|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 | |
|
macrumors bot
Join Date: Apr 2001
|
Unpatched OS X Java Vulnerabilities Drawing Attention
![]() Programmer and former Apple engineer Landon Fuller has released a proof-of-concept exploit demonstrating vulnerabilities in Apple's current implementation of Java that allow arbitrary code execution in Java-enabled Web browsers. While the vulnerabilities, first discovered last August, were disclosed and patched by Sun last December, Apple has yet to roll out a fix for its own implementation of Java. Quote:
The only recommended workaround at this time is to disable Java applets in all browsers and to disable the 'Open "safe" files after downloading' option in Safari. Disabling Java applets will cause some websites to behave incorrectly, but no other protection against exploits of the vulnerabilities is available until Apple releases a patch. Article Link: Unpatched OS X Java Vulnerabilities Drawing Attention |
|
|
|
|
|
|
#2 |
|
macrumors Demi-God
Join Date: Nov 2007
Location: Georgia, USA
|
I'm not really sure how to rate this news article.
I could rate Positive because Landon Fuller is really trying to bring the issue to everybody's attention. But then I could rate Negative because Apple still hasn't resolved this issue. Hmm... decisions, decisions.
__________________
People who talk in metaphors oughta shampoo my crotch. |
|
|
|
| themoonisdown09 |
| View Public Profile |
| Find More Posts by themoonisdown09 |
|
|
#3 |
|
macrumors Demi-God
Join Date: Nov 2008
Location: Denver, CO
|
__________________
[Gandalf-Q8200|Server 2008 R2] [Durin-3.2 W5580 Quad|10.6.2] [Arien-iMac|10.6.2] [Arwen-G4 Mini|Server 10.4] [Aragorn-G4 Mini|Server 10.4] [Frodo-G4 Cube|10.2] |
|
|
|
|
|
#4 |
|
macrumors 6502
Join Date: Apr 2007
|
When I read this, I immediately went to Safari's preferences menu to disable Java, only to find that I'd already disabled it. I'most likely have had it disabled since right after I finished installing OS X, along with 'Open "safe" files after downloading' of course...
Never noticed anything missing on the web without it. At all. |
|
|
|
|
|
#5 |
|
macrumors 68000
Join Date: Feb 2008
Location: B'ham
|
Totally unacceptable and inexcusable.
|
|
|
|
| Bubba Satori |
| View Public Profile |
| Find More Posts by Bubba Satori |
|
|
#6 |
|
macrumors 6502
Join Date: Feb 2009
|
So much for the always annoying Apple quarantine setting to be useful...
|
|
|
|
| celtikmind |
| View Public Profile |
| Find More Posts by celtikmind |
|
|
#7 |
|
macrumors 65816
Join Date: Apr 2005
|
Workaround is to disable Java in your browser
Here's the blog post from Intego:
The best way to protect against this exploit is to deactivate Java in your web browser. In Safari, choose Safari > Preferences, click the Security tab, and uncheck Enable Java if it is checked. It is safe to leave Enable JavaScript activated, since this vulnerability only affects Java applets. If you use Firefox, this setting is found on the Content tab of the program’s preferences. http://blog.intego.com/2009/05/20/in...vulnerability/
|
|
|
|
|
|
#8 |
|
macrumors 6502
Join Date: May 2008
|
Welp...it's been good, guys. but we all knew this day would come.
|
|
|
|
|
|
#9 |
|
macrumors 6502a
|
This isn't the first exploit that Apple eventually fixes.
__________________
2.6GHz 15" MacBook Pro (Penryn) / 4GB RAM / 500GB 7200RPM HDD / 8600M GT 512MB 32GB iPhone 3GS |
|
|
|
|
|
#10 | |
|
Demi-God (Moderator)
Join Date: Oct 2002
Location: The Bamboo Forest
|
Quote:
I will however be curious to see how long it takes them to fix this now that it's more widely talked about.
__________________
Ban violins in video games now! |
|
|
|
|
| SilentPanda |
| View Public Profile |
| Find More Posts by SilentPanda |
|
|
#11 |
|
macrumors 6502a
Join Date: Jul 2008
Location: Sweden
|
Yeah because Java exploits is something new...
__________________
MacBook 2.2 GHz 2 gig ram 120 GB HD; iPhone 3G 16 GB; iPod Video 30 GB
|
|
|
|
|
|
#12 | |
|
macrumors regular
Join Date: Mar 2005
|
Quote:
|
|
|
|
|
|
|
#13 |
|
macrumors regular
Join Date: May 2008
|
For all the good that Apple does, they still can't touch Microsoft's reliability when it comes to fixing vulnerabilities in a timely fashion. Sure there have been times that MS failed to deliver a patch for a very long time, but that seems to be in the past now. We know every month we are getting updates in one form or another for Windows, and yet we just hope that we get an update from Apple in some random timeframe that only they know about. They've been working on 10.5.7 for a few months before they released it and didn't bother fixing Java? What is that? Windows is a security nightmare for many, but at least MS makes an attempt to patch as quick as possible. I know I can disable Java and will probably not miss it, but that's not the point here.
|
|
|
|
| ghostface147 |
| View Public Profile |
| Find More Posts by ghostface147 |
|
|
#14 | |
|
macrumors regular
Join Date: Jun 2007
|
Quote:
|
|
|
|
|
|
|
#15 | |
|
macrumors 6502
Join Date: May 2008
|
Quote:
Yeah man, java has been exploited before, so we're safe.
Last edited by SilentPanda : May 20, 2009 at 03:54 PM. Reason: post merge |
|
|
|
|
|
|
#16 |
|
macrumors member
Join Date: Jul 2008
|
This reminds me of how I don't like the fact that Apple has to release java on it's own to begin with...
|
|
|
|
|
|
#17 |
|
macrumors 6502
Join Date: Sep 2006
|
wait wait wait... so those 8 or so java updates were for what?
__________________
"Technological progress is like an axe in the hands of a pathological criminal." "Nationalism is an infantile disease. It is the measles of mankind. " -Einstein |
|
|
|
| Corrosive vinyl |
| View Public Profile |
| Find More Posts by Corrosive vinyl |
|
|
#18 |
|
macrumors regular
Join Date: Sep 2008
Location: Western IL
|
You'd think that given all the virus-free trash talk in Apple ads lately that it won't be long before someone writes a really good OSX or java virus. Which could turn into a bit of a PR problem...
__________________
Was a PC, now my house is carpeted with Apple products... iMac / MBP / MM / Cube / IPT / iPod 5g / Would have iPhones if AT&T didn't suck. |
|
|
|
| OrganMusic |
| View Public Profile |
| Find More Posts by OrganMusic |
|
|
#19 |
|
macrumors 68040
Join Date: Oct 2003
Location: The soggy part of the Pacific NW
|
Hopefully this'll get patched soon, now that it's being widely acknowledged. But it did serve as a good reminder for me to turn off Java.
I think it's more important that Mac users learn to stop running as an admin by default! There's no good reason for doing that, since OS X makes it brainless (and transparent) to invoke an admin username/password when necessary. If you're not running as an admin, the worst an exploit like this could do is hose stuff in your own account. That's still very bad; but it's less likely to allow installation of something like a keylogger, trojan or spyware without your knowledge. Besides, you all have current backups don't you?
__________________
The fevered rantings found in this post are generated randomly. Any resemblance to coherent thought is completely coincidental. |
|
|
|
|
|
#20 |
|
macrumors 6502a
Join Date: Apr 2006
|
Why don't you just draw the hackers a diagram?
|
|
|
|
|
|
#21 |
|
macrumors 6502
Join Date: Sep 2008
|
The first thing I do when I install any browser is disable Java Applets. The thought of having such a powerful programming environment available to all and sundry is scary. Javascript itself is bad enough.
When you browse around the web these days, you are not just viewing this URL and viewing that URL, you are running this program and running that program. Hundreds of programs one after the other and you often know nothing about who wrote them. People are so careful about what they install, but then just browse any old where.
__________________
27" i7 iMac, iPhone 3G |
|
|
|
|
|
#22 |
|
macrumors regular
Join Date: Jan 2009
Location: United Kingdom
|
The only Java I've ever used is on Facebook. Unless I'm not leaving the confines of my oak table enough these days, I can't think of a single other website which uses Java :\
__________________
Pay-monthly UK iPhone user? Check your allowance with just one tap! |
|
|
|
|
|
#23 |
|
macrumors regular
Join Date: Sep 2008
|
Sounds sad, but I would do anything to keep the Mac community safe from Viruses. This shouldn't be the time that viruses come in mass for Macs.
If your in Safari 4, go tell Apple about it. I clicked the bug button ![]() They probably know, but oh well. Still do it ![]() ![]() ![]()
|
|
|
|
| o0samotech0o |
| View Public Profile |
| Find More Posts by o0samotech0o |
|
|
#24 | |
|
macrumors Demi-God
Join Date: Sep 2004
Location: By the roadside
|
Quote:
__________________
|
|
|
|
|
|
|
#25 |
|
macrumors 6502a
Join Date: Jan 2009
Location: New England, USA
|
Sounds like we'll be having at least one more update before Snow Leopard.
__________________
Dell Vostro A90 Aluminum iMac 7,1 iPhone 3G AEBS TV
|
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|