Errata Sec claims it's working on a fully-patched Ubuntu 12.04, provided you're using the official Java package instead of the default OpenJRE. OSX 10.8.1 has also been confirmed.