Access and Feeds

Technology: Java Security Under Attack

By Dick Weisinger

The more widely used software is, the bigger the target it becomes for hackers.  In the same way that Microsoft’s IE and Adobe’s Flash have been aggressively targeted in the past, Oracle’s Java has become a popular target of hackers just for that reason.  A report from the TIOBE Programming community finds that Java is popular — Java was tied with the C programming language as the most popular language of choice used by developers in 2012.

The list of Java exploits and security flaws has multiplied of late, with many of the problems being found with the run-time version of the language used by browser plug-ins.

In early January, the discovery of two ‘zero-day’ Java exploits were announced.  A partial patch was released shortly after the announcement of the discovery, but was criticized by some as not being sufficient to fix the problems.

A little later, in mid-January, Russian security firm Kaspersky Lab announced the discovery of malware they’d discovered that they believe was used as part of a campaign to steal information from high-profile diplomatic, military and government targets in as many as 39 different countries, with most of the incidents occurring in Eastern Europe, but also with targets in Western Europe and North America.  The campaign was dubbed Red October, and some believe that it may have been going on for more than five years.  Red October was based in part on security flaws found in earlier unpatched versions of Java.  Red October affected smart phones, Cisco network equipment, removable disk drives, Outlook email databases, and FTP servers.

Then, a few days later in January, word began circulating of code being sold by hackers that could exploit another unpatched Java flaw for $5000.

HD Moore, Metasploit project founder, commented that Oracle may need two years to fix some of the problems that have been uncovered, even if no additional problems appear.  His estimate is “based on the types of problems that have been found in Java over the last 12 months, namely sandbox escapes [achieved] by abusing reflection APIs.  These types of flaws are difficult to find and sometimes even harder to fix. Oracle has already spent a year working through these issues based on the initial Security Explorations report, but will likely need another two years to fix them completely,” according to comments made to John Leyden of the Register.
Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*