Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Java Exploit - Zero Day attack prevention techniques

Hopefully an out-of-band patch will emerge sooner than the anticipated mid-September timeframe from Sun/Oracle. Below are  approaches to stay protected until a patch arrives:

1. AVOIDANCE -- Stay as safe as possible with respect to email, websites, Facebook, etc ... Stay on mainstream sites and avoid anything suspicious.  An ounce of prevention is worth a pound of cure.

2. AV PROTECTION -- Most AV products offer exploit protection fairly soon as they emerge. Below is an example from Trend and other vendors have also recently added protection.  Please keep your AV signature files updated, as helps in protecting from emerging threats (including many zero day exploits) 

TREND LABS - Zero Day Java exploit
http://blog.trendmicro.com/java-runtime-environment-1-7-zero-day-exploit-delivers-backdoor/

3. DISABLE JAVA -- As noted in this article disabling Java is difficult for IE and it can help in cases where there are no business requirements to use Java

How to Disable JAVA
http://securitywatch.pcmag.com/hacking/302019-security-warning-disable-java-now
http://blogs.technet.com/b/mmpc/archive/2012/08/30/protecting-yourself-from-cve-2012-4681-java-exploits.aspx

When the patch emerges, it will offer the best form of protection and should be quickly installed