• Home
  • Advertise
  • Contact Us
  • Free eBooks
  • Infographics
  • About Us


  • Technology
    • Programming
      • Java
      • PHP
      • HTML
      • CSS
      • Javascript
      • XML
      • AJAX
      • JQuery
      • Perl
      • IDE
    • CMS
      • Opencart
      • WordPress
      • Prestashop
      • Magento
    • Database
  • Security
    • Cyber Laws
    • Digital Signature
    • Passwords
    • Reverse Engineering
    • Steganography
    • Forensics
    • Networking
  • E-Commerce
  • Digital Media
    • SEO
    • Social Media
      • Facebook
  • Gadgets
    • Laptops
    • Tablets
    • Just CellPhones
    • Social CellPhones
  • OS
    • Linux
    • Mac
    • Windows
    • iOS
    • Android
  • Courses
    • Development in Android
  • General

Breaking

The supercomputer "Tianhe-2" Takes No. 1 Ranking on 41st TOP500 List

Export tweets in different formats

OWASP - Top 10 Vulnerabilities

New Windows-backdoor deletes MBR

The world's first CPU of 5GHz

Critical vulnerability in 60 + models of CCTV and IP-cameras

Hack a Samsung TV with SmartTV function

The man who "almost broke the Internet"

The search continues for the sixth member of LulzSec

Statistics on the botnet Carna


New Java Exploit questions the effectiveness of protection against exploits

0 Comment
 29 Jan 2013   Posted by synt4x

1 Star2 Stars3 Stars4 Stars5 Stars
Loading ... Loading ...


flattr this!

Rating:

Researchers have discovered vulnerabilities to bypass security settings of Java, designed to protect against hidden exploits.

java-exploit

Researchers from security company Security Explorations managed to find vulnerabilities in the security of Java, which are designed to provide protection against hidden exploits. The flaw allows potential attackers to bypass security restrictions and perform drive-by attack in the browser of the victim.

Note that the user needs the ability to specify the security settings introduced by developers in December last year in Java 7 Update 10. They allow you to set limits on the run Java applications in web-browser. This is the “rigorous” safety of the four possibly to block all applications that do not have a legitimate signature.

At the same time, the head of Security Explorations Govdiaka Adam (Adam Gowdiak) said that none of the proposed restrictions can resist intruders.

“What we found was to successfully run unsigned Java code on the target system, Windows , no matter what settings restrictions is set in Java Control Panel », – follows from the messages in Govdiaka SecLists.

The expert also noted that the precise confirmation of the breach is only available for Java 7 Update Version 11 for Windows 7. Currently, the relevant information about the vulnerability and PoC-code for it had already been sent to developers at Oracle.

Spread The Word:

  • Facebook
  • Twitter
  • Pinterest
  • StumbleUpon
  • Google +1
  • Digg
  • Reddit
  • Email
  • LinkedIn
  • Tumblr
    Share This


Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • Find Us On Facebook

  • Airtel Hello Tunes

  • Ads.

  • Ads.

  • Shrugs Online


  • More...

    • Advertise
    • Crawl Fashion | Fashion Directory
    • Information Technology Act 2000 Compliance [Sec 43A and Sec 72A]
    • Java Tutorial
    • Netbeans Tutorial
    • Photography Blogs
    • Street Shopping
    • Virus Protection And Internet Security
  • Recent Posts

    • OWASP - Top 10 Vulnerabilities
    • New Windows-backdoor deletes MBR
    • Critical vulnerability in 60 + models of CCTV and IP-cameras
    • Hack a Samsung TV with SmartTV function
    • The man who "almost broke the Internet"
    • The search continues for the sixth member of LulzSec
  • Enter your email address to subscribe to "Bytes" Mag & receive THE latest updates on Tech!


Copyright © LetsByteCode Inc.
DMCA.com
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.