TMCnet Feature Free eNews Subscription
August 28, 2012

Poison Ivy Trojan Inside Java

By Frank Griffin, TMCnet Contributing Writer

If the code you are writing for your program is not checked thoroughly you can be sure people will find the vulnerability and exploit the weakness. This is true for any coder even if it is a multibillion dollar corporation. FireEye (News - Alert) found a new attack that exploits a vulnerability in Java and it was used to install a malware known as the Poison Ivy Trojan. If you were unlucky enough to have a machine that was targeted your data could be compromised.

When hackers make it known that there is a vulnerability in a program it spreads like wild fire and eventually evil doers will get a hold of it and inflict damage on innocent and unsuspecting computer users around the world.

 Metaspoil  released a proof of concept (POF) which is basically telling everyone out there that the hack is valid and you can use it to breach your target if they have Java installed on their machine. They tested it on a fully patched Windows 7 SP1 with Java 7 Update 6, Ubuntu Linux 10.0.4, Internet Explorer, Mozilla (News - Alert) Firefox and Google Chrome on Windows XP, Internet Explorer and Firefox on Windows Vista, Internet Explorer and Firefox on Windows 7 and Safar version 6.0 and Java 7 update 6 on Mac OS X 10.7.4. They also warn users by saying “As a user you should take this problem seriously, because there is currently no patch from Oracle (News - Alert). For now our recommendation is to completely disable Java until a fix is available.”

Java is very popular and it is virtually on every computer around the world, this fact alone should make Oracle break protocol and fix the patch ASAP so unsuspecting users will not be victimized by criminals who pray for such opportunities.

Secunia (News - Alert) is a recognized pioneer in the IT security ecosystem specializing in Vulnerability Management with customers such as Siemens and the Deutsche Bundesbank, the central bank of the Federal Republic of Germany. It rated the vulnerability as “extremely critical”, because if the system is breached it allows the execution of arbitrary code on those systems without user interaction. What this means to users is if you are visiting a website and the page contains a malicious Java applet the file will be downloaded and executed on your computer or enterprise system without doing anything.

The exploit is hosted on a site with an IP address in China and the payload is the malware that connects to a command and control server in Singapore.

Carsten Eiram of Secunia, said, "Another major reason for why Java is interesting from an exploitation point-of-view is how it's affected by certain bypass type vulnerabilities (like this one); these make it easy to reliably create exploits across different versions and platforms without having to worry about various security mechanisms e.g. ASLR and DEP on Windows."

Hopefully, by now the news of the vulnerability has reached Oracle but the company generally patches Java three times a year and the next update is almost two months away. So your best option is to remove Java from your browser until the patch is available.



Want to learn more about the latest in communications and technology? Then be sure to attend ITEXPO West 2012, taking place Oct. 2-5, in Austin, TX.  Stay in touch with everything happening at ITEXPO (News - Alert). Follow us on Twitter.




Edited by Brooke Neuman
» More TMCnet Feature Articles
Get stories like this delivered straight to your inbox. [Free eNews Subscription]
SHARE THIS ARTICLE

LATEST TMCNET ARTICLES

» More TMCnet Feature Articles