Showing posts with label Oracle Java. Show all posts
Showing posts with label Oracle Java. Show all posts

Saturday, 10 October 2015

Firefox Stops Java Support, But Flash Continues To Support


Like Google and Microsoft will also stop supporting Mozilla based on NPAPI plug-ins, but for Adobe Flash Player is an exception. According to Mozilla are plug-ins that the old Netscape Plug-in API (NPAPI) use responsible for performance issues, crashes and security incidents.

End 2016 Mozilla also wants to stop the support for most NPAPI plugins in Firefox. A process that was initiated some years ago, by letting users activate these plug-ins manually. In addition, the new 64-bit Firefox for Windows platform will be launched entirely without support plug-ins, because it is no longer needed by the browser developer.

Because Adobe Flash Player on so many websites use Mozilla continues this plug-in, as an exception to the rule, do support. "Mozilla and Adobe will continue to work to make improvements to the Flash experience within Firefox, among others in terms of stability and performance, and security features," said Mozilla's Benjamin Smedberg.

Java

He advises websites that use plugins such as Silverlight and Oracle Java to switch to web technologies. These plug-ins will be late next year would no longer supported. In the event websites can not be without, for example Java advised to develop the required features as a Firefox extension. In order to end of Java within Firefox run smoothly cooperates with Oracle there. So advises Oracle now on websites instead of Java applets, plug-in free solution such as Java Web Start to use.

Friday, 7 August 2015

American And British Companies Hacked Through Very Old Java Flaw



In recent years, American and British companies hacked a vulnerability in Java in 2011 has already been patched by Oracle. The attackers behind the attacks also are sent out zip files containing malware to their victims. That Dell SecureWorks announced.

To the companies through the old Java vulnerability to attack the attackers hacked some 100 sites that were visited by employees. It then went to websites of major production companies, embassies of countries in the Middle East, Europe and Asia in Washington DC and non-governmental organizations (NGOs). To ensure that only the right companies were attacked, the attackers used a whitelist. Based on IP address was determined whether users were attacked via the Java leak.

The group would also be other known vulnerabilities for which patches have been attacked available, but the Java vulnerability would have been particularly popular. Once access to the machine of a worker obtained a vulnerability in JBoss was used from 2010 to redirect the browser to other users to the attack code, so that the attackers gained access to other systems.

Social Engineering

Besides attacking known vulnerabilities, the attackers also used social engineering. So were targeted emails sent to targets with a zip file. The zip file contains both legitimate files as malware. As contained one of the zip files a PDF file, an image, and the malware was disguised as a file. Because no standard Windows file extensions display saw users in this case that the "picture" for instance ended in .exe.

According to Dell, the attackers had to cater for defense companies and were looking for information on US defense projects.Companies and organizations in other sectors, however, were also targeted. How many companies the attackers were able to compromise was not disclosed.

Monday, 13 July 2015

Targeted Attacks On Newly Discovered Java Leak


The Japanese anti-virus company Trend Micro warns of a new critical vulnerability in Java where no update is available for Oracle, which is used in attacks against American defense organization and a member of NATO. According to the virus fighter is about targeted attacks.

That would mean that the vulnerability is not yet widely used to infect home users with malware. For attacking the targets using the assailants emails with a link. The links used by the attackers appear on the left earlier in attacks against NATO members and the White House were deployed, says analyst Li Brooks . In this case the links were encountered in the emails to an American defense organization and a specific NATO member, but who exactly is going does not mean anti-virus company. The link points to a page that tries to make use of the Java leak. In the event that the attack is successful, there is placed on the computer malware.

Vulnerable

The vulnerability is present in the latest Oracle Java version, namely update Java 8 45. Older versions of Java, namely 6 and 7 are not vulnerable. Oracle would have been informed. In anticipation of an update enables users to Java in their browser off or the system removed . A few years ago were regularly called zero-day vulnerabilities found in Java and attacked which no update was available. According to Trend Micro, it is almost two years since the last zero-day Java was reported.

Saturday, 13 June 2015

Microsoft Sees Old Ask Toolbar As Unwanted Software


Microsoft security software sees old versions of the Ask Toolbar, which include the installation of Java is included, henceforth as unwanted software. Late last year, the software giant announced that measures would be taken against toolbars and other programs that change browser settings, unsolicited.

Toolbars for many users is a major source of annoyance. It also happens often that the default search engine users is adjusted and it is very difficult to change back the original engine. In late May Microsoft let them know that it was also customize this software. The new measures would take effect on June 1, and it seems that the software giant has kept his promise.

Old versions of the Ask Toolbar, given the large number of topics on its removal for many users a real plague , is now classified as unwanted software. This allows a user on Slashdot know, taking to an article in the malware encyclopedia indicates Microsoft. According to the description the Ask Toolbar Microsoft considers a "high threat" that can be removed by Windows Defender, Microsoft Security Essentials and Microsoft Safety Scanner.

Since the message on Slashdot the news was taken up by other media, which again for a response from Ask.com and Microsoft seems to have created. Indeed, there is an update posted in the encyclopedia, which now reported that the most recent version of the Ask Toolbar is not considered unwanted software.

Saturday, 18 April 2015

Oracle Is Silent On Ask Toolbar In Java Updates


Oracle does not want to know why the toolbar's search engine Ask.com combines with updates to Java and Ask.com will not talk about the cooperation with Oracle, as discovered a journalist from the LA Times. The newspaper interviewed a 71-year-old man who would have been about $ 450 spent to have it removed from his computer the Ask toolbar.

"It's just a bad guy who does not want to leave," Gary More informs, the man who for months has been trying to get the software from his computer. Also the helpdesk he turned has trouble. "They've tried everything. It's very, very difficult." When installing Java or Java updates will not install only the Ask Toolbar, but will Ask.com also the default search engine.Removing the toolbar would thereby offer no solution, since the search engine ever to Ask.com is put back.

"There is not really an easy way to remove it from your system and most people do not know how to do this," Eric Schlissel enables IT business GeekTek. The Ask Toolbar is labeled as adware by different parties. The toolbar uses the Ask search engine, which would be full of bad classified ads. Advertisements that are not of the "organic" results would be distinguished in most cases.

Reason for the LA Times to access Oracle, but the company does not know to want to respond to the Ask toolbar. Ask also wanted to give no official response. According Schlissel is all about money. "Nobody is more to Ask.com . So the only way to sell ads is by luring people there to. Oracle is paid by each downloaded toolbar by Ask or get a share of search traffic. "