<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title type="text">New Java malware, and free Anti Virus software suites</title>
  <updated>2012-09-02T15:12:16+01:00</updated>
  <generator uri="http://framework.zend.com" version="1.12.20">Zend_Feed_Writer</generator>
  <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757"/>
  <link rel="self" type="application/atom+xml" href="https://www.augwessex.org.uk/discussions/view/757/feed"/>
  <id>https://www.augwessex.org.uk/discussions/view/757</id>
  <author>
    <name>AUGW</name>
    <email>info@augwessex.org.uk</email>
    <uri>https://www.augwessex.org.uk/</uri>
  </author>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-05-01T17:18:20+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3339"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3339</id>
    <author>
      <name>Euan Williams</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Oh dear oh dear. Yet another Java villain has arrived, this time it uses Python scripts:<xhtml:br/>
<xhtml:br/>
http://nakedsecurity.sophos.com/2012/04/27/python-malware-mac/<xhtml:br/>
<xhtml:br/>
If you have used your browser preferences to "stop" Java -- NB "JavaScript" is something quite different and is fine to use -- and have installed all the latest Apple updates there should be no problem. But note that Apple have NOT issued updates to close off these attacks in OSX versions earlier than 10.6 Snow Leopard.<xhtml:br/>
<xhtml:br/>
The Sophos page offers a simple, quick check to see if you have been compromised, and also free anti-virus software from Sophos for home users:<xhtml:br/>
<xhtml:br/>
http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx<xhtml:br/>
<xhtml:br/>
ClamXav is another free (open source) antivirus protector if you prefer to use that:<xhtml:br/>
<xhtml:br/>
http://www.clamxav.com/download.php<xhtml:br/>
<xhtml:br/>
The two AV software suites have been reviewed widely (see Google).<xhtml:br/>
<xhtml:br/>
(re-posted from the F-Secure topic).</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-05-04T10:16:18+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3340"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3340</id>
    <author>
      <name>Mark Ford</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Did you instal this stuff Euan? <xhtml:br/>
'Mac Home Edition'? whatever is that? <xhtml:br/>
Which download, exactly, provides a 'swift, simple check..'?<xhtml:br/>
It all looks so dodgy!</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-28T19:19:22+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3550"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3550</id>
    <author>
      <name>Euan Williams</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Tuesday 28th August 2012<xhtml:br/>
Java's in trouble (again) this time it affects even the 1.7 Java runtime environment from Oracle:<xhtml:br/>
<xhtml:br/>
&gt;  http://www.macworld.co.uk/mac/news/?newsid=3378068&amp;olo=email  &lt;<xhtml:br/>
<xhtml:br/>
Pending a patch from Oracle (that's where Java patches come from these days) all Mac users should disable Java in their web browser. For Safari look in Safari &gt; preferences &gt; security &gt; ENABLE JAVA -- and make sure the tick box is empty.<xhtml:br/>
<xhtml:br/>
Firefox is vulnerable, and other browsers may be too.<xhtml:br/>
<xhtml:br/>
Java Script is something quite different, and is fine to use (keep the tick box ticked).<xhtml:br/>
<xhtml:br/>
Older OSX versions are vulnerable too, so unless you are using a "pure" version of Lion or Mountain Lion (with which Apple ceased to install Java by default) you should act on the MacWorld warning asap.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-28T20:26:59+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3551"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3551</id>
    <author>
      <name>Eleanor Spenceley</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">This new vulnerability is _only_ in Oracle's new  Java 7 (JRE 1.7), not earlier versions.<xhtml:br/>
<xhtml:br/>
You have had to explicitly download the latest Java runtime (directly from Oracle) _and_ have Java turned on in your browser. If not, there's nothing to worry about.<xhtml:br/>
<xhtml:br/>
If you want to know which version of Java you are running.<xhtml:br/>
<xhtml:br/>
Open Terminal.<xhtml:br/>
type in&gt;<xhtml:br/>
<xhtml:br/>
java -version<xhtml:br/>
<xhtml:br/>
Or go to <xhtml:br/>
<xhtml:br/>
Applications-&gt;Utilities-&gt;Java Preferences.<xhtml:br/>
<xhtml:br/>
Personally if you don't need Java (i.e. don't run any Java based Applications), I'd disable it on your Mac.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-29T13:53:32+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3552"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3552</id>
    <author>
      <name>Douglas Cheney</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Is it possible to delete Java from aMac</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-29T16:10:53+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3553"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3553</id>
    <author>
      <name>Thomas Maude</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Thanks for all this info guys and the links to possible solutions ....I for one am very grateful for you highlighting these kind of things that would have otherwise passed me by.<xhtml:br/>
<xhtml:br/>
Ive downloaded the Sophos free home edition package and it's scanning through my whole system now. it identyfied one possible troj connected to the adobe flash thing that I installed as an alerted upgrade recently ....so that has been 'cleaned up" as it described .....not sure what cleaned up really means but anyway it has ...<xhtml:br/>
<xhtml:br/>
Once again many thanks to Euan and Martin in particular and any others for providing this important stuff <xhtml:br/>
<xhtml:br/>
Tom</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-29T16:52:32+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3554"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3554</id>
    <author>
      <name>Eleanor Spenceley</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"><xhtml:em>Is it possible to delete Java from aMac</xhtml:em><xhtml:br/>
<xhtml:br/>
It depends on the version of Mac OS X you have and version of Java. Can you be more specific?</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-30T09:29:13+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3557"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3557</id>
    <author>
      <name>Douglas Cheney</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Running 10.8.1 and the latest Java 1.7</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-30T09:32:56+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3558"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3558</id>
    <author>
      <name>Eleanor Spenceley</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">A quick Google returns<xhtml:br/>
<xhtml:br/>
http://reviews.cnet.com/8301-13727_7-57423014-263/how-to-install-and-uninstall-java-7-for-os-x/</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-30T14:02:11+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3559"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3559</id>
    <author>
      <name>Douglas Cheney</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Thanks for that Martin, I went to the folder as listed but found it empty. I don't understand it because I did install the latest Java when it came out.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-31T11:45:37+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3562"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3562</id>
    <author>
      <name>Euan Williams</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Like Doug, I didn't find Java 7 in the folder, although v6 was there, despite having installed v7. I fear this is one of the many mysteries to which mortals do not have access (but, being curious, I do seek enlightenment).<xhtml:br/>
<xhtml:br/>
Meanwhile Oracle have posted a patch which may be appreciated by Java users:<xhtml:br/>
<xhtml:a href="http://www.appleinsider.com/articles/12/08/30/oracle_issues_patch_for_latest_java_security_flaw.html" target="blank">http://www.appleinsider.com/articles/12/08/30/oracle_issues_patch_for_latest_java_security_flaw.html</xhtml:a></xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-31T12:19:10+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3563"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3563</id>
    <author>
      <name>Eleanor Spenceley</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Try looking in both:<xhtml:br/>
<xhtml:br/>
/Library/Java/JavaVirtualMachines/<xhtml:br/>
<xhtml:br/>
and<xhtml:br/>
<xhtml:br/>
/System/Library/Java/JavaVirtualMachines/<xhtml:br/>
<xhtml:br/>
If it isn't there, then you must just have the Java runtime plugin for the web browser.<xhtml:br/>
<xhtml:br/>
see http://www.java.com/en/download/help/mac_uninstall_java.xml</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-31T16:17:08+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3564"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3564</id>
    <author>
      <name>Douglas Cheney</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Looked in System/LibraryJavaVirtualMachines and found 1.6.0.jdk. Is that what I should have found.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-31T16:20:26+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3565"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3565</id>
    <author>
      <name>Douglas Cheney</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Just found this on OS X Daily Java SE 7u7 Update Resolves Recent Security Issue. Should I update.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-08-31T23:54:50+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3567"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3567</id>
    <author>
      <name>Euan Williams</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Oops. Either the plot (or the soup) has thickened once more: Macworld has just reported as follows:<xhtml:br/>
<xhtml:br/>
"Security researchers from Poland-based security firm Security Explorations claim to have discovered a vulnerability in the Java 7 security update released Thursday that can be exploited to escape the Java sandbox and execute arbitrary code on the underlying system."<xhtml:br/>
<xhtml:br/>
Further details here:<xhtml:br/>
<xhtml:a href="http://www.macworld.com/article/1168382/researchers_find_critical_vulnerability_in_java_7_patch_hours_after_release.html#lsrc.rss_main" target="blank">MacWorld update 31 August</xhtml:a><xhtml:br/>
<xhtml:br/>
If it's not Hurricane Isaac or the GOP conference it's something else. I'm hibernating. (But before the hot chocolate, thanks Martin for chasing Java down its various burrows.)</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-09-01T08:37:20+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3568"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3568</id>
    <author>
      <name>Euan Williams</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">And a little mint to go with the chocolate?<xhtml:br/>
<xhtml:br/>
<xhtml:a href="http://www.theregister.co.uk/2012/08/31/critical_flaw_found_in_patched_java/" target="blank">More info from The A Register.</xhtml:a></xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-09-01T11:23:59+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3569"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3569</id>
    <author>
      <name>Mick Burrell</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">It's not crystal clear to me (like lots of things!) but can this vulnerability <xhtml:em><xhtml:strong>only</xhtml:strong></xhtml:em> be exploited through a browser with Java enabled? I ask because I suspect not many of us use applications written in Java so could remove it completely but I happen to use two so can't.<xhtml:br/>
<xhtml:br/>
I've long had Java disabled in my browsers and indeed have not downloaded Oracle's version - still using Apple's last one so it's for future reference really. I assume that normal firewalls etc. would prevent any internet based attack while running one of these applications - is that correct?</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: New Java malware, and free Anti Virus software suites]]></title>
    <updated>2012-09-02T15:12:16+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/757#3571"/>
    <id>https://www.augwessex.org.uk/discussions/view/757#3571</id>
    <author>
      <name>Eleanor Spenceley</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml"><xhtml:em>Can this vulnerability only be exploited through a browser with Java enabled? I</xhtml:em><xhtml:br/>
<xhtml:br/>
I believe so and only with Java JRE 1.7 (not 1.6).<xhtml:br/>
<xhtml:br/>
<xhtml:em> I suspect not many of us use applications written in Java so could remove it completely but I happen to use two so can't.</xhtml:em><xhtml:br/>
<xhtml:br/>
If you are running Lion, I'd leave 1.6 alone. This is because it's part of the install of Lion and there maybe dependencies. Let Apple manage this.<xhtml:br/>
<xhtml:br/>
<xhtml:em>I assume that normal firewalls etc. would prevent any internet based attack while running one of these applications - is that correct?</xhtml:em><xhtml:br/>
<xhtml:br/>
I assume your applications are basic Java desktop applications (like Eclipse or ThinkFree Office) and not Java web based or 'JNLP' downloadable applications. If so, then these applications behave like just another desktop application and cannot be accessed externally via the internet/network with or without a firewall in place (simplistically, basic OS security will prevent such access).</xhtml:div>
    </content>
  </entry>
</feed>
