Arthur Posted April 14, 2012 Posted April 14, 2012 newer versions do tend to download or at least prompt the user to download the update. I think that's the problem. The average user simply ignores the prompt. Perhaps Oracle should either install Java to %AppData% by default (like Chrome and Dropbox), or install a service that keeps it up-to-date without prompting the user at all.
Michael Posted April 14, 2012 Posted April 14, 2012 I suppose they could, but it may be down to compatibility or simply giving the user choice whether or not they want to install an update. I think the best advice is to only install it if needed in the first place. This decreases the surface area of attack on any platform.
SYNACK Posted April 14, 2012 Posted April 14, 2012 I think the best advice is to only install it if needed in the first place. This decreases the surface area of attack on any platform. +1, a service for updates would be good, last thing we need is another dirty app spewing rubbish into every users profile - how would you like 500 copies of chrome, yay - but I agree that simply not installing it is the best option, it is a massive security hole and if we did not 'need' it for lots of dirty little online education apps then it would be the first against the wall.
Arthur Posted April 14, 2012 Posted April 14, 2012 (edited) last thing we need is another dirty app spewing rubbish into every users profile It goes without saying that if installing to user profiles became the default, it should be overridable by admins doing network-wide installs. A service would be better (to go along with the update services for Adobe Reader, Flash Player, Firefox, iTunes/Safari/QuickTime and the various Google apps). the other question of course is why is this Java exploit only being exploited on Mac and not Windows? The Java vulnerability used by the Flashback trojan (CVE-2012-0507) is actually the same one used by the Kelihos.C spambot on Windows. Tech journalists obviously report on the former because it generates page views and thus more ad revenue. I think the best advice is to only install it if needed in the first place. Definitely. Edited April 14, 2012 by Arthur
localzuk Posted April 14, 2012 Posted April 14, 2012 How about, on Windows, these plugin makers work with Microsoft and release their updates via the Microsoft Update platform. A single unified update platform for all software would be great. Kinda like APT in Linux...
SYNACK Posted April 14, 2012 Posted April 14, 2012 How about, on Windows, these plugin makers work with Microsoft and release their updates via the Microsoft Update platform. A single unified update platform for all software would be great. Kinda like APT in Linux... They managed it with the drivers, the other placesa would have to give up some control and their horrific update platforms but yes this would be the ideal solution.
Michael Posted April 14, 2012 Posted April 14, 2012 On Adobe's Flash distribution page, it does state - Customers using the Microsoft System Center Updates Publisher 4.5 can import the Flash Player Catalog for deployment via WSUS 3.0 SP2 Why you can't just download the file and import directly into WSUS 3.0 SP2 is unclear.
SYNACK Posted April 14, 2012 Posted April 14, 2012 On Adobe's Flash distribution page, it does state - Why you can't just download the file and import directly into WSUS 3.0 SP2 is unclear. Messing with the WSUS DB is considered a premium feature, come to think of it there is an open source program - Local Update Publisher - that may let it be imported though. Unfortunatly its not automated so its just as much, if not more trouble than simply pushing out the new MSI through GPO every month or two.
Michael Posted April 14, 2012 Posted April 14, 2012 Yep and the fact it takes 5 mins of someone's time to download and deploy an MSI.
Arthur Posted April 14, 2012 Posted April 14, 2012 (edited) Yep and the fact it takes 5 mins of someone's time to download and deploy an MSI. Don't forgot to add the time it takes to initially create an MST (to disable the updater and the Java Quick Starter service) and to test the deployment to ensure each update installs/uninstalls cleanly and doesn't break any apps/websites. Edited April 14, 2012 by Arthur
Arthur Posted April 14, 2012 Posted April 14, 2012 This is interesting... OSX.Flashback.K – Suffering a Slashback – Infections Down to 270,000 « Symantec http://i.imgur.com/PBV4J.jpg
Arthur Posted April 21, 2012 Posted April 21, 2012 It looks like compromised Wordpress blogs are the infection vector for Flashback... The anatomy of Flashfake. Part 1 Around the end of February/early March 2012, tens of thousands of sites powered by WordPress were compromised. How this happened is unclear. The main theories are that bloggers were using vulnerable versions of WordPress or they had installed the ToolsPack plugin. Websense put the number of affected sites at 30,000, while other companies say the figure could be as high as 100,000. Approximately 85% of the compromised blogs are located in the US. Code was injected into the main pages when the blogs were hacked. Constructions of the following type were added to the code (example): As a result, when any of the compromised sites were visited, a partner program TDS was contacted. Depending on the operating system and browser version, the browser then performed a hidden redirect to sites in the rr.nu domain zone that had the appropriate set of exploits installed on them to carry out an infection. http://i.imgur.com/hWbRB.png
Michael Posted April 22, 2012 Posted April 22, 2012 Unfortunately there are doubts now whether or not the patch has actually worked. It really is a worrying time for Mac users, especially as many users believe they cannot be infected.
SYNACK Posted April 22, 2012 Posted April 22, 2012 Unfortunately there are doubts now whether or not the patch has actually worked. It really is a worrying time for Mac users, especially as many users believe they cannot be infected. Logic fail, if they don't know about it how can they be worried about it
Michael Posted April 22, 2012 Posted April 22, 2012 Logic fail, if they don't know about it how can they be worried about it Very true, but I blame Apple personally. The amount of times I've spoken with someone that said "Oh in the Apple shop, the salesman told me Macs cannot get viruses" which obviously appeals to consumers, but it simply isn't true. It all boils down to market share. Create a virus that targets 90% of the market or 10% of the market. The answer is obvious, but love them or hate them, virus/malware writers are clever people and are exploiting the knowledge some individuals think Apple Macs cannot get viruses.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now