Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 42862
  • Total Topics: 16071
  • Online Today: 1326
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: Warns from Microsoft: Huge number of Java attacks  (Read 4259 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7528
  • KARMA: 322
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Warns from Microsoft: Huge number of Java attacks
« on: 19. October 2010., 16:57:42 »


In the course of researching and preparing volume 9 of the Security Intelligence Report, Microsoft analysts discovered an interesting trend. According to Microsoft's findings, attacks against Java have recently surged to unprecedented levels--dwarfing attacks against Adobe PDFs.

Microsoft is accustomed to being a prime target for malware attacks, and Adobe has been hogging center stage for a while as well. But, a post on the Microsoft Malware Protection Center (MMPC) blog  notes, "by the beginning of this year, the number of Java exploits (and by that I mean attacks on vulnerable Java code, not attacks using JavaScript) had well surpassed the total number of Adobe-related exploits we monitored": http://blogs.technet.com/b/mmpc/archive/2010/10/18/have-you-checked-the-java.aspx

Java runs in the background under the radar and vulnerabilities may be left unpatched and exposed. Attacks on Java make sense for precisely the same reason that attacks on Adobe make sense. A malware developer that has to choose which operating system platform to attack will choose Microsoft because it offers significantly more potential targets. But, as Microsoft has developed more secure applications, and improved security controls, attackers have discovered that third-party cross-platform technologies are often a weak spot in the security armor.

Microsoft's Holly Stewart explains in the MMPC blog, "Java is ubiquitous, and, as was once true with browsers and document readers like Adobe Acrobat, people don't think to update it. On top of that, Java is a technology that runs in the background to make more visible components work. How do you know if you have Java installed or if it's running?"

Stewart also raises the question of why this surge in Java attacks seems to have flown under the radar. She dubs the phenomenon "Java-blindness". Essentially, Stewart theorizes that the IPS (Intrusion Prevention System) products that we expect to detect and identify new threats are blind to Java because the performance impact of interpreting Java in real-time is too great.

While the number of attacks against Java spiked, the attacks focused primarily on three Java vulnerabilities. More importantly, all three Java flaws already had patches available. Java just kind of runs silently doing its thing, though, so--while users and IT admins focus on Microsoft's monthly Patch Tuesday updates, or Adobe's quarterly security patches--Java is sort of "out of sight, out of mind" and vulnerabilities may go unpatched.

In the grand scheme of things, the attacks on Java are a drop in the bucket. The surge in Java attacks may be significant and unprecedented, but Java is still a relative blip on the radar. That said, Microsoft's findings highlight an alarming trend, and should provide incentive for users and IT admins to be more diligent about identifying and patching vulnerabilities in third-party apps that could expose systems to attack.

(PCW)

Samker's Computer Forum - SCforum.info

Warns from Microsoft: Huge number of Java attacks
« on: 19. October 2010., 16:57:42 »

Fintech

  • SCF VIP Member
  • *****
  • Posts: 367
  • KARMA: 49
  • Gender: Male
Re: Warns from Microsoft: Huge number of Java attacks
« Reply #1 on: 20. October 2010., 00:25:49 »
Fortunately I've updated java installed!
So, really much attacks on the java!
???

amitraina

  • SCF Member
  • **
  • Posts: 86
  • KARMA: 14
Re: Warns from Microsoft: Huge number of Java attacks
« Reply #2 on: 21. October 2010., 02:58:47 »
i updated thnks for inf

Brian

  • SCF Member
  • **
  • Posts: 15
  • KARMA: 6
  • Gender: Male
  • We live in a digital world!
    • TechAirlines
Re: Warns from Microsoft: Huge number of Java attacks
« Reply #3 on: 21. October 2010., 06:33:16 »
I usually forget to update Java. I get quite a lot of trojans from Java .class files.
Best regards,
Brian

TechAirlines - Journey into the World of Technology

grr

  • SCF VIP Member
  • *****
  • Posts: 64
  • KARMA: 12
Re: Warns from Microsoft: Huge number of Java attacks
« Reply #4 on: 25. October 2010., 09:01:58 »
thanks. I must also update my Java...

Samker's Computer Forum - SCforum.info

Re: Warns from Microsoft: Huge number of Java attacks
« Reply #4 on: 25. October 2010., 09:01:58 »

BGM

  • SCF Member
  • **
  • Posts: 36
  • KARMA: 5
Re: Warns from Microsoft: Huge number of Java attacks
« Reply #5 on: 02. November 2010., 13:58:23 »
Thanks for the update info.  Did have a small issue that attempted to run under Java , however the malware and firewall protection detected it. Did make sure that all Java updates were correctly installed :up:

Samker's Computer Forum - SCforum.info

Re: Warns from Microsoft: Huge number of Java attacks
« Reply #5 on: 02. November 2010., 13:58:23 »

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising