Google Search

Showing posts with label unpatched. Show all posts
Showing posts with label unpatched. Show all posts

Wednesday, March 6, 2013

Java hacker boasts of finding two more unpatched holes

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Serial Java fault-finder Adam Gowdiak has embarrassed Oracle yet again.

Gowdiak hit the headlines last year when he reported a vulnerability, waited for Oracle's response, and then upped the ante with a comeback vuln.

It's déjà vu all over again, with the Polish researcher publicly bragging about two brand-new vulnerabilities he's found even since Oracle's most recent patch just a week ago.

Gowdiak, who claims in his tagline to "bring security research to the new level," is critical of the way Oracle patched the latest hole.

He implies that although it locked the office door in update 7u11, Oracle left the entrance to the building open, which he considered as good as an invitation to find another way in.

MBeanInstantiator bug (or rather a lack of a fix for it) turned out to be quite inspirational for us. However, instead of relying on this particular bug, we have decided to dig our own issues.

Not only has he gone after new issues, he's found them, and is proud to tell us:

As a result, two new security vulnerabilities were spotted in a recent version of Java SE 7 code and they were reported to Oracle today.

Is this the next stage of a slow-motion train crash showing that Oracle is worse at security than everyone else?

Or is Oracle just the technology company that techies love to hate?

After all, as some commenters on Naked Security have pointed out, Windows and Microsoft have lots of vulnerabilities found week after week, yet they don't face the same public opprobrium as Java and Oracle.

Why is that, do you think?

Is is that Oracle is seen as a megacorp whose ultrarich founder hasn't yet got in touch with his philanthropic side (like Bill Gates), or brought to market sleek consumer products that everyone wants to own (like the late Steve Jobs)?

Is Oracle still the corporate database vendor that remained in security denial after everyone else had started to admit that this whole vulnerabilities-plus-exploits-equals-money-from-malware business might deserve a bit more proactivity?

Or is it simply as-yet unrequited technical antipathy that Oracle, of all possible suitors, had the temerity to buy Sun, and with it all of Sun's beardily-beloved technology?

Whatever the reasons, Oracle does seem to be learning something about the sociology of patching widely-distributed, consumer-targeted software like Java: patch early, patch often, don't be in denial, and think of extra mitigations beyond what is strictly necessary.

Indeed, Oracle's recent Java updates have introduced, amongst other things:

• The 7u11 patch that came out faster than many people expected.

• Stricter default security settings for code signing.

• A control panel with a "lock Java out of your browser" option.

Ironically, the biggest backlash on Naked Security against our suggestions to lock Java out of your browser has come from sysadmins saying, "You can't expect a business network to ditch Java so suddenly, and you're being thoughtless to suggest it."

Perhaps there's a bit of truth in that. We accept it's harder for a large and heterogeneous network to adapt its Java settings abruptly than it is for a consumer.

Nevertheless, we still think it's an issue you may as well confront now, instead of simply invoking "legacy reasons" as an excuse for ignoring it for too long, as many companies did with IE 6.

? Are you a sysadmin? Have you recently banned Java in corporate browsers? Or do you still have applets you simply must let everyone use? Send us an email, or leave a comment below, to tell us how you're getting along with Java...

Follow @duckblog


View the original article here

Tuesday, October 9, 2012

More than half of Androids have unpatched security holes, research claims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

X Ray appIf you're the owner of a mobile device running Google's Android mobile OS, the chances are pretty good that your device is vulnerable to attack, according to data from the firm Duo Security.

One in two Android devices that installed Duo’s X-Ray mobile vulnerability assessment software found known, unpatched vulnerabilities on the phone that could be used to take "full control of users' phones," according to a post by Duo CTO (and security Ninja) Jon Oberhide.

And the 50% number may be a conservative number, Oberhide warned.

Writing on the company's blog, Oberhide said that carriers' conservative approach to rolling out patches to fix Android vulnerabilities is a big part of the problem.

Duo's X-Ray application was released in July and has already been installed on 20,000 devices – a pretty good data set.

The application collects information on the version of the Android operating system a device is running, the carrier and any potentially vulnerable software.

Oberhide said that vulnerabilities on Android devices are a serious security problem and that vulnerable devices "often remain vulnerable for months and even years."

"Yes, it's a scary number, but it exemplifies how important expedient patching is to mobile security and how poorly the industry (carriers, device manufacturers, etc) has performed thus far," Oberhide wrote.

Data presented by Oberhide

Exploitable vulnerabilities are inevitable in complex software applications and operating systems and Duo says that Apple mobile devices like iPhones and iPad could contain vulnerabilities, also.

However, Apple and Google have taken radically different paths to market, with Apple retaining strict control over its operating system and the hardware platform it runs on. That has enabled the Cupertino, California company to easily and quickly push out operating system updates to its entire user base, regardless of carrier.

Google, however, offered its operating system as an open source offering that could run on any hardware.

That's been great for building a worldwide user base. Carriers and handset makers partnered to roll their own Android devices, each with a different version of the OS and a mélange of different applications and component.

That leaves Android device owners at the mercy of both their carrier and the handset maker if they want to get a security update to patch a serious, remotely exploitable hole; each update from Google has to be tested against a particular hardware platform by the manufacturer, then pushed out through carriers who are reluctant to do anything that might rile their mobile customer base.

Vanja Svajcer"Essentially, in Android ecosystem we are in a worse place than with pre-millennium Windows, before Automatic Updating was released," said Vanja Svajcer, a principal malware researcher at Sophos. "The main difference is that with Windows we did not have IBM, HP, Toshiba and Dell producing their own versions of the operating system and Best Buy, Walmart and Amazon deciding when to update."

Svajcer said the current, decentralized system of updates isn't sustainable: "Something will have to change with Android updating soon if we do not want to witness mass compromises of Android devices of the scale reminiscent Nimda, Code Red and other large Windows outbreaks from the beginning of the decade."

Oberhide presented the results of his company's survey of Android devices at the UNITED Security Summit in San Francisco on Friday, September 14.

Follow @paulfroberts

Tags: Android, Android attack, dnschanger, Duo Security, Exploit, Google, hacking, ios, Jon Oberhide, Malware, mobile malware, mobile phones, mobile virus, smart phones, United Summit, Vanja Svajcer, vulnerability, x-ray


View the original article here