Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,199,944 members, 7,973,251 topics. Date: Saturday, 12 October 2024 at 12:20 PM

Java Vulnerabilities Increasingly Targeted By Attackers, Researchers Say - Programming - Nairaland

Nairaland Forum / Science/Technology / Programming / Java Vulnerabilities Increasingly Targeted By Attackers, Researchers Say (977 Views)

Apple Will Be Targeted By Hackers In 2016 / Researchers: AI Program Smart Enough To Enter 80% Of Private Universities (2) (3) (4)

(1) (Reply)

Java Vulnerabilities Increasingly Targeted By Attackers, Researchers Say by benJAVA: 8:18am On Jul 26, 2012
Java has leapfrogged Flash and Adobe Reader as the target of choice for Web exploit toolkit developers

Java vulnerabilities are increasingly exploited by attackers to infect computers, and the problem could become worse if Oracle doesn't do more to secure the product and keep its installation base up to date, according to security researchers who will talk about Java-based attacks at the Black Hat USA 2012 security conference.

A large number of computers get infected today through drive-by-download attacks performed with the help of Web exploit toolkits -- malicious Web applications designed to exploit vulnerabilities in widespread browser plug-ins like Flash Player, Adobe Reader, or Java.

Java was acquired by Oracle as part of its 2010 acquisition of Sun Microsystems.

A couple of years ago, the most targeted browser plug-ins were Flash Player and Adobe Reader, but many of today's Web exploit toolkits rely heavily on Java exploits, said Jason Jones, a security researcher with HP DVLabs, Hewlett-Packard's vulnerability research division.

Jones has monitored the development of some of the most commonly used Web exploit toolkits, like Blackhole or Phoenix, and will present his findings at Black Hat on Thursday.

One clear trend is that Web exploit toolkit developers are increasingly focusing on Java exploits, Jones said. They are also integrating exploits for new Java vulnerabilities at a much faster pace than before.

In some cases attackers reuse exploit code that gets published online by security researchers after Oracle patches the vulnerabilities. However, they modify it and apply different obfuscation techniques to it in order to evade detection by security products.

"Overall, we have seen the amount of Java malware increasing over time, based on our telemetry," Jeong Wook Oh, a researcher with Microsoft Malware Protection Center, said via email. Oh is scheduled to talk about recent Java exploitation trends and malware at Black Hat on Thursday.

Cyber-criminals are attracted to Java exploits because they can have very high success rates. For example, one particular exploit integrated into Blackhole in 2011 had a success rate greater than 80 percent, Jones said. This is because users are not deploying the available security updates in a timely fashion, which is going to be an even greater problem now that attackers are targeting new Java vulnerabilities faster.

Adobe dealt with similarly low patch adoption rates for Flash Player and Adobe Reader by improving the update mechanisms for those products and even implementing automatic updates for Flash Player.

Those changes had a direct impact on the overall frequency of attacks targeting the two products and so did other in-depth security measures taken by the company, like the introduction of a SDL (security development cycle) -- a series of code security reviews and development practices that aim to reduce the number of vulnerabilities -- or the implementation of sandboxing technologies, said Carsten Eiram, the chief security specialist at vulnerability management firm Secunia.

Source / Read More
www.ictng.com/read.php?id=103

(1) (Reply)

Given A Seminar Topic on "Php"...Your contributions is needed. / Android Developers;which Service Do U Use For Push Notification? / Project Colarboration

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 14
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.