0-day exploit of Java via browser in the wild

MrColin

Platinum Member
May 21, 2003
2,403
3
81
http://www.theregister.co.uk/2012/08/27/disable_java_to_block_exploit/

Although the actual source of the exploit is not known, it was originally discovered on a server with a domain name that resolved to an IP address located in China. The malware it installed on compromised systems attempted to connect to a command-and-control server believed to be located in Singapore.

Oracle has yet to comment on the vulnerability or when users should expect a fix, but it might be a while. The database giant ordinarily observes a strict thrice-annual patch schedule for Java, and the next batch of fixes isn't due until October 16.
 

weovpac

Golden Member
Apr 12, 2000
1,381
0
76
But really, everyone should seriously consider disabling the Java plug-in in their browser and only enabling it when they absolutely need to. Most people don't need it turned on at all and they're just unnecessarily exposing themselves.

Indeed, in Firefox it is easy. about:addons => Plugins => click the Disable button for Java
 

MrColin

Platinum Member
May 21, 2003
2,403
3
81
I disabled it from "about:plugins" in the url bar for opera, chrome, and firefox. In IE its under "Internet Options" > Programs Tab > Manage Add-ons.