This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here

 

New Java exploit details emerge as attacks escalate; no patch from Oracle yet

By Peter Gothard

28 Aug 2012

View Comments
Java logo

While java hacks are an almost weekly occurrence, a zero-day exploit discovered yesterday looks set to become unusually disruptive, as Oracle has so far offered no solution, and experts are  recommending users turn off Java off unless absolutely necessary.

Threat research company DeepEnd Research approached Java expert Michael Schierl for an in-depth analysis, which has confirmed that Internet Explorer, Mozilla Firefox and even Google Chrome – for a while considered immune – are all under threat from the exploit.

Further reading

The exploit affects all versions of Java 7, and with Oracle's next scheduled Java update not due until 16 October, fears are running high that the exploit will soon cause widespread problems in the wild.

DeepEnd Research said it decided to publish its research on the exploit after exploit groups such as Metasploit and Blackhole published proof that exploit packs were being built.

"We decided that witholding details of the exploit will not offer additional protection but only hinder development of protection and signatures," said DeepEnd.

Revelations from Schierl's research for DeepEnd include a method of abusing restricted package permissions which, said the software engineer, "is new to me", as well as the finding that the vulnerability seems to focus on a new, Java 7-specific class:  com.sun.beans.finder.ClassFinder. This apparently opens up restricted packages for untrusted code, and thus allows the use of GetField to access private fields.

It is being widely reported that the exploit can be carried out without any visible interruption of a browser's performance, making it even harder to pick up without specific security tools.

Once the exploit has taken control to this point, said Schierl, "no security manager is left, and the applet can do anything Java can".

Computing has contacted Oracle for comment, and is currently awaiting a response.

Reader comments

blog comments powered by Disqus

Newsletters

Does Google know too much about you?

Google's linked data policy, which came into effect on March 1, allows the company to collect information about its users across all its products, services and websites and store it in one place. This has been criticised by organisations ranging from CNIL to Microsoft, all of whom have expressed concerns that it's difficult to tell which data Google collects and how it's used. Now the Information Commissioner's Office is investigating whether Google's privacy policy is compliant with UK law. Are you worried that Google knows too much about you?

41 %

5 %

15 %

39 %