Showing posts with label Java Exploit. Show all posts
Showing posts with label Java Exploit. Show all posts

Wednesday, 13 May 2015

Website Chef Jamie Oliver Hacked For Third Time


Attackers are there for the third time succeeded in hacking the website of the British chef Jamie Oliver and use for distributing malware. Previously it had been hit in February and March . As with these incidents the attackers malicious code added to jamieoliver.com.

This code sends visitors unnoticed to another website through which uses known vulnerabilities in Adobe Flash Player and Java to infect visitors with malware. It is malware that attempts to steal passwords. In case the software of visitors up-to-date, they are not at risk. The team that know the website of Oliver would be responsible of the incident and take measures to solve the "once and for all", says anti-virus company Malwarebytes . How the attackers were able to gain access to site is unknown.

Sunday, 15 March 2015

Website Chef Jamie Oliver Spreading Malware Again


The website of the British chef Jamie Oliver has been hacked again and again spreading malware. The site places attackers malicious code that visitors unnoticed forward to another site. This site contains the Fiesta exploitkit which makes abuse of vulnerabilities in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. In addition, the malware is signed, even though the certificate used now no longer valid, as reported anti-virus company Malwarebytes. The virus fighter discovered the first hack the website and then warned webmasters that it fixed the problem. Or so it seemed.

The structure used by the attackers to now placed malicious code is very similar to that of the first attack. "That's why we think this is the same infection that was not completely removed or perhaps that a vulnerability in the server or content management system (CMS) is still present," said the researchers. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Wednesday, 21 January 2015

Oracle Java SSL 3.0 Switches Off


To protect users from attack Java, Oracle SSL 3.0 disabled in the software. The measure is part of the security update that appeared Tuesday. "This Critical Patch Update disables the standard use of SSL 3.0. SSL 3.0 will be considered an obsolete protocol and this situation is exacerbated by the POODLE-leak. As a result, this protocol widely attacked by malicious hackers," says Eric Maurice Oracle.

The POODLE-vulnerability in SSL 3.0 ensures that an attacker who between a user and the Internet to know places, for example in an open Wi-Fi network, can steal information from encrypted connections, such as session cookies. Maurice gives organizations advised to discontinue use of all SSL versions, as it is no longer the safe communication between systems can be trusted.

Also Oracle customers have to change their code and switch to a more secure protocol such as TLS 1.2. Oracle employee further notes that Oracle in the future SSL in all Oracle software will turn off. Besides disabling SSL 3.0 update also fixes 19 vulnerabilities in Java, which in the worst case, an attacker can give full control over the system.