<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Java Zero-Day Exploit on Sale for &#8216;Five Digits&#8217;</title>
	<atom:link href="http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 19 Jun 2013 14:32:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Joe</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-132279</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Fri, 07 Dec 2012 16:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-132279</guid>
		<description><![CDATA[what white hat firms are paying 5 figures for java exploits. doesn&#039;t seem plausible.]]></description>
		<content:encoded><![CDATA[<p>what white hat firms are paying 5 figures for java exploits. doesn&#8217;t seem plausible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: christi parks</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130757</link>
		<dc:creator>christi parks</dc:creator>
		<pubDate>Sun, 02 Dec 2012 09:13:39 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130757</guid>
		<description><![CDATA[Hello, sir i would like to ask that what is the scope of java training, what all topics should be covered and it is kinda bothering me … and has anyone studies from this course http://www.wiziq.com/course/1779-core-and-advance-java-concepts of core and advance java online ?? or tell me any other guidance...
would really appreciate help… and Also i would like to thank for all the information you are providing on java concepts.]]></description>
		<content:encoded><![CDATA[<p>Hello, sir i would like to ask that what is the scope of java training, what all topics should be covered and it is kinda bothering me … and has anyone studies from this course <a href="http://www.wiziq.com/course/1779-core-and-advance-java-concepts" rel="nofollow">http://www.wiziq.com/course/1779-core-and-advance-java-concepts</a> of core and advance java online ?? or tell me any other guidance&#8230;<br />
would really appreciate help… and Also i would like to thank for all the information you are providing on java concepts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meh</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130461</link>
		<dc:creator>meh</dc:creator>
		<pubDate>Fri, 30 Nov 2012 19:35:30 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130461</guid>
		<description><![CDATA[Didn&#039;t google get in trouble for trying to sidestep it?  Our patent laws and tangled partnerships make it hard for a more secure replacement to replace it.]]></description>
		<content:encoded><![CDATA[<p>Didn&#8217;t google get in trouble for trying to sidestep it?  Our patent laws and tangled partnerships make it hard for a more secure replacement to replace it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rabid Howler Monkey</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130455</link>
		<dc:creator>Rabid Howler Monkey</dc:creator>
		<pubDate>Fri, 30 Nov 2012 18:49:01 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130455</guid>
		<description><![CDATA[Remember that this article is warning about a Java zero-day exploit that is for sale.  In this particular case, everyone with Java installed on their PCs is running a vulnerable Java version.

With regard to Java exploits for vulnerabilities that have been patched, remember that there are many computer users that fail to update their Java.  For these users, their installed Java version is likely further behind than that on the current LPS LiveCD.

A CD-R won&#039;t allow infections to persist on reboot.  Thus, running as root really isn&#039;t a problem for limited LiveCD sessions.  One can enable the NoScript add-on for Firefox (included in the LPS iso) and control the web sites where the Java plug-in is allowed.  Financial web sites have been hacked (e.g., Bank of India) with users redirected to malicious sites serving malware.

More on LiveCD usage from another of Brian&#039;s excellent articles here:

http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/

For individuals that don&#039;t need Java installed on their PCs to run Java applications locally, but DO need the Java plug-in to access certain web site(s) with their browser, the LPS LiveCD provides a reasonably safe option.  And as I stated in a previous post, one can sign up to be notified when a new version of LPS is released.]]></description>
		<content:encoded><![CDATA[<p>Remember that this article is warning about a Java zero-day exploit that is for sale.  In this particular case, everyone with Java installed on their PCs is running a vulnerable Java version.</p>
<p>With regard to Java exploits for vulnerabilities that have been patched, remember that there are many computer users that fail to update their Java.  For these users, their installed Java version is likely further behind than that on the current LPS LiveCD.</p>
<p>A CD-R won&#8217;t allow infections to persist on reboot.  Thus, running as root really isn&#8217;t a problem for limited LiveCD sessions.  One can enable the NoScript add-on for Firefox (included in the LPS iso) and control the web sites where the Java plug-in is allowed.  Financial web sites have been hacked (e.g., Bank of India) with users redirected to malicious sites serving malware.</p>
<p>More on LiveCD usage from another of Brian&#8217;s excellent articles here:</p>
<p><a href="http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/" rel="nofollow">http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/</a></p>
<p>For individuals that don&#8217;t need Java installed on their PCs to run Java applications locally, but DO need the Java plug-in to access certain web site(s) with their browser, the LPS LiveCD provides a reasonably safe option.  And as I stated in a previous post, one can sign up to be notified when a new version of LPS is released.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130417</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Fri, 30 Nov 2012 14:47:38 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130417</guid>
		<description><![CDATA[You don&#039;t need java to activate Webex; you can download the webex client yourself and install it manually.]]></description>
		<content:encoded><![CDATA[<p>You don&#8217;t need java to activate Webex; you can download the webex client yourself and install it manually.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rpw</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130358</link>
		<dc:creator>rpw</dc:creator>
		<pubDate>Fri, 30 Nov 2012 10:10:30 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130358</guid>
		<description><![CDATA[I heard LPS runs the browser as root and has an outdated Java...]]></description>
		<content:encoded><![CDATA[<p>I heard LPS runs the browser as root and has an outdated Java&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rb</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130163</link>
		<dc:creator>rb</dc:creator>
		<pubDate>Thu, 29 Nov 2012 13:37:59 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130163</guid>
		<description><![CDATA[Interesting - it was still giving me the forbidden error message this morning.  I reconfigured my browser to bypass our proxy and I got right in.]]></description>
		<content:encoded><![CDATA[<p>Interesting &#8211; it was still giving me the forbidden error message this morning.  I reconfigured my browser to bypass our proxy and I got right in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rabid Howler Monkey</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130068</link>
		<dc:creator>Rabid Howler Monkey</dc:creator>
		<pubDate>Wed, 28 Nov 2012 22:57:02 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130068</guid>
		<description><![CDATA[Just tried the U.S. Air Force Lightweight Portable Security (LPS) site with both Firefox and Opera and it was working:

http://www.spi.dod.mil/lipose.htm

P.S.  One can optionally sign up to be notified when a new version of LPS is released.]]></description>
		<content:encoded><![CDATA[<p>Just tried the U.S. Air Force Lightweight Portable Security (LPS) site with both Firefox and Opera and it was working:</p>
<p><a href="http://www.spi.dod.mil/lipose.htm" rel="nofollow">http://www.spi.dod.mil/lipose.htm</a></p>
<p>P.S.  One can optionally sign up to be notified when a new version of LPS is released.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rb</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130060</link>
		<dc:creator>rb</dc:creator>
		<pubDate>Wed, 28 Nov 2012 21:31:09 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130060</guid>
		<description><![CDATA[As an aside, I am not able to access the LPS website.  It displays a &quot;Forbidden&quot; error message.]]></description>
		<content:encoded><![CDATA[<p>As an aside, I am not able to access the LPS website.  It displays a &#8220;Forbidden&#8221; error message.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shinki-itten</title>
		<link>http://krebsonsecurity.com/2012/11/java-zero-day-exploit-on-sale-for-five-digits/comment-page-1/#comment-130048</link>
		<dc:creator>Shinki-itten</dc:creator>
		<pubDate>Wed, 28 Nov 2012 19:57:40 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=17677#comment-130048</guid>
		<description><![CDATA[I had the experience today that I had to activate JAVA in my browser in order to load a webinar that used WebEx technology. WebEx is used extensively for webinars hosted by law firms and other education providers. Activation (in Firefox) was bothersome, requiring a few steps -- more than I expected.]]></description>
		<content:encoded><![CDATA[<p>I had the experience today that I had to activate JAVA in my browser in order to load a webinar that used WebEx technology. WebEx is used extensively for webinars hosted by law firms and other education providers. Activation (in Firefox) was bothersome, requiring a few steps &#8212; more than I expected.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 5/22 queries in 0.004 seconds using memcached
Object Caching 379/395 objects using memcached

 Served from: krebsonsecurity.com @ 2013-06-19 10:38:27 by W3 Total Cache -->