Attacks/Breaches
8/30/2012
11:07 AM
50%
50%

Java Zero-Day Malware Attack: 6 Facts

New details reveal Oracle knew about the Java exploit in April, but has yet to release a patch. Here's how to protect yourself against active attacks.

4. Attackers Like Java For Its Simplicity

"In the past year or so the bad guys started paying much more attention to Java exploits," said Trustwave SpiderLabs security researcher Arseny Levin earlier this year in a blog post. "Java is a very appealing target, since it can be found on your home desktop, on your mobile, and even on many embedded devices." Furthermore, he noted that some vulnerabilities can be exploited via Java Virtual Machine shell bytecode, "meaning exploitation will be successful regardless of the operating system." The Apple OS X Flashback malware was one example of such an attack.

According to a BlackHole control panel screenshot published by Seculert, the Java array vulnerability found earlier this year--and targeted by Flashback--was successfully exploited by the exploit kit between 76% and 97% of the time.

5. Java Exploits Wildly Successful

Now, the BlackHole developer's rapid response has paid off for his crimeware customers. "We were able to count tens of thousands of new infected machines due to the Java 0-day, since the exploit was added to the BlackHole exploit kit," according to a blog post from the company. "Usually, a good exploit kit like BlackHole has a success rate of around 10% for infecting machines visiting the servers. In the new version of BlackHole infection servers, we have seen up to a 25% percent success rate," it noted, and said 99% of those successful exploits were thanks to using Java vulnerabilities.

Small wonder that Sean Sullivan, security advisor at F-Secure Labs, has dubbed the Java runtime environment (JRE) as a "perpetual vulnerability machine."

6. Malware May Be Targeting Mac Users

A variant of the Tsunami malware that can target both OS X and Linux systems may already be using the new Java vulnerabilities to infect systems. "This method of infection has not yet been confirmed, but as this OS X malware connects out to the same IP address as the Windows backdoors known to be dropped by [the Java vulnerability], it seems they are at least related incidents," said Lysa Myers, a "virus hunter" at Mac security software firm Intego, in a Wednesday blog post.

"At the time of writing, the JAR file that was purported to be dropping this Trojan has been replaced with a bit of threatening text. It seems like maybe someone knows they've been discovered?" she said.

One piece of good news for Mac users, however, is that only Java 6 is included by Apple in OS X. While Mac users can upgrade to Java 7, they would have had to have done so manually.

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
moarsauce123
50%
50%
moarsauce123,
User Rank: Apprentice
9/3/2012 | 4:03:44 PM
re: Java Zero-Day Malware Attack: 6 Facts
You are welcome, but then why do you still include links to this story in the many specialized and best of emails that come out days later? I received another link to this story today and by now I wondered if there is another flaw in the current version. Well, there is, but this article addresses the old, already fixed flaws. Your competition is much more on the ball.
1954 Stratocaster
50%
50%
1954 Stratocaster,
User Rank: Apprentice
8/31/2012 | 4:13:26 PM
re: Java Zero-Day Malware Attack: 6 Facts
I would like to see a "7th fact" about why Java 7 was vulnerable and Java 6 was/is not. Our current corporate standard -- yes, we have some corporate Web apps, both internal and contracted, which require Java -- is v6.x.
Mathew
50%
50%
Mathew,
User Rank: Apprentice
8/31/2012 | 10:53:35 AM
re: Java Zero-Day Malware Attack: 6 Facts
Thanks for the comment, moarsauce. Welcome to the fast-paced world of publishing, eh? Yes, after this story came out, Oracle issued its alert about the patch--which is a welcome fix. Our sister publication DarkReading has more on the Java 7 patch.
moarsauce123
50%
50%
moarsauce123,
User Rank: Apprentice
8/30/2012 | 11:31:01 PM
re: Java Zero-Day Malware Attack: 6 Facts
There is already a update out that addresses the vulnerability. Maybe it is worthwhile to be more up to speed with content and publishing.
Leo Regulus
50%
50%
Leo Regulus,
User Rank: Apprentice
8/30/2012 | 8:08:13 PM
re: Java Zero-Day Malware Attack: 6 Facts
Please forgive me for writing when you weren't reading. I have brought this up several times in the past.
GET THIS TO YOUR EDITOR:
You have made some client-unfriendly changes to your format.
When we hit the 'Print' Icon, we expect to see the entire article as one page and relatively 'free' of (insert your own euphemism).
On this article, it was necessary to go to page 2 to get the whole article.
The result was also littered with (insert your own euphemism).
What should have printed on 2 sheets took at least 5.
What callous disregard for the environment and your clients resources!
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4233
Published: 2015-07-02
SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu54037.

CVE-2014-1750
Published: 2015-07-01
Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html. NOTE: this was originally reported as cross-sit...

CVE-2014-1836
Published: 2015-07-01
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.

CVE-2015-0848
Published: 2015-07-01
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

CVE-2015-1330
Published: 2015-07-01
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vecto...

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report