<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Researchers: Java Zero-Day Leveraged Two Flaws</title>
	<atom:link href="http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Tue, 21 May 2013 15:16:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-117665</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Fri, 28 Sep 2012 08:31:52 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-117665</guid>
		<description><![CDATA[Flash is going away on all modern browsers, and Apple pretty much said they were dumping it. If you can&#039;t display flash content now, I&#039;d be surprised. (I guess - not having to play with Apples much)]]></description>
		<content:encoded><![CDATA[<p>Flash is going away on all modern browsers, and Apple pretty much said they were dumping it. If you can&#8217;t display flash content now, I&#8217;d be surprised. (I guess &#8211; not having to play with Apples much)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-109856</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Mon, 17 Sep 2012 07:15:17 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-109856</guid>
		<description><![CDATA[No one solution whether AV or AM can stop all attacks. Only a blended defense can come close; and only then will you reach about 97% success. After that - only solutions that can protect in an infected environment do any good.

If you have much to protect - like banking - then maybe a LiveCD is the solution.]]></description>
		<content:encoded><![CDATA[<p>No one solution whether AV or AM can stop all attacks. Only a blended defense can come close; and only then will you reach about 97% success. After that &#8211; only solutions that can protect in an infected environment do any good.</p>
<p>If you have much to protect &#8211; like banking &#8211; then maybe a LiveCD is the solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Guard Company</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-104256</link>
		<dc:creator>Security Guard Company</dc:creator>
		<pubDate>Sat, 08 Sep 2012 13:15:07 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-104256</guid>
		<description><![CDATA[Does anyone else think Apple/mobile tablets should have Flash installed? Great blog though, very interesting.]]></description>
		<content:encoded><![CDATA[<p>Does anyone else think Apple/mobile tablets should have Flash installed? Great blog though, very interesting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-103049</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Sun, 02 Sep 2012 18:36:05 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-103049</guid>
		<description><![CDATA[Yesterday I finally received the Java 7 update from File Hippo Update Checker; guess it just takes time.

After installing it, I went back to the site, and this time it detected the old Java 6 version 33 correctly, and marked my browser as vulnerable((Comodo Dragon) So I uninstalled the older version, and isjavaexploitable once again reports the same browser as safe.

Seems they couldn&#039;t detect the old version without the new Java 7 being on board?!  ?:\  (On this Chrome derivative that is)]]></description>
		<content:encoded><![CDATA[<p>Yesterday I finally received the Java 7 update from File Hippo Update Checker; guess it just takes time.</p>
<p>After installing it, I went back to the site, and this time it detected the old Java 6 version 33 correctly, and marked my browser as vulnerable((Comodo Dragon) So I uninstalled the older version, and isjavaexploitable once again reports the same browser as safe.</p>
<p>Seems they couldn&#8217;t detect the old version without the new Java 7 being on board?!  ?:\  (On this Chrome derivative that is)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George G.</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-103032</link>
		<dc:creator>George G.</dc:creator>
		<pubDate>Sun, 02 Sep 2012 16:29:42 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-103032</guid>
		<description><![CDATA[Thanks, Uzzi.

The URL you provided refers to &quot;Comment on: New Java 7 exploit can potentially affect Macs&quot;
I use Windows.

Also, when I try to bring up digitaloffense.net my WOT warns me that &quot;This site has a poor reputation based on
user ratings.&quot; So I did not go ahead and bring it up.]]></description>
		<content:encoded><![CDATA[<p>Thanks, Uzzi.</p>
<p>The URL you provided refers to &#8220;Comment on: New Java 7 exploit can potentially affect Macs&#8221;<br />
I use Windows.</p>
<p>Also, when I try to bring up digitaloffense.net my WOT warns me that &#8220;This site has a poor reputation based on<br />
user ratings.&#8221; So I did not go ahead and bring it up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uzzi</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-103022</link>
		<dc:creator>Uzzi</dc:creator>
		<pubDate>Sun, 02 Sep 2012 14:30:17 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-103022</guid>
		<description><![CDATA[Maybe this helps...
http://reviews.cnet.com/8618-13727_7-57501517.html?assetTypeId=12&amp;messageId=12811832

(...or ask &#039;hdm&#039; at digitaloffense.net)]]></description>
		<content:encoded><![CDATA[<p>Maybe this helps&#8230;<br />
<a href="http://reviews.cnet.com/8618-13727_7-57501517.html?assetTypeId=12&#038;messageId=12811832" rel="nofollow">http://reviews.cnet.com/8618-13727_7-57501517.html?assetTypeId=12&#038;messageId=12811832</a></p>
<p>(&#8230;or ask &#8216;hdm&#8217; at digitaloffense.net)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George G.</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-102937</link>
		<dc:creator>George G.</dc:creator>
		<pubDate>Sat, 01 Sep 2012 19:15:36 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-102937</guid>
		<description><![CDATA[Thanks for the response, Bloofinpork.

Yes, I got the exact same message as you did.

Then I manually enabled isjavaexploitable and got the response describe in my comment of Aug.30 (to which you replied).]]></description>
		<content:encoded><![CDATA[<p>Thanks for the response, Bloofinpork.</p>
<p>Yes, I got the exact same message as you did.</p>
<p>Then I manually enabled isjavaexploitable and got the response describe in my comment of Aug.30 (to which you replied).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rabid Howler Monkey</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-102911</link>
		<dc:creator>Rabid Howler Monkey</dc:creator>
		<pubDate>Sat, 01 Sep 2012 15:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-102911</guid>
		<description><![CDATA[Solo Owl wrote:
&quot;You can use Base with engines other than HSQLDB

A very good point (I was looking from the perspective of a personal database for non-geek users).  One can use Base as a front-end to external databases on multi-user database management systems such as MySQL, PostgreSQL, etc. as Base provides both ODBC and direct (along with JDBC) access as connection options.

In addition, geeks can install and configure MySQL, PostgreSQL, etc. for use as their personal database.  Just like on Windows, geeks can install and configure Microsoft SQL Server Express for their personal database and use MS Access as a front-end.]]></description>
		<content:encoded><![CDATA[<p>Solo Owl wrote:<br />
&#8220;You can use Base with engines other than HSQLDB</p>
<p>A very good point (I was looking from the perspective of a personal database for non-geek users).  One can use Base as a front-end to external databases on multi-user database management systems such as MySQL, PostgreSQL, etc. as Base provides both ODBC and direct (along with JDBC) access as connection options.</p>
<p>In addition, geeks can install and configure MySQL, PostgreSQL, etc. for use as their personal database.  Just like on Windows, geeks can install and configure Microsoft SQL Server Express for their personal database and use MS Access as a front-end.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bloofinpork</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-102731</link>
		<dc:creator>Bloofinpork</dc:creator>
		<pubDate>Fri, 31 Aug 2012 22:42:36 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-102731</guid>
		<description><![CDATA[George, I believe something is amiss in your configuration.  If I go to isjavaexploitable with noscript enabled, I get &quot;You&#039;ll need to enable Javascript for us to detect your Java version&quot; -- which is what I&#039;d expect.]]></description>
		<content:encoded><![CDATA[<p>George, I believe something is amiss in your configuration.  If I go to isjavaexploitable with noscript enabled, I get &#8220;You&#8217;ll need to enable Javascript for us to detect your Java version&#8221; &#8212; which is what I&#8217;d expect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mechBgon</title>
		<link>http://krebsonsecurity.com/2012/08/java-exploit-leveraged-two-flaws/comment-page-1/#comment-102402</link>
		<dc:creator>mechBgon</dc:creator>
		<pubDate>Fri, 31 Aug 2012 07:04:18 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16590#comment-102402</guid>
		<description><![CDATA[Cool!  Thanks David!  I&#039;m surprised they didn&#039;t use their friendly &quot;Fix-It&quot; approach, but that&#039;s still handy.  

I did ask an author on the IE team blog why the Java toggle has disappeared from the Internet Options user interface.  It used to be there, now it&#039;s not.  They left in the Scripting Of Java Applets option, but it turns out not to be effective.  D&#039;oh!]]></description>
		<content:encoded><![CDATA[<p>Cool!  Thanks David!  I&#8217;m surprised they didn&#8217;t use their friendly &#8220;Fix-It&#8221; approach, but that&#8217;s still handy.  </p>
<p>I did ask an author on the IE team blog why the Java toggle has disappeared from the Internet Options user interface.  It used to be there, now it&#8217;s not.  They left in the Scripting Of Java Applets option, but it turns out not to be effective.  D&#8217;oh!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 26/27 queries in 0.003 seconds using memcached
Object Caching 386/412 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-21 11:40:59 by W3 Total Cache -->