Jlhoffman Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 12 January 2013

Reacting To JAVA Vulnerability Media Hysteria!

Posted on 14:01 by Unknown

Recently there have been several stories in the media about a zero-day exploit vulnerability in Java.  I think it’s appropriate to fill in some of the details a little to limit any undue excitement out there.

Yes, several recent versions of Java have this zero day vulnerability.  The vulnerability affects Java 7 (1.7.0 and up). It does not affect Java 6 and earlier.  This vulnerability has been around since at least October when Oracle released an incomplete patch to fix the problem.  Earlier versions of Java do NOT have this vulnerability so it depends upon which Java release is loaded on your PC.

 Is this a serious problem?
We think it’s being over-hyped because it’s been around for a few months with little impact so far.  But!  The vulnerability is serious and based upon the pressure on Oracle to fix it, there should be a fix out pretty quickly. 

NOT EVERYONE HAS THE VULNERABLE VERSION OF JAVA LOADED.  You may not be vulnerable if you’re running any version of Java earlier than Java 1.7.0.
 
What does Java do?
It's a plug-in utility that most web site authors use to enhance features on their web sites to make them more interactive and user friendly.  It's also used in many browser-based programs that may run on a computer network.

 How do I know which version of Java I am using?

http://javatester.org/version.html  will give you that information.

Is this a Microsoft Windows thing? 

No, almost all browsers on all operating systems including Windows, Apple OS X, and Linux are vulnerable because Java is used by them all.

How are you exposed?

Visiting a web site infected with malware that use this exploit can lead to infection by any number of malicious programs that can launch Denial of Service attacks, steal information or propagate spam using your computer.

What can you do?

 At the extreme, you can disable the Java plugin  in your browser(s).  Here’s a link to do that but we don’t recommend it. 

 Here is the link to disable Java:   http://www.java.com/en/download/help/disable_browser.xml

This is an extreme reaction to the problem but if you visit a lot of new web sites each day and are concerned, this will reduce your exposure until the patch is released.  Be aware, though, that many web sites rely on Java to run correctly so you’ll probably not be able to access some sites if you do this.
 
Another alternative is to uninstall Java 7 (1.7) using your Add/Remove Programs option in Control Panel in Windows and the load an earlier version.  You can remove Java 1.7 and then install an earlier version:

Here is a link to the old version of the 32 bit download: http://www.filehippo.com/download_jre_32/13883/

And the 64 bit version:  http://www.filehippo.com/download_jre_64/13884/

This will allow you to use Java but not the most recent version when browsing.  Be aware that when you are prompted to update Java, say “No” because Java is a program that will keep trying to update itself.  Don’t say “Yes” until the patch release is announced by Oracle.

The final alternative is to just wait until next week and limit your use of unfamiliar web sites on the Internet.

Unfortunately, there’s no easy way for us to release a mass update to all of your computers to fix this but hopefully this will ease your concerns a little.

 Thanks

 Jeff and the gang at ACT
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Ransomeware Now #1 MalwareThreat - Learn More Here
    I just read an outstanding white paper from a couple of researchers at Sophos Security outlining how Ransomware is passing up FakeAlert malw...
  • Computer Support Rates - When Cheap Really Isn't
    What's in a labor rate?  Why are some IT companies more expensive than others?  Our company is neither the most expensive in our market ...
  • Server Configuration - Heaven Save Us From Well-Meaning Amateurs!
    How do I tell the client what their old tech did to them?  They've got to spend a bunch of money to correct the mess he made and I'm...
  • When It's Time To Fire A Customer
    What?  Isn't that backwards?  Isn't it the customer that usually does the firing? Usually, as business people, we work so hard to fi...
  • Using Personal Computers In the Workplace
    At ACT, we support a great many organizations that allow employees to use their own computers at work.  Sadly, I've noticed that some of...
  • What to do with Windows XP
    Well, it had a good long run.  Windows XP is now 13 years old.  In less than 10 months Microsoft is pulling the plug on our old friend XP.  ...
  • Wireless Networking Is Due For A Big Jump In Performance
    Just when we were getting comfortable with the 802.11n wireless standard, here comes a newer and better wireless solution - 802.11ac.  It wi...
  • Documentation - The Key To Client Support Success
    Recently, we won the trust of a new client that was unhappy with the service provided by their previous IT company.  After the client notifi...
  • Going to the Cloud is easy, getting out is a lot tougher!
    Everyone is pushing you to take your business to the cloud, right?  It's easy, right?  The sales rep used all the right words in his pit...
  • Support for Windows XP and Office 2003 stops on April 8th.
    All Microsoft support for Windows XP and Office 2003 stops on April 8th. What are the risks to your business if you don't upgrade? Let...

Blog Archive

  • ▼  2013 (39)
    • ►  November (3)
    • ►  October (4)
    • ►  September (2)
    • ►  August (4)
    • ►  July (3)
    • ►  June (9)
    • ►  May (3)
    • ►  April (3)
    • ►  March (6)
    • ▼  January (2)
      • Reacting To JAVA Vulnerability Media Hysteria!
      • Reflecting on 24 Years As President of ACT
  • ►  2012 (12)
    • ►  December (2)
    • ►  November (8)
    • ►  October (2)
Powered by Blogger.

About Me

Unknown
View my complete profile