Jump to content

Serious security flaw in JAVA

jos
The latest version of Java, 1.8, has a major zero-day security flaw that hackers are actively using. In this case, the hackers are a group called Pawn Storm, and they're specifically targeting NATO members and an unnamed U.S. defense organization.
 
However, just because Pawn Storm is using this flaw for targeted attacks doesn't mean you won't get caught up in it. Once other hackers figure it out, they'll use it to target anyone they can.
 
Like most Java flaws, the attack relies on directing a victim to a malicious site. The site triggers Java in the browser and uses the security flaw to run hacker-created code that takes over the computer or forces it to download viruses.

 

 

 
JAVA had huge security flaws back in 2013. Then the developers cleaned up JAVA and it has been 2 years since an attack like this occured. Adobe flash dethroned JAVA for such attacks ever since..
 
Link to comment
Share on other sites

Link to post
Share on other sites

Nothing new here.

 

CPU - FX 8350 @ 4.5GHZ GPU - Radeon 5700  Mobo - M5A99FX Pro R2.0 RAM - Crucial Ballistix 16GB @ 1600 PSU - Corsair CX600M CPU Cooler - Hyper 212 EVO Storage - Samsung EVO 250GB, WD Blue 1TB

Link to comment
Share on other sites

Link to post
Share on other sites

I just remember everyone, just a few years ago, saying learning java was the way to go for career seekers, and that's where the jobs would be

 

 

 

 

and called me stupid when I said that wasn't gonna happen 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

One more reason everyone should just build in C++. It's easier to build security if everyone's just using one language anyway.

Software Engineer for Suncorp (Australia), Computer Tech Enthusiast, Miami University Graduate, Nerd

Link to comment
Share on other sites

Link to post
Share on other sites

I just remember everyone, just a few years ago, saying learning java was the way to go for career seekers, and that's where the jobs would be

 

 

 

 

and called me stupid when I said that wasn't gonna happen 

Oh it's still happening. With Hadoop batch jobs Java is still the way to go until Google allows C++ executables. The reason they don't is without transactional memory they fear someone could expose their OS and all the secret sauce hiding behind the obscurity provided by their custom JVM and Python Virtual Machine.

Software Engineer for Suncorp (Australia), Computer Tech Enthusiast, Miami University Graduate, Nerd

Link to comment
Share on other sites

Link to post
Share on other sites

Why do Java programmers need glasses?

Because they can't C#.

( ͡° ͜ʖ ͡°) 

As a programmer myself who hates .NET... BOOOOOOOOO! HISSSSSS!

Software Engineer for Suncorp (Australia), Computer Tech Enthusiast, Miami University Graduate, Nerd

Link to comment
Share on other sites

Link to post
Share on other sites

Hey, if you see a java popup, READ WHERE IT CAME FROM! DONT JUST FUCKING CLICK RUN. Done. Problem solved.

 

 

 The problem is this flaw java to run in background without asking....

Link to comment
Share on other sites

Link to post
Share on other sites

Oh it's still happening. With Hadoop batch jobs Java is still the way to go until Google allows C++ executables. The reason they don't is without transactional memory they fear someone could expose their OS and all the secret sauce hiding behind the obscurity provided by their custom JVM and Python Virtual Machine.

I guess. 

I just don't think people in the 2007-2009 and a little later area really though the web applet side of java would die off as much as it did. 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Hey, if you see a java popup, READ WHERE IT CAME FROM! DONT JUST FUCKING CLICK RUN. Done. Problem solved.

TEtXUDj.png

qaiWZxP.png

you can make it not do that...again 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Jeez I bet java feels like Canadians unlocked doors everywhere.

NEVER GIVE UP. NEVER STOP LEARNING. DONT LET THE PAST HURT YOU. YOU CAN DOOOOO IT

Link to comment
Share on other sites

Link to post
Share on other sites

Shocking ... 

... Life is a game and the checkpoints are your birthday , you will face challenges where you may not get rewarded afterwords but those are the challenges that help you improve yourself . Always live for tomorrow because you may never know when your game will be over ... I'm totally not going insane in anyway , shape or form ... I just have broken English and an open mind ... 

Link to comment
Share on other sites

Link to post
Share on other sites

And this is why I hate and will continue to hate Java. I wish more people could use actual languages and we wouldn't have to rely on horrible abominations like Java.

Link to comment
Share on other sites

Link to post
Share on other sites

Aaand what about 1.7?

Blue Jay

CPU: Intel Core i7 6700k (OC'd 4.4GHz) Cooler: CM Hyper 212 Evo Mobo: MSI Z170A Gaming Pro Carbon GPU: EVGA GTX 950 SSC RAM: Crucial Ballistix Sport 8GB (1x8GB) SSD: Samsung 850 EVO 250 GB HDD: Seagate Barracuda 1TB Case: NZXT S340 Black/Blue PSU: Corsair CX430M

 

Other Stuff

Monitor: Acer H236HL BID Mouse: Logitech G502 Proteus Spectrum Keyboard: I don't even know Mouse Pad: SteelSeries QcK Headset: Turtle Beach X12

 

GitHub

Link to comment
Share on other sites

Link to post
Share on other sites

I just remember everyone, just a few years ago, saying learning java was the way to go for career seekers, and that's where the jobs would be

 

 

and called me stupid when I said that wasn't gonna happen 

Well you were wrong and they were right. Java is the best in terms of actually getting you a job. Most used/requested rarely translates to actually being the best in terms of performance/security/cost though.

 

 

Oh it's still happening. With Hadoop batch jobs Java is still the way to go until Google allows C++ executables. The reason they don't is without transactional memory they fear someone could expose their OS and all the secret sauce hiding behind the obscurity provided by their custom JVM and Python Virtual Machine.

What secret sauce? AOSP is open source.

And what Python VM? As far as I know Android doesn't have a Python VM in it. It's all Java as far as the apps goes (even when you use the NDK you still need a Java program to call your C/C++ code).

Link to comment
Share on other sites

Link to post
Share on other sites

Well you were wrong and they were right. Java is the best in terms of actually getting you a job. Most used/requested rarely translates to actually being the best in terms of performance/security/cost though.

What secret sauce? AOSP is open source.

And what Python VM? As far as I know Android doesn't have a Python VM in it. It's all Java as far as the apps goes (even when you use the NDK you still need a Java program to call your C/C++ code).

Google's Cloud Computing is not remotely open source.

Software Engineer for Suncorp (Australia), Computer Tech Enthusiast, Miami University Graduate, Nerd

Link to comment
Share on other sites

Link to post
Share on other sites

Google's Cloud Computing is not remotely open source.

But what does that have to do with anything? I am not following you at all at the moment.

How would C/C++ on Android leak the "secret sauce" for whatever software Google runs on their servers?

Link to comment
Share on other sites

Link to post
Share on other sites

But what does that have to do with anything? I am not following you at all at the moment.

How would C/C++ on Android leak the "secret sauce" for whatever software Google runs on their servers?

I think you missed something critical. When I say knowing Java is still hugely useful for getting a job, I mean lots of the computing done by large businesses today involves map-reduce jobs of big data collections for later analysis. The most common platform for this is Google's Hadoop which doesn't allow C++ interface due to the fact it could expose the operating system in the right hands. That operating system and the libraries Google has built in are some of the major underpinnings for a lot of its infrastructure, basically its trade secrets.

Software Engineer for Suncorp (Australia), Computer Tech Enthusiast, Miami University Graduate, Nerd

Link to comment
Share on other sites

Link to post
Share on other sites

I think you missed something critical. When I say knowing Java is still hugely useful for getting a job, I mean lots of the computing done by large businesses today involves map-reduce jobs of big data collections for later analysis. The most common platform for this is Google's Hadoop which doesn't allow C++ interface due to the fact it could expose the operating system in the right hands. That operating system and the libraries Google has built in are some of the major underpinnings for a lot of its infrastructure, basically its trade secrets.

Oops sorry yeah I misunderstood you. For some reason I thought you were talking about Android.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×