Tagged: Exploit Toggle Comment Threads | Keyboard Shortcuts

  • NegBox 4:20 pm on April 16, 2010 Permalink | Reply
    Tags: Emergency, Exploit, Java, Patch,   

    Update JAVA or get pwned – Sun Releases Emergency Java Patch 

    ALL YOUR BROWSERS ARE BELONG TO US

    Nice one with my morning coffee: Sun Releases Emergency Java Patch

    A week ago, Oracle claimed the vulnerability that had been discovered in Java was not a big deal at all. Apparently, they’ve changed their minds on that.

    Yesterday afternoon, Oracle pushed an update to Java that fixes a vulnerability that exposed Windows users to drive-by attacks. While Sun had claimed that the issue wasn’t serious enough for them to release a patch prior to the next scheduled version’s release, once Google’s Travis Ormandy released details of how the attack could be used, Sun relented and released a fix.

    The vulnerability was independently discovered by Ruben Sanamarta as well, and occurs because ofthe Java-Plugin Browser which runs “javaws.exe” withough validating command-line parameters.

    The new version, Sun Java 1.6.0_20 is available at the Java web site, or you can wait until it’s automatically pushed to you version.  Which will happen within 30 days.  Which you probably shouldn’t wait for.

    You can also read the full release notes on Oracle’s site.

    Don’t walk, run to update your Java… This affects ALL YOUR BROWSERS.

    Personally after getting pwned two weeks ago I’m running all browsers inside Sandboxie – See here for other ideas.

    ALL YOUR BROWSERS ARE BELONG TO US

     
  • NegBox 6:56 pm on April 4, 2010 Permalink | Reply
    Tags: Exploit, Firefox,   

    Firefox 3.6.3 Exploit is Out There 

    Damn. I can’t rememer exactly what I was browsing… Looking for some MAD TV stuff usin Firefox. I normally use several different browsers, but only FF and Chrome were active, and FF was the one I was using. Suddenly FF crashes and up pop this fake security scanne from an exe called VMA.EXE stored in Local Settings. It tried to make a network connection that the firewall stopped. I killed it and it came back up. There was anothe file in the same subdir with a number for a name and the same timestamp, both with hidden or system attributes. I nuked them, but they must have rewritten the EXE handler for Explorer.exe as no Programs would run – they would pop up the “select program to run this file with” dialog. I had seen a similar piece of shit a few weeks back in one of the kids machines.

    Messing with an infected machine is a waste of time. I immediately shut it off, popped in the Windows Home Server recovery disk and restored a backup. It didn’t look like this crapware was some sort of “sleeper” so I was back up and running with just a hicup.

    This reminds me… Maybe I should be using VIrtual Machines for browsing… I used to run my entire machine as a VM. I want to use VMs to offload a bit from my desktop workstation. This little incident was a bit of a reminder to stop goofing.

     
    • Mike Chiasson 1:22 pm on April 5, 2010 Permalink | Reply

      Enjoy watching videos in your VM lol. I’ve gotten into a habit of launching a VM full screen whenever I have company over. Being a IT guy I never run a virus scanner at home on my Server 08 box and my girlfriend had some friends over and someone sat down on my computer and launched IE to browse some sites (AAHHHHHH!). The next morning I noticed that something snagged my open FTP credentials and replaced a javascript viri code before the tag on every page in my http://ftp….nice when I was hosting like 15 sites on that account.
      My recent post Scraper Sites Stealing Your Clicks and Cash

    • negbox 5:23 pm on April 5, 2010 Permalink | Reply

      LOL… Hadn't thought of that… The video part will suck though a VM.

      Some of this crap is incredibly ingenious. I isolated one of the kids computer when it got that and it was displaying FAKE PORN sites. Hilarious… To convince you to purchase the 'antivirus' it would fake pop-ups of porn sites.

      BTW, love your site – We're in the maze! LOL. I'm putting up a blogroll, and you've just made the list.
      My recent post New Fucking Instant Messaging Rule

c
compose new post
j
next post/next comment
k
previous post/previous comment
r
reply
e
edit
o
show/hide comments
t
go to top
l
go to login
h
show/hide help
shift + esc
cancel