Latest Java poison romps on as ok.XXX4.net

Aug 28, 2012 by Nancy Owano report

(Phys.org)—Yet another Java-related computer threat, cross-platform, has been nailed by security researchers. An exploit was seen by FireEye researchers on Sunday, being hosted on a domain ok.XXX4.net. When successful, the exploit downloads and executes a malicious binary, which calls to another IP address/domain. The Java threat was reported by FireEye's security researcher Atif Mushtaq, who said on August 26 that the initial exploit "is hosted on a domain named ok.XXX4.net. Currently this domain is resolving to an IP address in China." Subsequent reports are that it was discovered on a server with a domain name that resolved to an IP address located in China, and that the malware once installed on systems attempted to connect to a command-and-control server believed to be in Singapore.

Numerous security watchers are calling this a worrying vulnerability in the latest version of Oracle's framework, which could get worse. The attackers have found a way to get at a vulnerability that affects the latest version of —Update 6—in order to infect computers with malware. More specifically, the affects Java 1.7 update 6.

Most recent Java run-time environments are vulnerable, added Mushtiuqe. "In my lab environment, I was able to successfully exploit my test machine against latest version of FireFox with JRE version 1.7 update 6 installed," he said.

Security experts warn that the exploit code works on several browsers and computer platforms. Once the initial attack is made, a second piece of software referred to as Poison Ivy is released that lets hackers gain control of the computer.

Numerous computer security firms are telling PC users to disable Java software until a patch is released. As of this writing, there was no patch from Oracle.

Oracle typically patches Java at given points throughout the year. The next patch is scheduled for October. The updates are supposed to be collections of for Oracle products. Oracle says on its site, however, that "Oracle will issue Alerts for vulnerability fixes deemed too critical to wait for distribution in the next Critical Patch Update."

As such, Java is gaining a dubious distinction as being not only globally ever-present but also among the apps most frequently exploited, taking its place on the throne alongside Adobe Reader and Flash. According to Oracle, 97% of enterprise desktops run Java. Under different circumstances, that factoid would sound far less menacing.

Explore further: Model will unlock mysteries of the voice

More information: blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html

Related Stories

Oracle Issues 36 Patches

Apr 18, 2007

The Critical Patch Update is among the smallest since Oracle began quarterly updates.

Recommended for you

Google Drive sports new view and scan enhancements

11 hours ago

(Phys.org) —Google Drive has a new look and functions. The makeover in Google Drive features scanning and interface enhancements that put the user into "card" mode. The enhancements make it easy for the ...

Model will unlock mysteries of the voice

May 22, 2013

Swedish researchers are leading the development of the world's first comprehensive model of the human voice, which could contribute to better voice care, voice prosthetics, talking robots and teaching opportunities.

Patented system better secures digitally stored data

May 21, 2013

(Phys.org) —Arizona State University computer scientist Gail-Joon Ahn has been granted a U.S. patent for a novel identity management system that helps protect personal identity information stored on digital devices.

UC Davis startup changes listening experience

May 20, 2013

Fifteen years of research at the University of California, Davis, is being turned into commercial products by Dysonics, a startup company based in San Francisco. Since becoming the first "graduate" from the Engineering Translational ...

User comments : 2

Adjust slider to filter visible comments by rank

Display comments: newest first

Expiorer
1 / 5 (1) Aug 28, 2012
like taking candy from a baby
kevinrtrs
1 / 5 (5) Aug 28, 2012
Seems like someone has it in for Oracle. Plenty of enemies around, what with Mr Ellison being so outspoken and definitely rubbing the competition up the wrong way.
The response will have to be really big - the company's future depends on it.

More news stories

Solar Kettle allows for boiling water off the grid

(Phys.org) —A company called Contemporary Energy has unveiled a new device it calls the Solar Kettle. It looks very much like a normal coffee thermos, but has flaps on one side that open to allow for collecting ...

Google Drive sports new view and scan enhancements

(Phys.org) —Google Drive has a new look and functions. The makeover in Google Drive features scanning and interface enhancements that put the user into "card" mode. The enhancements make it easy for the ...

Hormone replacement therapy—clarity at last

The British Menopause Society and Women's Health Concern have today released updated guidelines on Hormone Replacement Therapy (HRT) to provide clarity around the role of HRT, the benefits and the risks. The new guidelines ...

Controlling mood through the motions of mitochondria

(Medical Xpress)—Regulating the distribution of power in neurons is done by a system that makes the national electric grid look simple by comparison. Each neuron has several thousand mitochondria confined ...

A hidden population of exotic neutron stars

(Phys.org) —Magnetars – the dense remains of dead stars that erupt sporadically with bursts of high-energy radiation - are some of the most extreme objects known in the Universe. A major campaign using ...