PCDVD數位科技討論區
PCDVD數位科技討論區   註冊 常見問題 標記討論區為已讀

回到   PCDVD數位科技討論區 > 其他群組 > 七嘴八舌異言堂
帳戶
密碼
 

  回應
 
主題工具
E.A.G.Y.O.O
Advance Member
 

加入日期: Mar 2010
文章: 492
美國警告!立即解除電腦Java,免遭駭客入侵,自遠端執行指令

2013年01月11日19:21

美國國土安全部轄下的電腦資安單位CERT周日發布警告,Java升級10及之前的版本因出現漏洞,提醒下載java軟體的使用者,最好立即解除安裝,避免遭駭客入侵,自遠端執行任意指令。



美國CERT在官網發布警告,提醒消費者最好解除Java安裝。翻攝CERT網頁
     
      
舊 2013-01-12, 02:46 AM #1
回應時引用此文章
E.A.G.Y.O.O離線中  
chaotommy
Elite Member
 

加入日期: Mar 2003
您的住址: Vancouver, Canada
文章: 15,006
三個難兄難弟
Java & Acrobat & Flash
 
舊 2013-01-12, 03:02 AM #2
回應時引用此文章
chaotommy離線中  
ALPHONSE2501
Major Member
 
ALPHONSE2501的大頭照
 

加入日期: Jul 2005
您的住址: 加利福尼亞共和國
文章: 158
United States Computer Emergency Readiness Team


Vulnerability Note VU#625617 - Java 7 fails to restrict access to privileged code


引用:
Overview

Java 7 Update 10 and earlier contain an unspecified vulnerability that can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.



Description

The Oracle Java Runtime Environment (JRE) 1.7 allows users to run Java applications in a browser or as standalone programs. Oracle has made the JRE available for multiple operating systems.

The Java JRE plug-in provides its own Security Manager. Typically, a web applet runs with a security manager provided by the browser or Java Web Start plugin. Oracle's document states, "If there is a security manager already installed, this method first calls the security manager's checkPermission method with a RuntimePermission("setSecurityManager") permission to ensure it's safe to replace the existing security manager. This may result in throwing a SecurityException".

By leveraging unspecified vulnerabilities involving Java Management Extensions (JMX) MBean components and sun.org.mozilla.javascript.internal objects, an untrusted Java applet can escalate its privileges by calling the the setSecurityManager() function to allow full privileges, without requiring code signing. Oracle Java 7 update 10 and earlier are affected.

This vulnerability is being attacked in the wild, and is reported to be incorporated into exploit kits. Exploit code for this vulnerability is also publicly available.


Impact

By convincing a user to visit a specially crafted HTML document, a remote attacker may be able to execute arbitrary code on a vulnerable system.
Solution

We are currently unaware of a practical solution to this problem. Please consider the following workarounds:

Disable Java in web browsers

Starting with Java 7 Update 10, it is possible to disable Java content in web browsers through the Java control panel applet. Please see the Java documentation for more details.
Note: Due to what appears to potentially be a bug in the Java installer, the Java Control Panel applet may be missing on some Windows systems. In such cases, the Java Control Panel applet may be launched by finding and executing javacpl.exe manually. This file is likely to be found in C:\Program Files\Java\jre7\bin or C:\Program Files (x86)\Java\jre7\bin.
Also note that we have encountered situations where Java will crash if it has been disabled in the web browser as described above and then subsequently re-enabled. Reinstalling Java appears to correct this situation.

__________________
舊 2013-01-12, 03:42 AM #3
回應時引用此文章
ALPHONSE2501離線中  
Joss
*停權中*
 
Joss的大頭照
 

加入日期: Dec 2002
文章: 512
看來我還是把 JRE 刪掉比較保險些。
舊 2013-01-12, 10:19 AM #4
回應時引用此文章
Joss離線中  
DeepGreen
*停權中*
 

加入日期: Oct 2008
文章: 16
1. 你要有裝有Bug的java vm
2. 你要被引導到釣魚網站
3. 釣魚站上要剛剛好有攻擊這個漏洞的java applet
這不是重大流程或規格瑕疵造成的問題
很快就會被修復, 沒攻擊價值
舊 2013-01-12, 10:20 AM #5
回應時引用此文章
DeepGreen離線中  
u8526425
Elite Member
 

加入日期: Oct 2002
文章: 4,803
Java 7真的被攻很多次了
部份網站都建議使用者停留在Java 6比較安全
但是Java 6即將停止更新...現在到底是怎樣...
__________________
人性的醜陋就是,會在無權、無勢、善良的人身上挑毛病,卻在有權、有勢、缺德的人身上找優點。當無權、無勢、善良的人受到傷害的時候,還會站在所謂的道德制高點上,假惺惺地勸說無權、無勢、善良的人,一定要忍耐,一定要大度。
舊 2013-01-12, 03:43 PM #6
回應時引用此文章
u8526425離線中  
octapult
Junior Member
 
octapult的大頭照
 

加入日期: Aug 2005
您的住址: 木葉忍者村
文章: 735
還好我的 Java plugin 還停留在 1.6...
奇怪的是這個不是會自動更新的嗎?

Linux 底下用的則是 IcedTea Java
舊 2013-01-12, 08:35 PM #7
回應時引用此文章
octapult離線中  
AARONN
*停權中*
 

加入日期: Dec 2006
文章: 432
真的嗎?? 我好怕呀....我電腦裡可是有近一百TB的愛情動作片耶...

萬一這些心血毀於一旦,該怎麼辦?? 十年心血呀~~

此文章於 2013-01-12 08:40 PM 被 AARONN 編輯.
舊 2013-01-12, 08:39 PM #8
回應時引用此文章
AARONN離線中  
ghostman
Senior Member
 
ghostman的大頭照
 

加入日期: Jul 2002
您的住址: 台北市
文章: 1,176
引用:
作者AARONN
真的嗎?? 我好怕呀....我電腦裡可是有近一百TB的愛情動作片耶...

萬一這些心血毀於一旦,該怎麼辦?? 十年心血呀~~

你還是擔心你老母發現會怎麼樣想吧!
舊 2013-01-12, 08:47 PM #9
回應時引用此文章
ghostman離線中  
k2島民
*停權中*
 

加入日期: Feb 2011
文章: 346
引用:
作者u8526425
Java 7真的被攻很多次了
部份網站都建議使用者停留在Java 6比較安全
但是Java 6即將停止更新...現在到底是怎樣...


疑?Java 6比較安全??
我看了這篇後還傻傻的更新到Java 7,只因為沒在Java 6的控制台看到他說的安全選項
舊 2013-01-12, 09:02 PM #10
回應時引用此文章
k2島民離線中  


    回應


POPIN
主題工具

發表文章規則
不可以發起新主題
不可以回應主題
不可以上傳附加檔案
不可以編輯您的文章

vB 代碼打開
[IMG]代碼打開
HTML代碼關閉



所有的時間均為GMT +8。 現在的時間是06:01 AM.


vBulletin Version 3.0.1
powered_by_vbulletin 2025。