Jump to content

Recommended Posts

Posted
newer versions do tend to download or at least prompt the user to download the update.

I think that's the problem. The average user simply ignores the prompt. Perhaps Oracle should either install Java to %AppData% by default (like Chrome and Dropbox), or install a service that keeps it up-to-date without prompting the user at all.

Posted

I suppose they could, but it may be down to compatibility or simply giving the user choice whether or not they want to install an update.

 

I think the best advice is to only install it if needed in the first place. This decreases the surface area of attack on any platform.

Posted

I think the best advice is to only install it if needed in the first place. This decreases the surface area of attack on any platform.

 

+1, a service for updates would be good, last thing we need is another dirty app spewing rubbish into every users profile - how would you like 500 copies of chrome, yay - but I agree that simply not installing it is the best option, it is a massive security hole and if we did not 'need' it for lots of dirty little online education apps then it would be the first against the wall.

Posted (edited)
last thing we need is another dirty app spewing rubbish into every users profile

It goes without saying that if installing to user profiles became the default, it should be overridable by admins doing network-wide installs.

 

A service would be better (to go along with the update services for Adobe Reader, Flash Player, Firefox, iTunes/Safari/QuickTime and the various Google apps). :)

 

the other question of course is why is this Java exploit only being exploited on Mac and not Windows?

The Java vulnerability used by the Flashback trojan (CVE-2012-0507) is actually the same one used by the Kelihos.C spambot on Windows. Tech journalists obviously report on the former because it generates page views and thus more ad revenue. ;)

 

I think the best advice is to only install it if needed in the first place.

Definitely.

Edited by Arthur
Posted

How about, on Windows, these plugin makers work with Microsoft and release their updates via the Microsoft Update platform. A single unified update platform for all software would be great.

 

Kinda like APT in Linux...

Posted
How about, on Windows, these plugin makers work with Microsoft and release their updates via the Microsoft Update platform. A single unified update platform for all software would be great.

 

Kinda like APT in Linux...

 

They managed it with the drivers, the other placesa would have to give up some control and their horrific update platforms but yes this would be the ideal solution.

Posted

On Adobe's Flash distribution page, it does state -

 

Customers using the Microsoft System Center Updates Publisher 4.5 can import the Flash Player Catalog for deployment via WSUS 3.0 SP2

 

Why you can't just download the file and import directly into WSUS 3.0 SP2 is unclear.

Posted
On Adobe's Flash distribution page, it does state -

 

 

 

Why you can't just download the file and import directly into WSUS 3.0 SP2 is unclear.

 

Messing with the WSUS DB is considered a premium feature, come to think of it there is an open source program - Local Update Publisher - that may let it be imported though. Unfortunatly its not automated so its just as much, if not more trouble than simply pushing out the new MSI through GPO every month or two.

Posted (edited)
Yep and the fact it takes 5 mins of someone's time to download and deploy an MSI.

Don't forgot to add the time it takes to initially create an MST (to disable the updater and the Java Quick Starter service) and to test the deployment to ensure each update installs/uninstalls cleanly and doesn't break any apps/websites.

Edited by Arthur
Posted

It looks like compromised Wordpress blogs are the infection vector for Flashback... :(

 

The anatomy of Flashfake. Part 1

Around the end of February/early March 2012, tens of thousands of sites powered by WordPress were compromised. How this happened is unclear. The main theories are that bloggers were using vulnerable versions of WordPress or they had installed the ToolsPack plugin. Websense put the number of affected sites at 30,000, while other companies say the figure could be as high as 100,000. Approximately 85% of the compromised blogs are located in the US.

 

Code was injected into the main pages when the blogs were hacked. Constructions of the following type were added to the code (example):

 

 

As a result, when any of the compromised sites were visited, a partner program TDS was contacted. Depending on the operating system and browser version, the browser then performed a hidden redirect to sites in the rr.nu domain zone that had the appropriate set of exploits installed on them to carry out an infection.

 

http://i.imgur.com/hWbRB.png

Posted

Unfortunately there are doubts now whether or not the patch has actually worked.

 

It really is a worrying time for Mac users, especially as many users believe they cannot be infected.

Posted
Unfortunately there are doubts now whether or not the patch has actually worked.

 

It really is a worrying time for Mac users, especially as many users believe they cannot be infected.

 

Logic fail, if they don't know about it how can they be worried about it ;)

Posted
Logic fail, if they don't know about it how can they be worried about it ;)

 

Very true, but I blame Apple personally. The amount of times I've spoken with someone that said "Oh in the Apple shop, the salesman told me Macs cannot get viruses" which obviously appeals to consumers, but it simply isn't true.

 

It all boils down to market share. Create a virus that targets 90% of the market or 10% of the market. The answer is obvious, but love them or hate them, virus/malware writers are clever people and are exploiting the knowledge some individuals think Apple Macs cannot get viruses.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...