<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Zero-Day Java Exploit Debuts in Crimeware</title>
	<atom:link href="http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Thu, 20 Jun 2013 05:20:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Rabid Howler Monkey</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-143610</link>
		<dc:creator>Rabid Howler Monkey</dc:creator>
		<pubDate>Sun, 20 Jan 2013 16:40:47 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-143610</guid>
		<description><![CDATA[More on portable apps (mentioned immediately above by Zsolt Sandor, thx Zsolt) and Java.  For those that need access to Java applets served on important web sites and/or Java-based applications, portable apps might be a solution for some users.  In fact, one might be able to go Java free on their PC.

The Firefox portable app:

http://portableapps.com/apps/internet/firefox_portable

The portable Java Runtime Environment, jPortable:

http://portableapps.com/apps/utilities/java_portable

When you need to access a web site serving Java applets, just plug-in the USB stick with your portable apps and do your browsing.  When finished, safely remove the USB stick from the PC.  And be sure to keep your portable browser and Java up-to-date.

In addition, all or, perhaps,  some of one&#039;s Java-based apps (read JAR files) might also be placed on the USB stick and run via the Java portable launcher (it works with jPortable, above):

http://portableapps.com/apps/utilities/java_portable_launcher]]></description>
		<content:encoded><![CDATA[<p>More on portable apps (mentioned immediately above by Zsolt Sandor, thx Zsolt) and Java.  For those that need access to Java applets served on important web sites and/or Java-based applications, portable apps might be a solution for some users.  In fact, one might be able to go Java free on their PC.</p>
<p>The Firefox portable app:</p>
<p><a href="http://portableapps.com/apps/internet/firefox_portable" rel="nofollow">http://portableapps.com/apps/internet/firefox_portable</a></p>
<p>The portable Java Runtime Environment, jPortable:</p>
<p><a href="http://portableapps.com/apps/utilities/java_portable" rel="nofollow">http://portableapps.com/apps/utilities/java_portable</a></p>
<p>When you need to access a web site serving Java applets, just plug-in the USB stick with your portable apps and do your browsing.  When finished, safely remove the USB stick from the PC.  And be sure to keep your portable browser and Java up-to-date.</p>
<p>In addition, all or, perhaps,  some of one&#8217;s Java-based apps (read JAR files) might also be placed on the USB stick and run via the Java portable launcher (it works with jPortable, above):</p>
<p><a href="http://portableapps.com/apps/utilities/java_portable_launcher" rel="nofollow">http://portableapps.com/apps/utilities/java_portable_launcher</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zsolt Sandor</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-142142</link>
		<dc:creator>Zsolt Sandor</dc:creator>
		<pubDate>Wed, 16 Jan 2013 17:37:21 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-142142</guid>
		<description><![CDATA[The bug is in the runtime library of Oracle&#039;s Java, but it only means, that the cracker can run a program as a normal user (the user in it&#039;s name the browser was started). It is also unlike that a hacker cares about linux, the target platforms are mostly windows. But, it does not mean your are invulnerable, only that most likely you won&#039;t have a problem. I suggest however to switch off java in your browser, and if a page requires java (banking operations, etc.) use a separate browser only for that purpose.]]></description>
		<content:encoded><![CDATA[<p>The bug is in the runtime library of Oracle&#8217;s Java, but it only means, that the cracker can run a program as a normal user (the user in it&#8217;s name the browser was started). It is also unlike that a hacker cares about linux, the target platforms are mostly windows. But, it does not mean your are invulnerable, only that most likely you won&#8217;t have a problem. I suggest however to switch off java in your browser, and if a page requires java (banking operations, etc.) use a separate browser only for that purpose.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zsolt Sandor</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-142141</link>
		<dc:creator>Zsolt Sandor</dc:creator>
		<pubDate>Wed, 16 Jan 2013 17:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-142141</guid>
		<description><![CDATA[A solution to this problem is to install a portable firefox/chrome/etc. on your computer, where you have enabled java, and use this portable browser for accessing pages, which require java (government portal, banking). 

Disable java in the browser you use for regular surfing. 

Not very elegant way, but at least a safe one.]]></description>
		<content:encoded><![CDATA[<p>A solution to this problem is to install a portable firefox/chrome/etc. on your computer, where you have enabled java, and use this portable browser for accessing pages, which require java (government portal, banking). </p>
<p>Disable java in the browser you use for regular surfing. </p>
<p>Not very elegant way, but at least a safe one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-141572</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Tue, 15 Jan 2013 05:18:21 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-141572</guid>
		<description><![CDATA[I&#039;m just guessing, but I would speculate that even if the malware could compromise your browser, they wouldn&#039;t be able to do anything with it. I&#039;ve tested some zero day threats that are supposed to work on Mac, only to find they can&#039;t run on RISC architecture. In fact I&#039;ve had some clients who were under attack by what was obviously concerted efforts by corporate espionage groups, who switched to old PowerPCs and have been able to run again. This doesn&#039;t guarantee they aren&#039;t still under surveillance, but at least they can operate their business.

When you have the big guns after you, that can take over a new Mac Air with your cell phone! I assume using bluetooth. You know you are a target of interest!]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m just guessing, but I would speculate that even if the malware could compromise your browser, they wouldn&#8217;t be able to do anything with it. I&#8217;ve tested some zero day threats that are supposed to work on Mac, only to find they can&#8217;t run on RISC architecture. In fact I&#8217;ve had some clients who were under attack by what was obviously concerted efforts by corporate espionage groups, who switched to old PowerPCs and have been able to run again. This doesn&#8217;t guarantee they aren&#8217;t still under surveillance, but at least they can operate their business.</p>
<p>When you have the big guns after you, that can take over a new Mac Air with your cell phone! I assume using bluetooth. You know you are a target of interest!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WD</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-141467</link>
		<dc:creator>WD</dc:creator>
		<pubDate>Mon, 14 Jan 2013 19:36:08 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-141467</guid>
		<description><![CDATA[Redhat has confirmed that OpenJDK is affected.  Part of the confusion of whether or not it was affected are because 1) The exploit takes advantage of more than one weakness in Java to achieve code execution.  2) The PoC sample is crafted to work with Oracle Java, but the fact that it doesn&#039;t work with OpenJDK doesn&#039;t mean that OpenJDK isn&#039;t vulnerable.
https://bugzilla.redhat.com/show_bug.cgi?id=894172]]></description>
		<content:encoded><![CDATA[<p>Redhat has confirmed that OpenJDK is affected.  Part of the confusion of whether or not it was affected are because 1) The exploit takes advantage of more than one weakness in Java to achieve code execution.  2) The PoC sample is crafted to work with Oracle Java, but the fact that it doesn&#8217;t work with OpenJDK doesn&#8217;t mean that OpenJDK isn&#8217;t vulnerable.<br />
<a href="https://bugzilla.redhat.com/show_bug.cgi?id=894172" rel="nofollow">https://bugzilla.redhat.com/show_bug.cgi?id=894172</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: StevenHB</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-141428</link>
		<dc:creator>StevenHB</dc:creator>
		<pubDate>Mon, 14 Jan 2013 18:03:26 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-141428</guid>
		<description><![CDATA[As they say, absence of evidence isn&#039;t the same as evidence of absence.]]></description>
		<content:encoded><![CDATA[<p>As they say, absence of evidence isn&#8217;t the same as evidence of absence.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: godivademaus</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-141410</link>
		<dc:creator>godivademaus</dc:creator>
		<pubDate>Mon, 14 Jan 2013 16:51:44 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-141410</guid>
		<description><![CDATA[I am running on a mac 10.5.8 Leopard, on a powerPC, which means that a) I cannot update beyond this operating system because subsequent OS upgrades will not work on my powerPC chipset.

Also, Adobe, and other software and utility developers have ceased to include my OS and my chipset among their included upgrades, therefore I only have java 6 and is not included among the automatic upgrades.

So, can I assume from this that my machine would not be impacted from this recently discovered flaw in the Java SE 7?]]></description>
		<content:encoded><![CDATA[<p>I am running on a mac 10.5.8 Leopard, on a powerPC, which means that a) I cannot update beyond this operating system because subsequent OS upgrades will not work on my powerPC chipset.</p>
<p>Also, Adobe, and other software and utility developers have ceased to include my OS and my chipset among their included upgrades, therefore I only have java 6 and is not included among the automatic upgrades.</p>
<p>So, can I assume from this that my machine would not be impacted from this recently discovered flaw in the Java SE 7?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-141245</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Mon, 14 Jan 2013 02:58:27 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-141245</guid>
		<description><![CDATA[Maybe:

But from everything I read on many tech sites everywhere; Java and Adobe are the TOP vectors for criminals bent on pwning your stuff!]]></description>
		<content:encoded><![CDATA[<p>Maybe:</p>
<p>But from everything I read on many tech sites everywhere; Java and Adobe are the TOP vectors for criminals bent on pwning your stuff!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-141244</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Mon, 14 Jan 2013 02:54:18 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-141244</guid>
		<description><![CDATA[Good to hear Greg - I wonder if Revo Uninstaller may help if it happens again?]]></description>
		<content:encoded><![CDATA[<p>Good to hear Greg &#8211; I wonder if Revo Uninstaller may help if it happens again?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/comment-page-1/#comment-141243</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Mon, 14 Jan 2013 02:52:22 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18395#comment-141243</guid>
		<description><![CDATA[Good thing the update is out now js; and you won&#039;t have to worry - for a while - anyway. *]]></description>
		<content:encoded><![CDATA[<p>Good thing the update is out now js; and you won&#8217;t have to worry &#8211; for a while &#8211; anyway. *</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 1/23 queries in 0.007 seconds using memcached
Object Caching 375/393 objects using memcached

 Served from: krebsonsecurity.com @ 2013-06-20 01:25:12 by W3 Total Cache -->