Attacks/Breaches
8/30/2012
11:07 AM
Connect Directly
RSS
E-Mail
50%
50%

Java Zero-Day Malware Attack: 6 Facts

New details reveal Oracle knew about the Java exploit in April, but has yet to release a patch. Here's how to protect yourself against active attacks.

Businesses are growing worried about drive-by infections by malware that exploits two zero-day Java vulnerabilities.

Attackers, apparently operating from China, chained the two vulnerabilities together to defeat Java 7 security settings, allowing them to execute arbitrary code on targeted PCs. But the exploit code has since been added to attack toolkits and used in new, targeted attacks.

Here are six facts that businesses need to know about the vulnerabilities being exploited, as well as how to protect their users:

1. Warning: Uninstall Java, Or Maybe Disable

Security experts have recommended that users disable all Java browser plug-ins, pending a patch from Oracle.

US-CERT has offered detailed instructions about how to disable Java in Chrome, Firefox, and Internet Explorer browsers. But it warned that where IE is concerned, nuking the Java plug-in isn't a straightforward manner, as "there are multiple ways for a Web page to invoke a Java applet, and multiple ways to configure Java plug-in support."

[ Windows 7 and 8 password clues are vulnerable to attack. See Windows Password Clues Easy To Crack. ]

In fact, at least for IE users, US-CERT suggested that the difficulties involved in disabling Java might require stronger measures. "Due to the complexity and impracticality of disabling Java in Internet Explorer, you may wish to uninstall Java to protect against this vulnerability."

2. Oracle Learned Of Vulnerabilities Four Months Ago

Is Oracle patching critical vulnerabilities in Java quickly enough? Sunday, FireEye went public with details of a never-before-seen attack. In response, some security researchers this week criticized the company for behaving irresponsibly by not having worked with Oracle to patch the flaws before disclosing them publicly.

But IDG News reported Wednesday that Polish vulnerability research company Security Explorations disclosed the two exploited vulnerabilities to Oracle--including detailed proof-of-exploit attack code--more than four months ago, on April 2. "Among a total of 19 weaknesses discovered, there are issues that allow to either create a specific Java security bypass condition or that facilitate the exploitation process of a certain type of vulnerabilities," according to a press release issued by Security Explorations. The firm said it had developed reliable proof-of-concept exploits for all of the vulnerabilities, including 12 mock attacks "that demonstrate a complete JVM security sandbox bypass."

"Why critical remote code execution vulnerabilities were not fixed in Oracle's June patch is unknown," said Chester Wisniewski, a senior security advisor at Sophos Canada, in a blog post. "Oracle has yet to acknowledge these publicly, but had set expectations with Security Explorations that they were to be fixed in October."

3. Vulnerability Added To BlackHole Within Hours

The seriousness of the new Java exploits can be measured by the speed with which exploit toolkit authors updated their software to make use of the exploit. According to Wisniewski at Sophos, "it took less than 12 hours from the time the proof of concept for the latest Java zero-day vulnerabilities went public for exploits of those vulnerabilities to be included in a commercial crimeware kit"--namely, the BlackHole toolkit.

Of course, BlackHole isn't the only exploit kit on the market. "Exploit competition heats up. Latest Java exploit added to Redkit exploit kit too," tweeted Mikko Hypponen, chief research officer at F-Secure, about the Russian-language RedKit, a relatively new exploit kit that competes with the BlackHole and Phoenix crimeware packs, and which gained notoriety earlier this year for targeting a new Java exploit.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
moarsauce123
50%
50%
moarsauce123,
User Rank: Apprentice
9/3/2012 | 4:03:44 PM
re: Java Zero-Day Malware Attack: 6 Facts
You are welcome, but then why do you still include links to this story in the many specialized and best of emails that come out days later? I received another link to this story today and by now I wondered if there is another flaw in the current version. Well, there is, but this article addresses the old, already fixed flaws. Your competition is much more on the ball.
1954 Stratocaster
50%
50%
1954 Stratocaster,
User Rank: Apprentice
8/31/2012 | 4:13:26 PM
re: Java Zero-Day Malware Attack: 6 Facts
I would like to see a "7th fact" about why Java 7 was vulnerable and Java 6 was/is not. Our current corporate standard -- yes, we have some corporate Web apps, both internal and contracted, which require Java -- is v6.x.
Mathew
50%
50%
Mathew,
User Rank: Apprentice
8/31/2012 | 10:53:35 AM
re: Java Zero-Day Malware Attack: 6 Facts
Thanks for the comment, moarsauce. Welcome to the fast-paced world of publishing, eh? Yes, after this story came out, Oracle issued its alert about the patch--which is a welcome fix. Our sister publication DarkReading has more on the Java 7 patch.
moarsauce123
50%
50%
moarsauce123,
User Rank: Apprentice
8/30/2012 | 11:31:01 PM
re: Java Zero-Day Malware Attack: 6 Facts
There is already a update out that addresses the vulnerability. Maybe it is worthwhile to be more up to speed with content and publishing.
Leo Regulus
50%
50%
Leo Regulus,
User Rank: Apprentice
8/30/2012 | 8:08:13 PM
re: Java Zero-Day Malware Attack: 6 Facts
Please forgive me for writing when you weren't reading. I have brought this up several times in the past.
GET THIS TO YOUR EDITOR:
You have made some client-unfriendly changes to your format.
When we hit the 'Print' Icon, we expect to see the entire article as one page and relatively 'free' of (insert your own euphemism).
On this article, it was necessary to go to page 2 to get the whole article.
The result was also littered with (insert your own euphemism).
What should have printed on 2 sheets took at least 5.
What callous disregard for the environment and your clients resources!
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-2413
Published: 2014-10-20
Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary web script or HTML via the Mod* cookie parameter to html/modules.php.

CVE-2012-5244
Published: 2014-10-20
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to...

CVE-2012-5694
Published: 2014-10-20
Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (4) agentControlKey, or (5) platformDD1 parameter to frameworkgui/attach2Agents.p...

CVE-2012-5695
Published: 2014-10-20
Multiple cross-site request forgery (CSRF) vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allow remote attackers to hijack the authentication of administrators for requests that conduct (1) shell metacharacter or (2) SQL injection attacks or (3) send an SMS m...

CVE-2012-5696
Published: 2014-10-20
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers to obtain the plaintext database password via a direct request.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.