{"id":3561,"date":"2013-01-21T07:00:23","date_gmt":"2013-01-21T15:00:23","guid":{"rendered":"http:\/\/www.formtek.com\/blog\/?p=3561"},"modified":"2013-01-21T07:00:23","modified_gmt":"2013-01-21T15:00:23","slug":"technology-java-security-under-attack","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/technology-java-security-under-attack\/","title":{"rendered":"Technology: Java Security Under Attack"},"content":{"rendered":"<p>The more widely used software is, the bigger the target it becomes for hackers. \u00a0In the same way that Microsoft&#8217;s IE and Adobe&#8217;s Flash have been aggressively targeted in the past, Oracle&#8217;s Java has become a popular target of hackers just for that reason. \u00a0A <a title=\"TIOBE Programming Community survey of language choice\" href=\"http:\/\/www.tiobe.com\/index.php\/content\/paperinfo\/tpci\/index.html\" target=\"_blank\">report from the TIOBE Programming community<\/a> finds that Java is popular &#8212; Java was tied with the C programming language as the most popular language of choice used by developers in 2012.<\/p>\n<p>The list of Java exploits and security flaws has multiplied of late, with many of the problems being found with the run-time version of the language used by <a title=\"Which Java has a problem?\" href=\"http:\/\/www.informationweek.com\/security\/vulnerabilities\/java-security-warnings-cut-through-the-c\/240146598\" target=\"_blank\">browser plug-ins<\/a>.<\/p>\n<p>In early January, the discovery of <a title=\"Zero-day exploits for Java\" href=\"http:\/\/www.informationweek.com\/security\/attacks\/java-under-attack-again-disable-now\/240146082\" target=\"_blank\">two &#8216;zero-day&#8217; Java exploits<\/a> were announced. \u00a0A partial patch was released shortly after the announcement of the discovery, but was criticized by some as not being sufficient to fix the problems.<\/p>\n<p>A little later, in mid-January, Russian security firm <a title=\"Red October security flaw\" href=\"http:\/\/www.zdnet.com\/red-october-hackers-also-used-java-exploit-for-spy-campaign-7000009881\/\" target=\"_blank\">Kaspersky Lab announced the discovery of malwar<\/a>e they&#8217;d discovered that they believe was used as part of a campaign to steal information from high-profile diplomatic, military and government targets in as many as 39 different countries, with most of the incidents occurring in Eastern Europe, but also with targets in Western Europe and North America. \u00a0The campaign was dubbed <a title=\"Red October announced\" href=\"http:\/\/www.theregister.co.uk\/2013\/01\/16\/red_october_java_connection\/\" target=\"_blank\">Red October<\/a>, and some believe that it may have been going on for more than five years. \u00a0Red October was based in part on security flaws found in earlier unpatched versions of Java. \u00a0Red October affected smart phones, Cisco network equipment, removable disk drives, Outlook email databases, and FTP servers.<\/p>\n<p>Then, a few days later in January, <a title=\"Buy Java exploit for $5000\" href=\"http:\/\/www.technewsworld.com\/story\/77108.html\" target=\"_blank\">word began circulating of code<\/a> being sold by hackers that could exploit another unpatched Java flaw for $5000.<\/p>\n<div id=\"_mcePaste\"><a title=\"HD Moore bio\" href=\"http:\/\/www.linkedin.com\/in\/hdmoore\" target=\"_blank\">HD Moore<\/a>,\u00a0Metasploit project founder, commented that Oracle may need two years to fix some of the problems that have been uncovered, even if no additional problems appear. \u00a0His estimate is &#8220;based on the types of problems that have been found in Java over the last 12 months, namely sandbox escapes [achieved] by abusing reflection APIs. \u00a0These types of flaws are difficult to find and sometimes even harder to fix. Oracle has already spent a year working through these issues based on the initial Security Explorations report, but will likely need another two years to fix them completely,&#8221;<a title=\"John Leydon article on Java exploits in the UK Register\" href=\"http:\/\/www.theregister.co.uk\/2013\/01\/18\/fake_java_update\/\" target=\"_blank\"> according to comments made to John Leyden<\/a> of the Register.<\/div>\n<div><\/div>\n<div>\n<div><\/div>\n<\/div>\n<div><\/div>\n<div>\n<div><\/div>\n<\/div>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Ftechnology-java-security-under-attack%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>The more widely used software is, the bigger the target it becomes for hackers. \u00a0In the same way that Microsoft&#8217;s IE and Adobe&#8217;s Flash have been aggressively targeted in the past, Oracle&#8217;s Java has become a popular target of hackers<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/technology-java-security-under-attack\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36],"tags":[],"class_list":["post-3561","post","type-post","status-publish","format-standard","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/3561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=3561"}],"version-history":[{"count":0,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/3561\/revisions"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=3561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=3561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=3561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}