AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=1039
Last Updated: 2006-01-13 20:17:17 UTC
"US-CERT* and AUSCERT** warn about a bug in java being exploited. They claim (the) bug was made public in November 2005.
…Download that latest greatest java environment now if you haven't done so already and upgrade. Better yet: in addition to upgrading all java versions, also check those browser settings and turn java off for all sites that you either not trust 100% to execute code on your machines or that don't absolutely need it to work.
UPDATE
We have been informed multiple times the hostile java seems to be at a webserver at fullchain [dot] net. Might be interesting to check your logs in a corporate environment. The supposedly hostile code is still there so we won't be providing detailed URLs for now. The class file on that website is not detected as malicious by any anti-virus product participating in virustotal… It's also necessary to remove the old java environments, not just get the new ones as an attacker can target the old environments when they are still present.
* http://www.us-cert.gov/current/current_activity.html#javaapi
** http://www.auscert.org.au/render.html?it=5925
>>> http://sunsolve.sun.com/searchproxy/docume…y=1-26-102003-1
"…Resolution…
* SDK and JRE 1.4.2_09 and later
* JDK and JRE 5.0 Update 4 and later
J2SE 1.4.2 is available for download at http://java.sun.com/j2se/1.4.2/download.html
J2SE 5.0 is available for download at http://java.sun.com/j2se/1.5.0/download.jsp …
Note: It is recommended that affected versions be removed from your system…"

- http://isc.sans.org/diary.php?storyid=1039
Last Updated: 2006-01-13 20:17:17 UTC
"US-CERT* and AUSCERT** warn about a bug in java being exploited. They claim (the) bug was made public in November 2005.
…Download that latest greatest java environment now if you haven't done so already and upgrade. Better yet: in addition to upgrading all java versions, also check those browser settings and turn java off for all sites that you either not trust 100% to execute code on your machines or that don't absolutely need it to work.
UPDATE
We have been informed multiple times the hostile java seems to be at a webserver at fullchain [dot] net. Might be interesting to check your logs in a corporate environment. The supposedly hostile code is still there so we won't be providing detailed URLs for now. The class file on that website is not detected as malicious by any anti-virus product participating in virustotal… It's also necessary to remove the old java environments, not just get the new ones as an attacker can target the old environments when they are still present.
* http://www.us-cert.gov/current/current_activity.html#javaapi
** http://www.auscert.org.au/render.html?it=5925
>>> http://sunsolve.sun.com/searchproxy/docume…y=1-26-102003-1
"…Resolution…
* SDK and JRE 1.4.2_09 and later
* JDK and JRE 5.0 Update 4 and later
J2SE 1.4.2 is available for download at http://java.sun.com/j2se/1.4.2/download.html
J2SE 5.0 is available for download at http://java.sun.com/j2se/1.5.0/download.jsp …
Note: It is recommended that affected versions be removed from your system…"