1. This is your standard take-victims-to-a-malicious-Web-page kind of
attack. Why the excitement? Because of the high danger of the breach? What?
This vulnerability in Java is the second one in the last 6 months (first one
on August 29, 2012).
The problem with Java is that it is cross platform and it is installed on
over 1 billion devices (according to Oracle) on a multitude of platforms and
operating systems. If something so wide-spread like Java gets affected and
misused to spread malware or worse (imagine what an impact would a DDOS
started by this would have) it is absolutely normal to be so much in the
2. Oracle’s fix switches Java security settings to high by default. This
requires users to expressly authorize the execution of applets which are
either unsigned or self-signed. Doesn’t any decent AV system already do that
if it’s set up to do that by the user?
Not necessarily the AV software should do this. That there are millions of
applets out there which are not signed or self-signed. If the AV producers
would only report something like this, they would do nothing else than
whitelist these applets.
In my opinion it is the responsibility of the platform (Java in this case)
to have such a configurable functionality built-in.
3. US-CERT recommends that users temporarily disable Java even after
applying Oracle’s Java 7 Update 11 unless it’s absolutely necessary to run
Java in Web browsers. It also says there’s potentially a bug in the Java
installer. And it states that there have been situations where Java will
crash if it’s been disabled in the Web browser after being updated to &u11
and then re-enabled, and needs a reinstall.
So has Oracle done enough? What doesn’t the fix do? What more should Oracle
In my opinion, Oracle did what any software company would do under high
pressure: the minimum necessary to solve the problem.
With each such vulnerability they are in the news, they lose market share in
favor of Microsoft (Silverlight) and Adobe(Flash).
But, when developing critical software under pressure has only one
consequence: even more bugs.
I am expecting to see soon even more bugs and vulnerabilities related to
this quick fix or similar to it.
I can’t say what the fix doesn’t do as I don’t know the internals of Java.
I can say, however, what it should do: it should mitigate all possible
attack vectors so that on the long term they make the platform secure by
design, default and deployment.
On the long term, I think that the best thing what Oracle should do is to
rethink its entire software development strategy.
Java is something that was acquired and was developed during many years by
many people. In time, this means that the code has become close to
impossible to maintain.
4. Apparently there’s already malicious code in the wild that exploits this
vulnerability and thousands of people have been affected, or so it seems. Is
We don’t have exact data, but considering how wide-spread Java is, it is to
be expected that many people got affected without knowing it.
If somebody used this vulnerability to spread new malware, it is possible
that we will see in the medium term future some malware like Stuxnet or
Think of it like a targeted malware attack. It is not needed to infected
millions, it is enough to infected only those who matter.
5. What can victims who’ve been affected do? Reinstall their systems
Everybody who was in contact with Java in a browser (applets) should keep an
eye on their systems.
Any suspicious activity like increased CPU activity, network traffic or hard
drive activity should be reported to system administrators and AV producers
In case of important systems where it is not acceptable to risk anything
(systems managing PII, life critical systems, industrial systems) it is
advisable to reinstall (or revert) the system in order to achieve maximum
6. What steps should businesses and consumers take to protect themselves?
First of all, analyze if they really need Java. If not, uninstall it from
all computers in your company.
If you do need it, consider the advices written here
and in the other articles referenced in it.
© Copyright 2013 Sorin Mustaca, All rights Reserved. Written For: Sorin Mustaca on Cybersecurity
Check www.mustaca.com for the IT Consulting services I offer.
Visit www.itsecuritynews.info for latest security news in English
Besuchen Sie http://de.itsecuritynews.info für IT Sicherheits News auf Deutsch