bk99.de entertain the web since 1997

hß Security update check shut down because of a security hole

Summary

In August 2012 heise Security shut down its online update check because it required Java, and Java 7 had just been found to have a highly critical hole that was already being exploited. The hole affected all browsers with the Java 7 plugin; modules for the Blackhole exploit kit were already circulating, and no patch from Oracle had been announced yet. As an alternative, heise recommended the locally installed Personal Software Inspector.

Ideas

  • A security service that needs Java endangers its users when Java is vulnerable.
  • Exploit kits make new holes exploitable without programming skills.
  • The only thing that helped against the zero-day hole was disabling Java.
  • A local checking tool replaced the web-based check.

Insights

  • Consistently switching off your own service can be the most responsible security decision.
  • For years, browser plugins were one of the biggest points of entry for malware.

Facts

  • F-Secure had already spotted modules for the Blackhole exploit kit.
  • The current Java version 7 was affected on all operating systems.

References

Critique

  • The report gives no identifier for the hole, which makes it harder to match against later updates.

Remarks

  • Oracle closed the hole a few days later in an unscheduled update; Java applets in the browser have since been abolished entirely.

Recommendations

  • Remove runtime environments and plugins that you do not actively need.
  • With security tools, check which dependencies they bring with them.

Read the original article

Search the Web Archive