New Zero Day Java Vulnerability Being Exploited in the Wild
thenextweb.com
thenextweb.com
<shameless plug> For those interested, a recent blog post of mine analyzes a similar attack that uses CVE-2008-5353: http://jsaxton.com/fun-with-wireshark-and-ie-java-exploits-p... </shameless plug>
jsaxton86's comment sets the scene nicely so I'll just copy it here:
"This family of JRE attacks is far too common. Basically, when an unsigned applet runs, the JRE tries really hard to prevent it from creating a ClassLoader object. However, if you manage to create a ClassLoader object, it's game over -- you can break out of the sandbox and do whatever you please."
The exploit is very clever, it never actually creates an instance of the ClassLoader object, but rather it uses Java reflection to call a particular method on a ClassLoader object, which was tricked into creation inside a separate exploit involving the JMX (Java Management Extensions) framework.
JMX has its own methods to instantiate classes, and a subclass of ClassLoader ("sun.org.mozilla.javascript.internal.GeneratedClassLoader") is passed in as a String; then the method defineClass is called via reflection in a way that deceives all the ClassLoader protection. Once this method is allowed to be invoked via reflection, it's "game over" as explained at the start.
http://pastebin.com/raw.php?i=cUG2ayjh http://www.oracle.com/technetwork/java/javase/tech/javamanag... http://www.cs.rit.edu/usr/local/pub/swm/jdoc6/com/sun/jmx/mb...
http://pastebin.com/raw.php?i=cUG2ayjh
This is a result of two vulnerabilities one of which Oracle tried to fix in the last patch release with CVE-2012-5088.
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/...
My HP JetDirect print server also uses a small mass of applets to perform advanced functions like setting an IP or finding out if the printer is online.
Uninstall it, completely, and the next time this article is posted (with the dates changed and little else), you'll be glad it has nothing to do with you.
If you actually do novel things with your computer from time to time, you are likely to run into Java sooner or later. If you run the same three programs all the time, sure, ruthlessly uninstall everything else.
Even on a desktop where I am not currently using any Java apps, I see no reason to go out of my way to uninstall it if it's already there. It isn't hurting me, and installing it is enough of a pain that avoiding that hassle is a win.
Fuck you, danish goverment.
Friend of mine told me about that, my first thought was the situation with Internet Explorer in South Korea...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-468...
"bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields"
Java in the browser (applets, web start) runs in a plugin which is supposed to have a strong sandbox to prevent applications from doing things like touching files or controlling your window manager without your permission.
On the server (or invoked from the commandline/jar), the security policy is much looser and there's no sandboxing (outside of what the OS and interpreter prevent).
Stat Owl reports that the Java plugin is installed on 68% of browsers[0] based on data from 28 million monthly uniques[1].
0: http://www.statowl.com/java.php 1: http://www.statowl.com/about_our_data.php
People are working for companies that use Java, and these employees cannot disable Java in their browser because it's required for their job. I happen to work at one of these shops, and I can confirm to you 12,000 people in the US from just my company alone who must have Java in their browser and running constantly. We're not alone in this regard. We're all vulnerable, and the suggestion to disable the plugin doesn't help much.
The reason you normally see fixes deployed when you hear about the bug is because of "responsible disclosure" - details are held until a fix is ready. Those suggesting that oracle won't fix this outside of their normal quarterly patch cycle are off the mark though, surely there will be a (relatively) quick response from them (within a week or two would be my bet).
But by the time I heard about it, Oracle could have 100 developers busy on this one issue.
Thankfully this one is only concerning Java applets.
Java applets where probably the stupidest thing ever. They surely did sck and did bring terribly bad reputation to Java : (
Don't know who's still using them.
Can Google Chrome even be made to run Java applets?
I know latest OS X don't even ship* with Java anymore...
The likes of Google and Mozilla might want us all to drop these tried and tested technologies and move to shiny new ones like HTML5 and the latest JS and CSS developments, but realistically, it takes time for users to move on. Most of us don’t have the luxury of controlling our customers’ platforms so we can ensure they run up-to-date builds of Firefox or Chrome with all the latest toys.
It takes time for developers to move on, too. I’m currently working on a project that uses a Java applet for a client. If I were starting the same project today, I’d probably chose different tools, but it wasn’t started today, and not so many years ago when the architectural decisions were being made, those new tools didn’t exist yet.
The main thing holding Java applets back today seems to be the second rate support they now get from the major browsers and/or Oracle, assuming they are supported at all. The number of blatant, show-stopping bugs in browser/Java interactions is getting silly, and code that has worked for years is breaking because someone installed a software “upgrade”. That’s a pity, IMHO, because the JVM is still a decent platform, and there are several interesting modern programming languages other than Java itself that we could be using to develop web apps otherwise.
Can you show me any examples of what I might be missing out on?
Besides downloading the Java app, you can play Minecraft in the browser through an applet at https://minecraft.net/play.
So no, if you are not running Java in the browser, a malicious web page can't run neither Minecraft nor other Java apps that you have locally installed.
There is no direct input to the printer as a byte buffer, the browser will always print a markup document. Unless HTML5 comes up with Printer Sockets, we are stuck with Applets in order to be granted hardware access to the client machine.
To interact with the danish government online (say because you want to update your tax records) you have to login -- with a java applet.
That also means you can't do it from your phone.
Yeah, Java is still used in plenty of places, and yes Chrome still support it.
One thing about applets is they are the only way I know of to generate UDP packets from the browser. If it wasn't for that I couldnt think of anything.
At least one online banking site of a large Scandinavian bank...
Flash and Unity, etc have taken over, but who's to say that they are more secure?
http://howto.cnet.com/8301-11310_39-57536917-285/enable-clic...