Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 16th, 2013, 14:50 GMT · By

BLOG

Java 7 Update 11 Zero-Day Exploit Sold for $5,000 on Underground Market

SHARE:

Adjust text size:


Java 7 Update 11 zero-day sold on underground markets Enlarge picture - Java 7 Update 11 zero-day sold on underground markets
Less than a week has passed since Oracle patched the vulnerability in Java 7 Update 10 and another zero-day exploit – which is said to work on Java 7 Update 11 – is already being sold on the cybercriminal underground market.

Brian Krebs, who came across an ad for the exploit on a hacker forum on Monday, reveals that the author had offered to sell it to two people for the price of $5,000 (3,750 EUR). The buyers were promised an “encrypted” and “weaponized” version of the exploit.

In the ad he posted, the seller claimed that the exploit was not integrated into any known crime kits, not even in the expensive Cool Exploit Kit.

According to Krebs, the cybercriminal most likely found buyers since the post was removed from the forum.

This shows that the US Department of Homeland Security is right to advise users to uninstall Java if they don’t need it for their everyday tasks.

In its advisory, the DHS has warned that Oracle might have addressed one issue, but some old vulnerabilities are still unfixed and security holes are identified in Java all the time.

TELL US WHAT YOU THINK:

3,080 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


DHS Advises Users to Ditch Java, Despite Zero-Day Fix

Java 7 Update 11 Addresses the Flaw Partly Fixed in October 2012, Experts Say

Java 7 Zero-Day Exploit Used to Distribute Reveton Ransomware

Java 7 Zero-Day Possible Because Oracle Didn’t Properly Address Old Vulnerability

Expert Finds Java 1.7 Zero-Day on High-Profile Website

READER COMMENTS:


Comment #1 by: jishnu on 16 Jan 2013, 15:50 UTC reply to this comment

Disable java immediately to get protected until a complete patch is released

Disable Java n Browsers


Comment #2 by: oldsaltIT on 17 Jan 2013, 02:57 UTC reply to this comment

How can we uninstall it? You can't go 5 minutes without hitting a website that says "needs java". Are we to stay off the internet? Let's send some hit teams out after these people with laser-guided bombs and high power rifles. They deserve execution on site, nothing less: no trial, no tearful mother saying "he's a good boy". Just * their brains out.


Comment #3 by: ThatGuy on 19 Jan 2013, 03:05 UTC reply to this comment

@ Jishnu - Wait until a complete patch? not possible with Java. Oracle is the perpetuating vulnerability machine.

@OldSaltIT - I dont know what sites you are on; I have not had Java loaded on a machine in 5 years; no conflicts found. Though I do like your approach as well.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM