Author Topic: Java Malware alert!  (Read 1358 times)

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
Java Malware alert!
« on: April 15, 2010, 06:54:44 AM »
I know many of you allow Java to run freely on your browsers, and those who use FireFox think they are bullet-proof, so I thought I would give you a heads up about a potential problem you might have.
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline uptown

  • Plutonium Member
  • *******
  • Posts: 8569
Re: Java Malware alert!
« Reply #1 on: April 15, 2010, 07:59:14 AM »
Thanks for the headsup  :salute
Lighten up Francis

Offline 1701E

  • Silver Member
  • ****
  • Posts: 1896
      • VBF-18 Bearcats
Re: Java Malware alert!
« Reply #2 on: April 15, 2010, 09:07:41 AM »
Yikes, glad I don't have java....just what I need is another stupid infection.  Getting tired of reformatting. :)
Thanks for the heads up Skuzz.
ID: Xcelsior
R.I.P. Fallen Friends & Family

"The only ones who should kill are those prepared to be killed"

Offline soda72

  • Platinum Member
  • ******
  • Posts: 5201
Re: Java Malware alert!
« Reply #3 on: April 15, 2010, 10:27:00 AM »
Quote
Disabling the Java plugin is not sufficient to prevent exploitation, as the toolkit is installed independently.

 :uhoh

Offline Ghastly

  • Silver Member
  • ****
  • Posts: 1756
Re: Java Malware alert!
« Reply #4 on: April 15, 2010, 11:03:54 AM »
I spent a some time 2 days ago on this, and I found

a) Our current installation of Eset's Nod32 (EAVBE, 4.2.40.0) quarantines the sample script - so I'd like to presume that it would protect you from an attempt to exploit - and I would like to assume that the retail version would to, although I didn't test it.
b) NoScript (with Firefox) will mitigate this, in that you have to enable scripting from the exploitive web site before it can run
c) removing npdeploykt.dll (or replacing it with another innocuous dll, which is what I did administratively to all of the workstations at work) prevents the exploit from deploying.

Also, I noticed that Java has released a new patch release (6.20) overnight - I'd like to assume that this is fixed, but haven't had time to confirm that.

<S>
Guy

"Curse your sudden (but inevitable!) betrayal!"
Grue

Offline Dragon

  • Platinum Member
  • ******
  • Posts: 7055
      • AH JUGS
Re: Java Malware alert!
« Reply #5 on: April 15, 2010, 02:21:55 PM »



Oh    Yippee.
SWchef  Lieutenant Colonel  Squadron Training Officer  125th Spartan Warriors

Offline 007Rusty

  • Gold Member
  • *****
  • Posts: 2634
Re: Java Malware alert!
« Reply #6 on: April 15, 2010, 02:28:02 PM »
fun fun  :banana:  thanks for the heads up  :aok
C.O. 444TH AIR MAFIA
 WD40 (FS0)
 

Offline Eagler

  • Plutonium Member
  • *******
  • Posts: 18755
Re: Java Malware alert!
« Reply #7 on: April 15, 2010, 02:38:49 PM »
"The main lure so far seems to be a song lyrics publishing site, with Rihanna, Usher, Lady Gaga and Miley Cyrus being used, among others."

good thing I know their lyrics by heart :)

j/k

thanks
Skuzzy
"Masters of the Air" Scenario - JG27


Intel Core i7-13700KF | GIGABYTE Z790 AORUS Elite AX | 64GB G.Skill DDR5 | 16GB GIGABYTE RTX 4070 Ti Super | 850 watt ps | pimax Crystal Light | Warthog stick | TM1600 throttle | VKB Mk.V Rudder

Offline soda72

  • Platinum Member
  • ******
  • Posts: 5201
Re: Java Malware alert!
« Reply #8 on: April 15, 2010, 05:14:08 PM »
Some how I can't picture Skuzzy listening to Lady Gaga..

 :lol
« Last Edit: April 15, 2010, 05:19:48 PM by soda72 »

Offline uptown

  • Plutonium Member
  • *******
  • Posts: 8569
Re: Java Malware alert!
« Reply #9 on: April 15, 2010, 05:25:04 PM »
Lady Gaga!? Oh no, the wifes computer will be locked up in no time.  :uhoh


Wait, that's a good thing.  :D
Lighten up Francis

Offline DREDIOCK

  • Plutonium Member
  • *******
  • Posts: 17775
Re: Java Malware alert!
« Reply #10 on: April 15, 2010, 08:23:43 PM »
Some how I can't picture Skuzzy listening to Lady Gaga..

 :lol

Not with the sound turned up anyway  :D
Death is no easy answer
For those who wish to know
Ask those who have been before you
What fate the future holds
It ain't pretty

Offline DREDIOCK

  • Plutonium Member
  • *******
  • Posts: 17775
Re: Java Malware alert!
« Reply #11 on: April 15, 2010, 08:32:39 PM »
Ok wheres a site. Im willing to play Guinea pig.
My daughter has gotten me to get pretty good at getting rid of these bastages.

BTW Facebook users. Beware of ads on facebook as some have recently been known to carry that windows security Trojan.

If your using firefox I suggest adding adblock as well as noscript
Death is no easy answer
For those who wish to know
Ask those who have been before you
What fate the future holds
It ain't pretty

Offline Denholm

  • Plutonium Member
  • *******
  • Posts: 9667
      • No. 603 Squadron
Re: Java Malware alert!
« Reply #12 on: April 16, 2010, 09:22:50 PM »
Thanks for the warning, Skuzzy. I doubt it, yet out of general curiosity, does this exploit manage to unload onto Linux systems?
Get your Daily Dose of Flame!
FlameThink.com
No. 603 Squadron... Visit us on the web, if you dare.

Drug addicts are always disappointed after eating Pot Pies.

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
Re: Java Malware alert!
« Reply #13 on: April 17, 2010, 06:12:35 AM »
It effects all versions of Sun's Java runtime, regardless of the OS.  However, the chances of the malware/spyware program being able to run on a Linux box is pretty low as virtually all these types of programs are written for Windows.
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline Changeup

  • Persona Non Grata
  • Platinum Member
  • ******
  • Posts: 5688
      • Das Muppets
Re: Java Malware alert!
« Reply #14 on: April 17, 2010, 06:10:51 PM »
"The main lure so far seems to be a song lyrics publishing site, with Rihanna, Usher, Lady Gaga and Miley Cyrus being used, among others."

good thing I know their lyrics by heart :)

j/k

thanks
Skuzzy

Wow....the artists with the most "issues"...how coincidental.  Lady Gaga is a trainwreck that only lacks a place to happen...and somehow I can't see Miley Cyrus's "Greatest Hits" on Skuzzy's Ipod...lol

V/r
Changeup



PS - If I knew any of their lyrics I would kick my own ass....Go buy some CRUE!!! lmao
« Last Edit: April 17, 2010, 06:15:09 PM by Changeup »
"Such is the nature of war.  By protecting others, you save yourself."

"Those who are skilled in combat do not become angered.  Those who are skilled at winning do not become afraid.  Thus, the wise win before the fight, while the ignorant fight to win." - Morihei Ueshiba