New Java 0-Day Vulnerability Being Exploited in the Wild
thenextweb.com
New Java 0-Day Vulnerability Being Exploited in the Wild
1–10 of 80 posts
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#2"You know, one of these days, we're going to use that second digit.” — Stephen Colbert
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#3Maybe im in the minority but i never see java applets, and i think i browse ~ the avg. Of course i also disable all plugins until i click on something.
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#4I dont understand all the fus around these exploits. Are they exploits? Yes. Do people actually use java in the web? Not really. Maybe im in the minority but i never see java applets, and i think i browse ~ the avg. Of course i also disable all plugins until i click on something.
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#5I dont understand all the fus around these exploits. Are they exploits? Yes. Do people actually use java in the web? Not really. Maybe im in the minority but i never see java applets, and i think i browse ~ the avg. Of course i also disable all plugins until i click on something.
This is not the attack sequence:
* site has pre-existing Java
* site gets compromised somehow
* site now infects users
This is how it usually plays out: * site gets compromised somehow
* exploit includes a 0-day Java attack
* site now infects users
Literally 0 sites on the net could be hosting Java applets and that would make no difference; it's the number of active Java plugins that creates the potential for mass-infection. So long as you have the Java plugin enabled, you'll be exposed to this attack.Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#6I dont understand all the fus around these exploits. Are they exploits? Yes. Do people actually use java in the web? Not really. Maybe im in the minority but i never see java applets, and i think i browse ~ the avg. Of course i also disable all plugins until i click on something.
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#7Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#8I dont understand all the fus around these exploits. Are they exploits? Yes. Do people actually use java in the web? Not really. Maybe im in the minority but i never see java applets, and i think i browse ~ the avg. Of course i also disable all plugins until i click on something.
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#9I dont understand all the fus around these exploits. Are they exploits? Yes. Do people actually use java in the web? Not really. Maybe im in the minority but i never see java applets, and i think i browse ~ the avg. Of course i also disable all plugins until i click on something.
It makes no difference how prevalent they are in common web apps, the problem is that the Java plugin is still installed and active for a large number of users. This is not the attack sequence: * site has pre-existing Java * site gets compromised somehow * site now infects users This is how it usually plays out: * site gets compromised somehow * exploit includes a 0-day Java attack * site now infects users Literally…
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#10I dont understand all the fus around these exploits. Are they exploits? Yes. Do people actually use java in the web? Not really. Maybe im in the minority but i never see java applets, and i think i browse ~ the avg. Of course i also disable all plugins until i click on something.
It makes no difference how prevalent they are in common web apps, the problem is that the Java plugin is still installed and active for a large number of users. This is not the attack sequence: * site has pre-existing Java * site gets compromised somehow * site now infects users This is how it usually plays out: * site gets compromised somehow * exploit includes a 0-day Java attack * site now infects users Literally…
It's incredible how far and fast client side Java has fallen because of Oracle's tepid response to security concerns. I've developed many internal apps for client-side Java and supported them for over a decade. I don't think I'll develop another.