Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Surprised? Old Java exploit helped spread Red October spyware (New Java exploit ....out)
The Register (UK) ^ | 16th January 2013 21:12 GMT | Neil McAllister in San Francisco

Posted on 01/17/2013 7:55:07 AM PST by Ernest_at_the_Beach

New Java exploit can be yours for $5,000

Unpatched Java installations may have helped spread the malware responsible for the recently uncovered "Red October" cyber-spying campaign, researchers at Seculert have revealed.

Kaspersky Labs first disclosed the existence of Red October on Monday, claiming that the program had been responsible for attacks on systems in Eastern European countries, former Soviet republics, and Central Asian nations over the last five years.

The primary vectors used to install the malware were emails containing attached documents that exploited vulnerabilities in Microsoft Word and Excel. Recipients who opened the documents became unwitting participants in the cyber-espionage scheme.

But further investigation by Seculert has revealed that Red October's masterminds had a backup plan – namely, installing the malware by directing users to a web page that exploited a known vulnerability in the Java browser plugin.

In a blog post on Tuesday, Seculert researchers explained that a special folder on the Red October command-and-control servers contained a PHP page that could exploit the Java flaw, causing the hapless victim's browser to download and execute Red October's "Rocra" malware automatically.

Similar exploits have made headlines in recent months, with hackers and security researchers exposing a seemingly endless series of Java vulnerabilities that could allow attackers to compromise client machines. Occasionally, researchers have discovered sites that actively exploit these flaws in the wild.

In the case of Red October, the specific vulnerability targeted was an old one, CVE-2011-3544, which Oracle fixed with a Critical Patch Update in October 2011.

It may seem strange that Red October's authors would go after such an ancient flaw, given that their exploit code was compiled in February 2012, well after a fix had already been issued. But these Java vulns have a way of lingering around on unpatched machines.

In fact, CVE-2011-3544 was one of the Java vulnerabilities used to spread the Mac-specific Flashback Trojan in early 2012. One of the reasons that attack was so successful was because at the time, security fixes for Apple's Mac OS X–specific version of Java tended to lag behind fixes for the mainline version.

Even Oracle has been known to take its sweet time patching potentially risky Java bugs. In August 2012, Adam Gowdiak of Polish firm Security Explorations revealed that although he had promptly informed Oracle of several serious vulnerabilities he had discovered, the database giant dragged its feet for more than four months before issuing patches, a delay that gave cyber-crooks time to discover and exploit the flaws. And even then, Oracle's fix didn't fully address the problem.

Metasploit founder HD Moore claims it will likely take Oracle two years to get its Java security house in order, given its past track record. Little wonder, then, that no less than the US Department of Homeland Security has cautioned users to disable Java in their browsers "unless it is absolutely necessary."

According to Seculert, Java flaws probably weren't involved in most Red October infections, but only because a misconfigured server disabled the PHP code that would have delivered the exploit.

If hackers were looking for a new way to keep Red October going, however, it wouldn't be hard to find one. On Sunday, security researchers announced that a new, unpatched Java security hole had already been discovered following Oracle's most recent patch, and that one enterprising hacker was offering to sell an exploit kit at a price of $5,000 a throw. ®


TOPICS: Business/Economy; Crime/Corruption; News/Current Events
KEYWORDS: java; malware; microsoft; oracle

1 posted on 01/17/2013 7:55:16 AM PST by Ernest_at_the_Beach
[ Post Reply | Private Reply | View Replies]

To: Ernest_at_the_Beach

I have programs that are Java dependent. Oh well . . .


2 posted on 01/17/2013 7:57:44 AM PST by BipolarBob (Happy Hunger Games! May the odds be ever in your favor.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

fyi


3 posted on 01/17/2013 7:58:59 AM PST by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 1 | View Replies]

To: BipolarBob

Do you keep personal data on the same computer?


4 posted on 01/17/2013 8:07:21 AM PST by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 2 | View Replies]

To: Ernest_at_the_Beach

I have always hated Java. I hate it even more now.


5 posted on 01/17/2013 8:08:18 AM PST by E. Pluribus Unum (TYRANNY: When the people fear the politicians. LIBERTY: When the politicians fear the people.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
CVE-2011-3544 was one of the Java vulnerabilities used to spread the Mac-specific Flashback Trojan in early 2012. One of the reasons that attack was so successful was because at the time, security fixes for Apple's Mac OS X–specific version of Java tended to lag behind fixes for the mainline version.

Mac Purists will descend on the thread in 5, 4, 3...

6 posted on 01/17/2013 8:10:33 AM PST by Old Sarge (We are officially over the precipice, we just havent struck the ground yet...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Yes I do.


7 posted on 01/17/2013 9:10:30 AM PST by BipolarBob (Happy Hunger Games! May the odds be ever in your favor.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: rdb3; Calvinist_Dark_Lord; Salo; JosephW; Only1choice____Freedom; amigatec; stylin_geek; ...

8 posted on 01/17/2013 10:51:13 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #9 Removed by Moderator

To: moder_ator
While I appreciate your zeal for your job, and looking out for those of us who may double post, #9 was, in fact, not a duplicate post.

Post #9 was a ping to the second half of my ping list.

Thank you.

10 posted on 01/17/2013 11:13:53 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 8 | View Replies]

To: AdmSmith; Big Giant Head; grey_whiskers; Brandybux; dfwright; Bikkuri; Dacula; BuddaBudd; mbj; ...

11 posted on 01/17/2013 11:14:56 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Bookmark.


12 posted on 01/17/2013 11:25:36 AM PST by The Cajun (Sarah Palin, Mark Levin......Nuff said.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: E. Pluribus Unum

I suggest that everyone install the add-on “QuickJava” for their browser. I know it is available for FireFox, and is likely available for others.

It provides a row of buttons on the bottom edge of the browser window for each of: Java, JavaScript, Flash, Silverlight, CSS, and some others. It is a snap to enable/disable those features for any web site.

I almost always run with Java disabled, but occasionally will allow it. I have never enabled Silverlight. It is often interesting to disable CSS. Disabling Flash provides some better security for some pages, as well as faster loading times. For some sites, loading with “images” disabled greatly speeds up access.

Try QuickJava - I bet you will like it and hate Java less!


13 posted on 01/17/2013 11:44:02 AM PST by AFPhys ((Praying for our troops, our citizens, that the Bible and Freedom become basis of the US law again))
[ Post Reply | Private Reply | To 5 | View Replies]

To: AFPhys
Just installed it. We'll see.
14 posted on 01/17/2013 11:46:04 AM PST by E. Pluribus Unum (TYRANNY: When the people fear the politicians. LIBERTY: When the politicians fear the people.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Ernest_at_the_Beach

I’m not high tech at all. What do I now with this Java problem? Seems like a lot of stuff needs Java to run properly.


15 posted on 01/17/2013 7:31:29 PM PST by PapaNew
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach; B4Ranch

Bump


16 posted on 01/18/2013 9:47:45 AM PST by tubebender (Evening news is where they begin with "Good Evening," and then proceed to tell you why it isn't.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce; AFPhys

Now I’ve got a popup to install Java 1.7.0_11. Should I or should I not install?

I’m not high tech at all.

What should I do with this Java problem? Seems like a lot of stuff needs Java to run properly.


17 posted on 01/19/2013 7:56:55 PM PST by PapaNew
[ Post Reply | Private Reply | To 13 | View Replies]

To: PapaNew

NO NO NO NO NO

DO NOT INSTALL JAVA THROUGH THE POPUP

IT IS A VIRUS EXPLOIT !!!!!

Sorry I didn’t see this earlier. I hope I am in time.

See link here:
http://dottech.org/93867/beware-of-fake-java-update-patch-it-contains-malware/


18 posted on 01/19/2013 10:34:53 PM PST by AFPhys ((Praying for our troops, our citizens, that the Bible and Freedom become basis of the US law again))
[ Post Reply | Private Reply | To 17 | View Replies]

To: AFPhys
Thanks for the heads up. Fortunately, I didn't install it.

Seems like I need Java for all the video stuff I watch on the computer. Awhile back, I disabled Java and all the video stuff (live streaming, YouTube, weather.com, MLB, NFL, etc.) had problems. When I reinstalled/reenabled Java, things seemed to run better.

So it seems like Java helps things to run, but it sounds like there are some kind of virus risks with Java. Down to either my computer doesn't work well without Java or gets a virus with Java and doesn't work at all. Not good choices here. Any suggestions?

19 posted on 01/20/2013 7:11:36 AM PST by PapaNew
[ Post Reply | Private Reply | To 18 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson