The Conservative Cave

The Help Desk => Computer Related Discussions & Questions => Topic started by: EagleKeeper on February 20, 2013, 11:36:40 AM

Title: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 11:36:40 AM
I'm serious about this.

You don't have to run windows update, just go to the Oracle website.

http://www.java.com/en/download/index.jsp

If your not running windows it *does* matter, either disable it or make sure it's up to date.

I'm not kidding, do it.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: thundley4 on February 20, 2013, 02:32:16 PM
They have been releasing more updates than Microsoft lately.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: J P Sousa on February 20, 2013, 03:28:46 PM
I uninstalled Java.........nobody seems to know what's what with this thing.  :hammer:
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 06:30:32 PM
I'm bumping this.

I just spoke with someone that told me that their network got borked by this (multiple) vulnerablity(s).

If you run windows you are vulnerable.

I don't care what version of windows you have, update it.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: formerlurker on February 20, 2013, 06:33:20 PM
Can you give us an update as to why we need to do this (I just did it - thanks for the warning).
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 06:38:18 PM
I don't know what this thing is called yet, I'm kinda out of the loop.

I do know that it made a network drive unavailable for an entire company.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: formerlurker on February 20, 2013, 06:40:57 PM
Ok thanks.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: Maxiest on February 20, 2013, 06:45:40 PM
I don't know what this thing is called yet, I'm kinda out of the loop.

I do know that it made a network drive unavailable for an entire company.

I highly doubt that.  I am not onsite, but I haven't read anything about any of these Java virus's attacking any network resources.  And they are pretty much just malware.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 06:56:12 PM
That's fine.

Here is what I know...

It didn't effect the mainframe.

It made a company wide network drive unavailable for 2 days.

The person I talked to said that it had something to do with java but this person is not in IT. This person must talk to the IT folkes as part of her job.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: Maxiest on February 20, 2013, 07:06:31 PM
That's fine.

Here is what I know...

It didn't effect the mainframe.

It made a company wide network drive unavailable for 2 days.

The person I talked to said that it had something to do with java but this person is not in IT. This person must talk to the IT folkes as part of her job.

Yeah we always blame it on some bullshit when talking to non-IT folks, we hate going into how the PERC 3/Di Raid controller failed to initialize after we just upgraded the firmware because it couldn't handle the new drives we purchased and now even since we did the firmware upgrade neither the old or new drives will initialize.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 07:26:25 PM
Whatever

I'm only going to do this once.

The person I talked to runs a group within a company,right?

The various groups need to talk to IT, primarily to discuss mainframe programming.

The person I talked to is not in IT but because she understands what her business unit needs to see from the mainframe she talks to IT.

While she was talking to IT she learned (sorta) why her L drive had been missing for 2 days. She doesn't give a damn about computers but she does care about the L drive and it was explained to her that they had a virus problem that caused them to not have an L drive for two days.

She understood that it was caused through a vulnerability within java.

Do you remember spybot 32...I saw it coming, from spain, but I didn't recognize what it was and neither did they.

It didn't bother me to much, all I had to do was square away the servers. The helpdesk on the otherhand was much more challenged. 
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: Maxiest on February 20, 2013, 07:37:42 PM
Whatever

I'm only going to do this once.

The person I talked to runs a group within a company,right?

The various groups need to talk to IT, primarily to discuss mainframe programming.

The person I talked to is not in IT but because she understands what her business unit needs to see from the mainframe she talks to IT.

While she was talking to IT she learned (sorta) why her L drive had been missing for 2 days. She doesn't give a damn about computers but she does care about the L drive and it was explained to her that they had a virus problem that caused them to not have an L drive for two days.

She understood that it was caused through a vulnerability within java.

Do you remember spybot 32...I saw it coming, from spain, but I didn't recognize what it was and neither did they.

It didn't bother me to much, all I had to do was square away the servers. The helpdesk on the otherhand was much more challenged. 

I wasn't trying to argue.  Sorry if you thought that.  Just making conversation.

Just in my experience, I have never seen or heard of a Java virus that could even touch a network drive/server/array.

Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: J P Sousa on February 20, 2013, 07:50:44 PM
I wasn't trying to argue.  Sorry if you thought that.  Just making conversation.

Just in my experience, I have never seen or heard of a Java virus that could even touch a network drive/server/array.



Facebook ???

http://www.forbes.com/sites/andygreenberg/2013/02/15/facebook-hacked-via-java-vulnerability-claims-no-user-data-compromised/

.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 07:57:23 PM
I wasn't trying to argue.  Sorry if you thought that.  Just making conversation.

Just in my experience, I have never seen or heard of a Java virus that could even touch a network drive/server/array.



No Maxiest, I just want folkes to understand that it is the virus they don't know about that will delete their files (or their L drives).

A well constructed virus moves through the internet like a hot knife.

Java has problems and the bad guys know it.

Update Java and if you can push it out to your clients do it.

And it's not just windows.

Update your fookin java!
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: Maxiest on February 20, 2013, 08:02:10 PM
Facebook ???

http://www.forbes.com/sites/andygreenberg/2013/02/15/facebook-hacked-via-java-vulnerability-claims-no-user-data-compromised/

.

As I said...

This attacked on a couple machines(laptops) and didn't go any further.

Quote
The compromised website hosted an exploit which then allowed malware to be installed on these employee laptops. The laptops were fully-patched and running up-to-date anti-virus software. As soon as we discovered the presence of the malware, we remediated all infected machines, informed law enforcement, and began a significant investigation that continues to this day.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 08:06:04 PM
Maxiest

Just for conversation.

Can I ask what you have on the perimeter of your network?
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: Maxiest on February 20, 2013, 08:17:00 PM
We use Sonic Firewall and Barracuda, but most of our stuff is connected through the state, and I have no idea what they are using.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 08:35:26 PM
When I was in the biz we used barracuda for web traffic.

Two Clearswift servers for email (I think they are strictly devices now) and of course a cisco firewall.

I also had Snort sensors that listened to every link that went to the internet. And to every link that went to other parts of the company.

On the other end we had an embedded checkpoint firewall 1 running on a nortel bln (backbone Lan Node) 9000 I think.

We had T-1, mpls, and VPN links done through nortel devices.


At this point I ain't trying to prove anything, I'm just talkin shop.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: Chris_ on February 20, 2013, 08:37:47 PM
I had a friend that did network security for the state for a few years until moving on to self-employment.  He could probably have told you exactly what they were using.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: Maxiest on February 20, 2013, 08:38:50 PM
When I was in the biz we used barracuda for web traffic.

Two Clearswift servers for email (I think they are strictly devices now) and of course a cisco firewall.

I also had Snort sensors that listened to every link that went to the internet. And to every link that went to other parts of the company.

On the other end we had an embedded checkpoint firewall 1 running on a nortel bln (backbone Lan Node) 9000 I think.

We had T-1, mpls, and VPN links done through nortel devices.

Yeah, see that State does all of that web site motioning on their end as we use their DNS.

Our internal VPN is run through a Cisco firewall.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: Maxiest on February 20, 2013, 08:40:28 PM
I had a friend that did network security for the state for a few years until moving on to self-employment.  He could probably have told you exactly what they were using.

Yes I know who you are talking about as we have talked about him before.  He probably did know more specifics on the State hardware than I did as we are a Non-Consolidated department.  Meaning we provide most of the IT services minus a the major backbone, although we are looking at moving away from that as we have to pay the State for those services.  And shitty ones at that.
Title: Re: Make sure the JAVA running your Comp is up to date!
Post by: EagleKeeper on February 20, 2013, 08:48:22 PM
Yes I know who you are talking about as we have talked about him before.  He probably did know more specifics on the State hardware than I did as we are a Non-Consolidated department.  Meaning we provide most of the IT services minus a the major backbone, although we are looking at moving away from that as we have to pay the State for those services.  And shitty ones at that.

Do yourself a favor and start reading up on GRE

Start with the Requests for comments (RFC)