Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 27 guests and 1 member online
You are here:
Home
Resources
News from the Outside World
Java Zero DAy exploit
EH-Net
May 19, 2013, 10:23:30 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
News from the Outside World
(Moderator:
don
) >
Java Zero DAy exploit
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Java Zero DAy exploit (Read 9592 times)
0 Members and 1 Guest are viewing this topic.
Jamie.R
Sr. Member
Offline
Posts: 429
Java Zero DAy exploit
«
on:
August 28, 2012, 01:29:45 PM »
Hi All,
For anyone that does not know recently a java zero day was released.
http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html
http://pastie.org/4594319
Logged
OSWP | Hackingdojo Nidan | eCPPT
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: Java Zero DAy exploit
«
Reply #1 on:
August 28, 2012, 01:35:17 PM »
And it's already in Metasploit.
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Java Zero DAy exploit
«
Reply #2 on:
August 29, 2012, 04:02:26 AM »
Everything points to this being an interesting bug. Immunity have released a
blog post
indicating that there was actually two different 0-day bugs being exploited to achieve full compromise from the PoC:
Quote
There are 2 different zero-day vulnerabilities used in this exploit:
one is used to obtain a reference to the sun.awt.SunToolkit class and the other is used to invoke the public getField method on that class.
Quote from: shadowzero on August 28, 2012, 01:35:17 PM
And it's already in Metasploit.
Available
here
This bug may hang around for a while as there is evidence surfacing that the issue is reproducable in most JRE implementations.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Java Zero DAy exploit
«
Reply #3 on:
August 29, 2012, 01:29:03 PM »
Yep and is also included in new version of SET.
Logged
OSWP | Hackingdojo Nidan | eCPPT
3xban
Hero Member
Offline
Posts: 605
Re: Java Zero DAy exploit
«
Reply #4 on:
August 29, 2012, 06:28:16 PM »
played with the metasploit module last night briefly. Tested against Windows 8 and Defender grabbed it. Attempted to send it to Win7 and WinXPSP3 but kept getting an error on the victim. Then got tired and went to sleep.
Logged
Certs: GCWN
(@)Dewser
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Java Zero DAy exploit
«
Reply #5 on:
August 30, 2012, 11:00:04 AM »
I was able to get it working on my up-to-date Backtrack system. I obviously needed to install the official JRE7 package though.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
SecurityMonkey
Jr. Member
Offline
Posts: 89
Re: Java Zero DAy exploit
«
Reply #6 on:
August 30, 2012, 09:11:01 PM »
Oracle have released a patch....
https://isc.sans.edu/diary/Oracle+Releases+Java+Security+Updates/14008
Logged
www.securitymonkey.net
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Java Zero DAy exploit
«
Reply #7 on:
August 31, 2012, 03:11:51 AM »
I saw this last night on twitter time to get patching
Logged
OSWP | Hackingdojo Nidan | eCPPT
m0wgli
Full Member
Offline
Posts: 247
Re: Java Zero DAy exploit
«
Reply #8 on:
September 01, 2012, 02:54:07 AM »
Here we go again: Critical flaw found in just-patched Java.
http://www.theregister.co.uk/2012/08/31/critical_flaw_found_in_patched_java/
Logged
Security + | OSWP | eCPPT | CSTA
Cyber.spirit
Sr. Member
Offline
Posts: 351
The World is sick, Save your mind...
Re: Java Zero DAy exploit
«
Reply #9 on:
September 02, 2012, 12:33:01 AM »
metasploit has it
Logged
ICS Academy Network Security Certified
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Java Zero DAy exploit
«
Reply #10 on:
September 02, 2012, 02:23:45 PM »
Quote from: m0wgli on September 01, 2012, 02:54:07 AM
Here we go again: Critical flaw found in just-patched Java.
http://www.theregister.co.uk/2012/08/31/critical_flaw_found_in_patched_java/
Any more news on this find ?
Logged
OSWP | Hackingdojo Nidan | eCPPT
SecurityMonkey
Jr. Member
Offline
Posts: 89
Re: Java Zero DAy exploit
«
Reply #11 on:
September 02, 2012, 10:03:16 PM »
Blackhole targeting Java vulnerability via fake Microsoft Services Agreement email phish:
https://isc.sans.edu/diary/Blackhole+targeting+Java+vulnerability+via+fake+Microsoft+Services+Agreement+email+phish/14020
Logged
www.securitymonkey.net
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Java Zero DAy exploit
«
Reply #12 on:
September 03, 2012, 03:56:56 AM »
Got in this morning to find this.
We've updated the Microsoft Services Agreement, which governs many of our online services - including your Microsoft account and many of our online products and services for consumers, such as Hotmail, SkyDrive, Bing, MSN, Office.com, Windows Live Messenger, Windows Photo Gallery, Windows Movie Maker, Windows Mail Desktop, and Windows Writer. Please read over the new Microsoft Services Agreement here to familiarize yourself with the changes we've made.
The updated agreement will take effect on October 19, 2012. If you continue to use our services after October 19th, you agree to the terms of the new agreement or, of course you can cancel your service at any time.
We have modified the agreement to make it easier to read and understand, including using a question and answer format that we believe makes the terms much clearer. We also clarified how Microsoft uses your content to better protect consumers and improve our products, including aligning our usage to the way we're designing our cloud services to be highly integrated across many Microsoft products. We realize you may have personal conversations and store personal files using our products, and we want you to know that we prioritize your privacy.
Finally, we have added a binding arbitration clause and class action waiver that affects how disputes with Microsoft will be resolved in the United States.
Thank you for using Microsoft products and services!
________________________________________
Microsoft respects your privacy. Please read our online Privacy Statement.
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052
Logged
OSWP | Hackingdojo Nidan | eCPPT
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: Java Zero DAy exploit
«
Reply #13 on:
September 06, 2012, 10:21:54 AM »
From InfoWorld:
Quote
Security pros advise users to ditch Java
The 'write once, run anywhere' software platform has become a favorite of cyber attackers. Is it time for users to kill their Java?
Security firms are being none too gentle with Oracle's Java following the revelation this week that attackers are using two unpatched Java vulnerabilities to compromise selected targets. The most common advice: Uninstall the Java plug-in in your browser and don't use services that require the software.
On Monday, security firm FireEye revealed that a customer had been attacked with a previously unknown vulnerability. Yet Oracle already knew about the security issue and apparently had an update at the ready to be released on its regularly scheduled patch day in October. With reliable exploits for the vulnerabilities rapidly being adopted by security researchers and cyber criminals alike, the company rushed out a fix for the flaw on Thursday.
Overall, the incident has left a bitter taste in the collective mouths of many security professionals.
"I think there is a lot of sentiment toward not using Java at all if you can avoid it," says Stephen Cobb, security evangelist for antimalware firm ESET. "That is what I would say, and I'm not the first to say that, and I'm not alone in saying that."
Security firm Sophos is among the many to recommend that users turn off the Java plug-in within the browser. And the U.S. Computer Emergency Readiness Team (CERT), the response agency for the U.S. government, offered advice for system administrators that boiled down to "remove Java plug-ins." In April, InfoWorld covered the backlash against Java in the wake of the infection of more than 600,000 Mac computers by the Flashback Trojan and pointed out why removing Java infrastructure is not an option for many enterprises.
While Oracle is not to blame for malicious actors using Java, the company needs to clarify its commitment to securing the platform, argues ESET's Cobb.
An analysis of the flaws found that Oracle introduced the issues into Java 7 a year ago and warned that while it was found recently, cyber criminals and intellectual-property thieves had likely been using the attack for months.
For full article:
http://www.infoworld.com/t/web-security/security-pros-advise-users-ditch-java-201457
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Java Zero DAy exploit
«
Reply #14 on:
September 07, 2012, 03:14:39 AM »
To Ditch Java I think is very hard for any business. As Java says itself its used everywhere from Tv to bank cards.
Logged
OSWP | Hackingdojo Nidan | eCPPT
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(85) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.